harness

privacy

Effective 31 July 2026

the short version

  • Screen capture, indexing, and history search happen on your device. In standard and private modes, selected evidence and a compact, expiring text/audio change log can transit Harness to keep the answer current.
  • Your memory database lives on your device. Relevant snippets can enter a turn you request; backup gives us only an encrypted copy we can't read.
  • Your conversations live on your device too. We keep a short summary and a recent copy on our servers so things work across your devices, but after about a month we keep only the summary — your device stays the real record.
  • You can delete any of this, or all of it, at any time.
  • Analytics are anonymous. We never connect them to your account.

1who we are

Harness is an independent project, not a registered company. It is run by the people building it, and it does not have a corporate entity behind it today. If that changes, this page changes with it.

For anything in this policy, including access and deletion requests, reach us on our Discord.

2what stays on your device

  • Reading your screen. Capture, OCR, image recognition, indexing, and history search happen in your browser. If you choose a remote answering model, the selected current or recalled frame or crop for that turn leaves the device.
  • A short buffer of what you recently shared. So you can ask about something you scrolled past a minute ago. Held on your device only.
  • Your memory. What Harness learns about you over time, like your preferences and the thread of your work, lives in a database on your own device.
  • Your own AI provider keys, if you use them, are stored in your browser. A hosted turn sends the relevant key to Harness in the request so the server can call that provider; Harness does not persist it.

3what leaves your device

When you send a message, your device puts together only what's needed to answer it, and sends that. Specifically:

  • Your message, and any file you attach.
  • Selected screen evidence. This can be a current frame or crop while you're sharing, or a recalled historical frame from local screen history. Harness can only capture the tab, window, or screen you chose, and live capture stops the instant you stop sharing.
  • A compact text log of recent screen changes (and audio transcript segments, if the shared tab has sound), so answers stay relevant between screenshots. In standard and private modes this working ledger transits Harness, is held in memory rather than written as durable screen history, and is discarded automatically within the hour. Confidential mode keeps it on your device.
  • Anything from your memory that's actually relevant to your question.

4what we store on our servers

  • Account. Your email address, and a name or photo if you add one.
  • A copy of recent messages, plus each conversation's title and a short summary. This supports recent chat continuity and search; the full conversation lives on your device. We drop the message copy after about a month; only the title and summary stay.
  • Profile. A short summary Harness keeps of how you like to work, used to shape its replies.
  • Writing samples. Messages you've sent, so Harness can match your voice when it drafts something for you. Deletable anytime.
  • Billing. Your subscription and payment history. Stripe handles your card details directly; we never see them.
  • Encrypted backup, if you turn it on. A sealed copy of your memory and conversations, so they survive a lost device and follow you to a new one. We store it, but can't read it. Only you hold the key, and if you lose it, neither can we recover it.
  • Background tasks. If you ask Harness to keep working after you close the window, or to delegate something, we keep the instructions and results so they're there when you come back.
  • Short-lived technical logs, used for billing and to keep things running smoothly, like basic connection and usage records. These don't contain what you said, and are deleted automatically within days.

5how private you want to be

Harness never trains AI models on your data. You choose how your requests are handled, in settings:

  • Standard. The default. Gets you the best available AI, including major closed models — the provider sees your message to answer it, but not who you are.
  • Private. Skips closed AI models entirely, using only open models from providers who commit to not keeping your data.
  • Most private. Uses AI running in specially secured, verified environments. The compact screen ledger stays on your device, and web search plus general-purpose tools are switched off. If explicitly enabled, a separately requested work-pattern audit can use an approved end-to-end encrypted route.

For Standard and Private requests, we often use a routing service to find an available AI provider; it can see the request on its way to that provider. It never sees anything in Most private mode.

6venice powers frontier ai

When you use a frontier model, meaning one of the large, closed AI models rather than an open or on-device one, your request runs through Venice, the AI infrastructure Harness is built on. Your message, and your screen content while you're sharing, go to Venice to produce the answer. Venice doesn't receive your name, your email, or anything that identifies your account, only the request itself.

Prefer to avoid frontier models entirely? Choose Private or Most private in settings.

7analytics

Analytics are anonymous by construction, not by promise. An event can never be attached to your account, your email, or your name. We don't record your screen or the interface, don't collect the text of things you click, and don't capture error messages automatically, since those can carry data we don't want. What remains is simple counts: pages viewed, buttons clicked, how long a reply took.

8cookies

  • Sign-in. Keeps you signed in. Can't be read by page scripts.
  • Guest. If you try Harness without an account, lasts seven days so your trial conversation survives a refresh. Cleared when you create an account.
  • Analytics. Avoids counting one person as many. Not linked to your account.

We don't use advertising cookies, and we don't sell data.

9trying harness without an account

Guest conversations are handled the same way signed-in ones are. To stop automated abuse of free usage, we record the IP address a guest session was created from, along with a daily count. If you later create an account, your guest conversation moves onto it.

10your controls

  • Delete your account and everything in it, from settings. One operation, and it can't be undone.
  • Delete a single conversation, at any time, from the interface.
  • Delete your encrypted backup and its history.
  • Delete your writing samples.
  • Wipe local data by clearing site data in your browser, which removes your on-device memory and screen buffer.
  • Turn off screen sharing at any time, which stops all capture immediately.

For anything you can't do yourself, ask on our Discord and we'll action it.

11how long we keep things

Your conversation titles and summaries are kept until you delete them or your account. The messages themselves are kept for about a month, then only the summary remains. Live screen and audio context is discarded within the hour. Technical logs are deleted within days. Guest sessions last seven days. Backups persist until you delete them.

12security

Traffic is encrypted in transit, and your data is kept separate per account in our systems. Encrypted backups are sealed on your device with strong encryption (AES-256) before they're ever sent to us, using a key made from your passphrase, which we never see.

No system is perfectly secure, and we won't claim otherwise. If you find a vulnerability, please tell us on our Discord.

13children

Harness is not intended for anyone under 13, and we do not knowingly collect their data.

14changes

When this policy changes materially, we'll update the effective date and say so in the product.

back to harness