Skip to main content
LEGAL / PLAIN LANGUAGE

Privacy Policy

Effective July 20, 2026

Launch configuration required: the operator's verified legal name and mailing address have not been configured. This notice intentionally does not invent them. Configure NEXT_PUBLIC_LEGAL_NAME and NEXT_PUBLIC_LEGAL_ADDRESS before public launch and obtain legal review.

Who operates Harmony

This notice applies to the Harmony website and Harmony desktop application operated by the Harmony project operator (“Harmony,” “we,” or “us”). Contact us at brian@ideharmony.com.

The important local-first distinction

The downloadable application is local-first. Harmony does not currently provide a managed model backend. Your source code, terminal contents, prompts, model outputs, file paths, and project names are not sent to this website or its analytics system.

If you configure a third-party model, coding agent, terminal tool, or account, that provider may receive information under its own terms and privacy notice. Harmony cannot control a provider you choose to run.

Harmony Cloud (optional)

Harmony Cloud is optional, and nothing is uploaded unless you start a transfer. When you do, the repository files and patches you confirm are uploaded to a hosted workspace. Workspaces run on Freestyle, a virtual-machine provider.

For Cloud we store your account email until you delete the account; the workspace filesystem while the workspace exists, plus the retention period after cancellation shown on the pricing page; the sealed transfers you chose, until the workspace and account they belong to are deleted; secrets you add under Account → Secrets, encrypted at rest, until you remove them or delete the account; and your device list, until a device is revoked or the account is deleted.

Known credential files such as .ssh, .aws and .env are refused when a transfer is built. That is a block list, not a guarantee that every secret is caught. When you sign an agent in inside a workspace, the provider creates that credential on that machine; it is not sent to our servers. Deleting your account destroys every workspace. Details are in the Cloud data-handling documentation.

Information you choose to provide

  • Contact forms: name, email, company, message, source page, and newsletter choice.
  • Newsletter: email address, confirmation token, and confirmation status.
  • Optional website account: email, name if provided, hashed session token, and account timestamps.
  • Optional purchases if enabled: product, amount, currency, status, and processor transaction identifiers. Stripe handles payment-card details; Harmony does not store complete card numbers.
  • Bug reports from the desktop application: title, description, severity, application version, platform, release channel, optional diagnostic summary, optional client context, optional screenshots, and an optional contact email. Reports are scanned for secrets before storage. Screenshots are limited to PNG format. You may omit contact email to submit a report anonymously.

Website analytics and delivery evidence

Optional browser analytics is off until you choose Allow analytics. If allowed, we use a random first-party session identifier for up to 30 days and store normalized page paths, allowlisted campaign parameters, normalized referrer origin/path, locale, and coarse device, operating-system, and browser families. We record CTA and download intent. We discard query values other than allowlisted UTM campaign values.

We do not persist raw IP addresses or full user-agent strings. An IP address is used transiently to create a secret-keyed rate-limit digest; that digest cannot be used by the dashboard to recover the IP. Hosting and network providers necessarily process network metadata to deliver requests and may keep their own security logs.

Artifact delivery, generated installer requests, bounded installer outcomes, first observed launch, update stages, and product-usage events may be counted without browser analytics so we can operate a reliable release channel and know whether the product is being used. Installer records use a random install ID minted per script fetch. Application records contain the event, app and target versions, release channel, platform, desktop-or-CLI source, an allowlisted status code, and a feature name drawn from a fixed published list. Session lengths are recorded as a bucket, never as a start and end time.

Application records carry a durable installation ID.It is a random UUID generated on your machine, stored alongside the application’s settings, and sent with each application event so repeated reports from one installation can be counted once instead of many times. It is not derived from your hardware, your account, or anything else about you, and we hold nothing that links it to a person — which also means that if you ask us to delete it, we cannot find it unless you tell us the value. Deleting the application’s data directory, or reinstalling, produces a new one. Earlier versions of this page said application records contained no persistent client identifier; that stopped being true when the identifier was introduced, and this paragraph replaces it.

