Privacy
What Harvio holds, why it holds it, who else sees it, and how long it stays. Written from the system rather than from a template.
Last updated
Two kinds of data, and they are not the same
Harvio is used by businesses to run their own customer relationships, so there are two quite different things in it.
Your workspace’s data — the companies you sell to, the people at them, your conversations, demos, onboarding and training records. That is yours. You decide what goes in it, what it is used for and when it goes. Harvio holds and processes it on your instructions, and does not use it for anything of our own.
Your account data — the names and email addresses of the people on your team who sign in, and the records of them doing so. That one is ours to be responsible for, because it exists so the product can work at all.
What is collected
| What | Why it exists | Where it comes from |
|---|---|---|
| Name and email of each seat | So people can sign in and be told who did what | An owner invites them |
| Sign-in records | So a session can be trusted and an owner can revoke one | Created when you sign in |
| Your customers' details | The record your business runs on | You enter it, import it, or a form you sent collects it |
| Conversations | Email and WhatsApp threads, so replies have context | Sent to or from your workspace |
| Demo and training activity | Who opened what, how far they got | Recorded as a link is used |
| Files and images | Attachments, logos, step screenshots, voice notes | Uploaded by you or by someone you sent a link to |
| Theme preference | Whether the portal is light or dark for you | A cookie, set when you choose |
| A connected Google Calendar | So bookings avoid your busy times and land in your calendar | You connect it, on Google's own consent screen |
| A connected Gmail mailbox | So a person's mail lives here as well as in Gmail, on the records it belongs to | They connect it, on Google's own consent screen |
Not collected: no analytics, no behavioural tracking, no advertising identifiers, no profiling, and no cookies beyond the two named on the Security page. Harvio loads no third-party scripts at all, which is enforced by a check in our build rather than by good intentions.
Who else sees it
Harvio passes data to a small number of services in order to function. The full list, and what each one sees, is on the Security page.
Two of them process content with AI and deserve saying twice. Anthropic receives the conversation being answered when Harvio drafts a suggested reply; every workspace starts in draft-only mode, where a person reads and sends. OpenAI receives the audio of a voice comment left on a demo, in order to transcribe it. Neither trains on your data, both can be switched off for your workspace on request, and neither ever receives your data for any purpose you have not asked for.
Google Calendar, if you connect it
A person on your team can connect their Google account to Harvio from Meetings › Your availability. Harvio asks Google for three things, and Google shows each on its consent screen: the list of their calendars, whether those calendars are busy or free, and permission to create and change events. Only the third writes anything, and only the bookings Harvio itself makes.
What is read: the names of the calendars, and the free/busy answer for the ones they tick — the start and end of each busy period, never a title, a guest or a description. Harvio keeps those busy periods for the next 45 days so a booking page can refuse a time that is taken, and re-reads them every few minutes. What is written: each booking made through Harvio, into the one calendar they choose — moved when it moves, removed when it is cancelled — and a Google Meet link where the kind of meeting asks for one. Nothing else in the calendar is touched, and Harvio sends no email through Google.
The connection’s tokens are stored encrypted under a key derived from the platform secret and are never shown to anyone. Disconnecting revokes them at Google and deletes them here; events already written stay in the calendar as ordinary events. Harvio’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: that information is used only to provide the scheduling features described here, is never used for advertising, and is never sold or passed to anyone else.
Gmail, if you connect it
A person on your team can connect their own Gmail from Settings › You. Harvio then keeps a copy of that mailbox — the last twelve months, then every message as it arrives — so their mail lives here as well as in Gmail. Google asks them for two things on its consent screen: to read and organise the mailbox, and to send from it. Sending from it is not used yet; when it is, this page will say so first.
Who sees a mirrored thread is decided by rule, and enforced by the database rather than by a screen. A thread with somebody on one of your records in it goes on that record and is shared with your team — unless your workspace has chosen otherwise, or the person whose mailbox it is marks it private. A thread with nobody on a record in it, a thread among colleagues, and any thread with an address on your never-log list stay private to the mailbox’s owner and appear on no record.
The connection’s tokens are stored encrypted under a key derived from the platform secret and are never shown to anyone. Disconnecting revokes them at Google and stops the mirror; what was already mirrored stays, under the same rules. Harvio’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: mailbox data is used only to show and organise that mail inside Harvio for the workspace it belongs to, is never used for advertising, is never used to train models, and is never sold or passed to anyone else.
How long it stays
Deleted records remain restorable for a window your workspace chooses — 90 days unless you change it — and are then erased, with their files removed from storage. What remains afterwards is the fact that something happened and when, not what it contained.
Everything else stays for as long as your workspace is open. Close it and tell us, and it goes.
Asking for your data, or its removal
You can see and export the contents of your workspace from inside the product at any time, and delete records yourself.
If one of your customers asks you for a copy of what you hold about them, or asks you to erase it, that is a request to you rather than to us — and everything needed to answer it is on their record. If you would like help, ask and we will help.
If you are on a Harvio team and want a copy of your own account data, or want it removed, ask an owner of your workspace or contact us directly.
Contacting us
Reach us through your usual contact at Harvio. A published privacy address, our registered company details and the identity of our supervisory authority will appear here before Harvio is open to workspaces beyond its first few.
If we change how any of this works, this page changes with it and the date at the top moves.