Legal

Privacy Policy

Last updated July 20, 2026 · v7.0 architecture

What We Collect

Email Address

If you subscribe to our email list or purchase the product, we collect your email address via Kit for onboarding and product updates. You may unsubscribe at any time.

Payment Information

All payments are processed through our Merchant of Record (payment processor). We do not store credit card information, bank details, or other sensitive payment data. Our processor handles PCI compliance and payment security.

How the scoring engine works

The Harvest connector sends each tool call to our Cloudflare Worker. To do its job, a call includes the ticker you're researching and the numeric inputs that tool needs — for example, the market's CAPE ratio, or optional portfolio-level numbers you choose to provide (such as a drawdown percentage or a cash amount to split across positions). The Worker fetches public market data, runs the proprietary scoring math, returns the result, and stores none of those inputs — with one narrow, separately opt-in exception described in "Outcome Tracking" below, where the ticker itself (never your other numbers, never your identity) is retained to check the methodology against real outcomes.

Call logging

For each call we log a small operational record: a one-way hash of your license key, the tool name (e.g., harvest_dcf), the timestamp, request latency, and whether the call succeeded or failed. On a failed call we also record the ticker involved, so we can reproduce and fix the bug — never on a successful call. We do not log your dollar amounts, your holdings, or your portfolio composition, and we do not retain IPs in association with your license.

BYO API Keys

The engine works with zero keys of your own (SEC filings and macro data come from public government sources automatically). If you choose to add your own free data-provider API keys for extra depth — at our setup page, mcp.getharvestprotocol.com/setup — we encrypt them at rest in Cloudflare KV using AES-GCM with a per-license-derived secret. We use these keys only to fetch the data you request through your scoring calls. You can rotate or delete your stored keys at any time.

Analytics

We use Cloudflare Web Analytics to track page views, traffic patterns, and basic user behavior on the marketing site (no personal identifiers). This helps us understand which content is most valuable. No tracking pixels, no third-party advertising networks, no behavioral profiling.

"Do Not Track" Signals

Some browsers send a "Do Not Track" signal. We don't have a special way to respond to it — but not because we ignore it: we run no interest-based advertising and no third-party trackers to opt out of in the first place, so there's nothing a DNT signal would change. This is a structural fact about how the site and engine are built, not a policy we could quietly reverse.

Methodology Telemetry (Opt-In)

Telemetry is off by default. We ask your choice once during guided setup (set up harvest), and you can change it anytime by re-running setup. If you opt in, we record aggregated calibration data: methodology version, verdict band, sweep type, a monthly-rotating salted cohort hash, predicted probability, near-miss distance, outcome bucket (hit / miss / near-miss / pending), and time-to-resolution. We never capture: tickers, dollar amounts, IP addresses, persistent user identifiers, or sub-day timestamps. The cohort salt rotates monthly and is destroyed afterward, making historical re-identification structurally impossible.

Outcome Tracking (Opt-In, Separate from Telemetry)

This is a second, separate opt-in question from the methodology telemetry above — off by default, asked as its own explicit yes/no during guided setup, and answering one question never opts you into the other. Its purpose: methodology telemetry alone can tell us what fraction of verdicts were PASS/WATCH/HOLD, but it cannot tell us whether those verdicts were actually right — that requires knowing which ticker a verdict was about, so it can be checked against real, public price history later. If you opt in, we record: the ticker, the verdict token, the methodology version, a same-day-granularity date, and (when already computed in that call) the composite score and entry price. We do not record your license key, any hash of it, any cohort code, or any other identifier alongside this data. A stock ticker is public market information; without an identity attached to it, it is not personal data about you. We're precise about the limits of that: while we opt in a small number of testers, we know who has said yes (the opt-in itself is recorded on your license), so we could in principle infer whose research a given row came from during that period — the guarantee is that we don't record or use that link, not that correlation is mathematically impossible at every scale. As the buyer base grows, that inference gets harder by construction. This is the only place where a ticker is ever retained by the Worker outside the failed-call logging described above (which exists only to reproduce bugs, is deleted within the same 12-month rolling window, and is never used for methodology analysis). Outcome-tracking rows are kept until they're resolved against price history and folded into aggregate methodology-accuracy reporting, at which point the individual row is deleted — we haven't built that resolution job yet, so today "kept until resolved" means indefinitely; a fixed maximum retention period will be set before this is offered beyond named testers.