Application records never contain filesystem paths, project or repository names, prompt or completion text, terminal input or output, source code, environment variables, credentials, IP addresses, raw user-agent strings, account identifiers, or free-text of any kind. That is enforced structurally rather than by review: every field of the payload is a fixed list, a bounded number, or a pattern with a length limit, and a build fails if a field is added that could hold anything else. Application telemetry is off until you turn it on. A fresh installation reports nothing: with no stored preference the application sends no usage or lifecycle events at all. Turning it on is a deliberate choice, and nala telemetry off turns it back off and deletes anything still queued. NALA_TELEMETRY=0 also suppresses reports from a shell installer. An earlier version of this page described this as something you opt out of; the application has always required the opposite, and this sentence corrects the description rather than the behaviour.

If Google Analytics is configured, its script is also blocked until you allow analytics. We honor Global Privacy Control and Do Not Track by disabling optional analytics, even if a prior preference said otherwise.

Analytics preference

Current state: not chosen

A Global Privacy Control or Do Not Track signal always wins over the saved preference.

Local storage and cookies

NamePurposeDuration
nala_analytics_consentLocal-storage preference you explicitly chooseUntil cleared
nala-themeLocal-storage UI preference for light or dark themeUntil cleared
harmony_hero_last_variant_v1Local-storage preference used to show a different homepage artwork on a later visitUntil cleared
harmony_hero_session_variant_v1Session-storage preference that keeps one homepage artwork stable while you browseBrowser session
harmony_hero_session_assignment_v1Random session identifier used to deduplicate consented homepage experiment eventsBrowser session
nala_exit_intent_dismissedLocal-storage UI preference so the newsletter prompt does not reappear after you close it7 days
nala_sidOptional first-party analytics session; set only after consent30 days
nala_sessionEssential, revocable account login if you request an account session30 days
nala_admin_sessionEssential restricted operator access; not used for public visitors8 hours

Why we use information

  • Provide requested downloads, accounts, emails, support, and optional purchases.
  • Protect the site, prevent abuse, diagnose bounded release failures, and keep downloads trustworthy.
  • Measure consented acquisition and installation stages and improve the website.
  • Meet legal obligations and enforce applicable agreements.

We do not sell personal information or use it for targeted advertising.

Service providers and disclosure

We use infrastructure providers for website hosting, PostgreSQL, private object storage, and network delivery. If configured, we also use Resend for requested email, Stripe for payments, Google Analytics for consented measurement, and OpenRouter for AI model inference via the gateway. When using the inference gateway, your prompts and model outputs are sent to OpenRouter under their published terms. Harmony Cloud workspaces run on Freestyle, which hosts the files you choose to transfer. They process information on our behalf or under their own published terms. We may also disclose information when required by law, to protect people or systems, during a business transfer, or with your direction.

Retention

Analytics events are retained for the configured period (180 days by default) and keyed rate-limit counters for no more than roughly 48 hours after use. Expired installer tokens are not stored as reusable credentials. Account, lead, email, transaction, and bug report records are kept while needed to provide the requested service, meet legal obligations, resolve disputes, or until a valid deletion request applies. Backups may age out on a separate operational cycle.

Your choices and requests

You can decline or later disable analytics above, enable Global Privacy Control or Do Not Track, unsubscribe using an email footer, sign out to revoke a browser session, and request access, correction, deletion, or portability where applicable by emailing brian@ideharmony.com. We may need to verify a request and may retain information where the law permits or requires it.

Security, transfers, and children

We use access controls, private storage, hashed or signed credentials, bounded inputs, and encrypted transport in production. No system can guarantee absolute security. Our providers may process information in the United States or other locations where they operate. Harmony is not directed to children under 16, and we do not knowingly collect their personal information.

Changes and contact

We will post material changes here and update the effective date. Questions or privacy requests can be sent to brian@ideharmony.com.