Privacy
Last updated: 21 September 2026
Harry works by reading and writing your team’s working conversation, so it is worth being exact about what that means. This page says what we hold, why we hold it, and how to make us stop.
Who we are
Harry is an AI project-manager assistant operated by the team behind getharry.app. For anything on this page, including access and deletion requests, write to privacy@getharry.app.
What we collect
We hold five kinds of data, and nothing else:
- A copy of your CRM’s data, if you connected one: deals, leads, contacts, funnels, activities and client conversations — and the access key to it, stored encrypted and never shown back.
- The messages you exchange with Harry — text, voice notes and files you send him, plus his replies.
- Your messenger identity — the account id, display name and language your messenger reports. We key everything internally on our own person id, not on that handle.
- The working record your organisation builds: tasks, goals, reminders, people and reporting lines.
- Operational logs — timestamps, error traces and job records needed to run and debug the service.
Why we process it
To run the service you asked for: answering questions, keeping the record, sending reminders and following up on work.
To keep it working and safe: diagnosing failures, preventing abuse, and meeting legal obligations where they apply.
Large language models
Producing a reply means sending the relevant part of the conversation, and the records it touches, to our language-model provider. The provider processes it on our behalf under contract, and does not use it to train models.
Voice notes are transcribed by the same route. Images and documents you send are read the same way when a request needs them.
Where it lives
One Postgres database that we operate holds the CRM copy, the working record, the conversation history and the job queue. Files you send are stored in an object store; the database keeps only a reference to them.
Separation between organisations is enforced by row-level security inside Postgres, so an application bug above it cannot expose one organisation to another.
Who can reach it
Three groups, and no others:
- People in your organisation, scoped by their role — an admin sees the organisation, everyone else sees themselves and the people who report to them.
- Our operators, for support and diagnosis, through an audited console.
- Our infrastructure and language-model providers, strictly as processors.
What we never do
We do not sell your data, we do not use it for advertising, and we do not share one organisation with another.
How long we keep it
For as long as your organisation uses the service, plus a short window afterwards for backups to roll over. Ask us to delete an organisation and we delete it, including its conversation history.
Your choices
You can stop Harry at any time by blocking the bot in your messenger. You can ask for a copy of your organisation’s data, or its deletion, at privacy@getharry.app.
The messenger you reach Harry through is a separate service with its own privacy policy; this page covers what happens on our side of that conversation.
Changes to this page
When this policy changes we update the date at the top. Material changes are announced in the chat, not only here.