Portfolio & Financial Data

Critical: We never collect or store your portfolio, holdings, income, net worth, or identity-linked research history. A tool call may pass our Worker the ticker you're researching and the numbers that tool needs to compute — but the Worker uses them to return a result and stores none of them, except the narrow, separately opt-in, identity-free exception described in "Outcome Tracking" above (see also "How the scoring engine works"). Your personal financial-planning figures never leave your Claude chat: the retirement-planning tools are designed to take only public market inputs (for example, the safe-withdrawal-rate tool takes the market CAPE, never your dollar figures — the arithmetic on your own numbers happens locally in your session). You see every input and output; we keep no record of what you own, and the only research record we ever keep — the ticker under Outcome Tracking — is never linked to you.

Data Use & Retention

Email addresses are used solely for:

• Onboarding sequences (post-purchase)
• Product updates and release notes
• Community announcements
• Support requests (if you contact us)

Concrete retention periods. We hold data only as long as needed for the purpose collected:

Email address & list data: retained until you unsubscribe or request deletion, then purged within 30 days (except where a longer period is required by law, e.g., tax/transaction records held by our Merchant of Record).
License-validation & call logs (hashed key, tool name, timestamp, latency, success/failure status; ticker on failed calls only): rolling 12 months, then deleted automatically by a daily job.
BYO API keys in Cloudflare KV: retained until you call DELETE /v1/keys or 90 days after your license lapses, whichever is first, then cryptographically destroyed.
Opt-in methodology telemetry: aggregated only, contains no personal identifiers; the monthly cohort salt is destroyed after rotation, making historical re-identification structurally impossible.
Opt-in outcome tracking: ticker + verdict + methodology version + date, with no license or identity linkage of any kind; retained to check verdicts against real price history, then aggregated into methodology-accuracy reporting.

You may request deletion at any time by unsubscribing or emailing hello@getharvestprotocol.com.

GDPR Rights (EU Residents)

If you are in the EU, you have the right to:

• Access the personal data we hold about you
• Request correction of inaccurate data
• Request deletion ("right to be forgotten")
• Request portability of your data
• Object to processing for marketing purposes

To exercise any of these rights, email hello@getharvestprotocol.com with "GDPR Request" in the subject line.

California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to:

Know / Access: request the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and any third parties with whom it is shared
Delete: request deletion of personal information we have collected from you
Correct: request correction of inaccurate personal information
Opt out of sale/sharing: see below
Limit use of sensitive personal information
Non-discrimination: we will not deny service, charge a different price, or provide a different quality of service because you exercised these rights

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not use or disclose sensitive personal information beyond the purposes permitted by the CPRA. Notice at collection: we collect your email address (to deliver the product, onboarding, updates, and support), payment data (processed solely by our Merchant of Record / payment processor — we never receive card data), and the limited technical license-validation and call-log data described above. A tool call may transiently pass our Worker the ticker you're researching and numbers a tool needs to compute (see "How the scoring engine works"), but we do not retain or store your portfolio, holdings, or financial data — the one narrow exception, described in "Outcome Tracking" above, retains only the ticker itself with no identity link, under a separate opt-in. We retain each category only for the periods stated in "Data Use & Retention" above.

To exercise any California right, email hello@getharvestprotocol.com with "California Privacy Request" in the subject line. We will acknowledge within 10 business days and respond within 45 calendar days (extendable once by 45 days with notice). You may use an authorized agent; we will verify your identity using the email associated with your account before responding.

Third Parties

Kit (formerly ConvertKit): Handles email list management. See their privacy policy at kit.com/privacy

Merchant of Record (payment processor): Processes payments and handles file delivery under their own privacy policy. We never receive your card data.

Cloudflare: Provides analytics and CDN services. See their privacy policy at cloudflare.com/en-gb/privacy/

Security

All data transmission uses HTTPS encryption. We store email addresses in encrypted form and restrict access to authorized personnel only. However, no online transmission is 100% secure — use strong passwords and enable two-factor authentication on your email and Claude accounts.

Contact

For privacy questions or to exercise your rights, email hello@getharvestprotocol.com with "Privacy Request" in the subject line.