Legal

Privacy Policy

How Harvest collects, uses, and protects your data.

Effective: June 12, 2026 · Version 2.0 · Joe@harvest-app.net
01

Information We Collect

We collect information needed to operate Harvest and support real estate prospecting workflows.
  • Account and profile info: name, email, phone number, brokerage, agent profile, business or brokerage mailing address, signature block, and license or jurisdiction information if collected or provided.
  • Team and workspace data: teams, members, roles, invites, workspace settings, visibility settings, plan or entitlement status, and team activity.
  • Listing, property, and farm data: listing addresses, property details, farm boundaries, nearby homeowner records, lead status, notes, dispositions, call outcomes, follow-up tasks, exports, and related audit history.
  • Homeowner and prospecting data: names, property addresses, mailing addresses, phone numbers, emails, property attributes, ownership signals, estimated values, DNC or suppression flags where applicable, and provider match information.
  • Campaign and suppression records: generated copy, campaign records, exported recipient lists, unsubscribes, opt-outs, do-not-contact flags, and suppression records.
  • AI inputs and outputs: prompts, listing/contact context, notes, scripts, emails, texts, summaries, transcripts, and other information needed to fulfill user-triggered AI features.
  • Usage and purchase information: device type, OS version, app version, diagnostics, crash logs, usage events, and Apple-provided purchase transaction identifiers. We never see your payment card number.

Third-party contact, skip-trace, property, and homeowner data may be inaccurate, incomplete, outdated, or misattributed. Users should verify contact and property information before relying on it.

02

Sources & Device Permissions

We collect information from users, team members, service providers, public/property records, Apple, and user-triggered AI providers.

We collect information directly from you when you create an account, complete your profile, set up a team, upload or enter listings, import contacts, create farms, write notes, generate drafts, export data, contact support, or otherwise use Harvest.

We may receive information from team members or administrators, public and property records, third-party property/contact/skip-trace providers, service providers, Apple, authentication providers, email providers, diagnostics providers, and AI providers when you trigger AI features.

Device permissions are optional and controlled by your device settings. Harvest requests permissions only when a feature needs them.

📍 Location
To show your current farm on the map and recommend nearby neighborhoods. You can revoke this anytime in iOS Settings → Privacy & Security → Location Services.
👤 Contacts
Only when you tap "Save to Contacts" or "Import contacts into farm." Harvest reads only the contacts you select. It does not upload your address book in the background.
📷 Camera
Only when you pick or take a profile photo, or attach a photo to a lead note.
🎤 Microphone
Only when you tap "Record voice recap" or another voice feature. Audio may be sent to supported transcription or AI providers to fulfill the feature, and transcripts or summaries may be saved according to the app workflow.
🔔 Notifications
To alert you when a hot lead lands, a callback comes due, or a teammate touches a contact. Disable anytime in iOS Settings → Notifications → Harvest.
03

How We Use Your Information

We use information to operate Harvest, keep workspaces separate, prepare drafts and follow-ups, apply suppression controls, secure the service, and process App Store purchases.
  • Create farms around listings, properties, and nearby homeowner opportunities.
  • Identify property context and organize homeowner, lead, and follow-up workflows.
  • Generate user-triggered scripts, texts, emails, campaign copy, summaries, and follow-up drafts.
  • Maintain team separation, permissions, activity reporting, and workspace audit history.
  • Apply opt-out, unsubscribe, DNC, do-not-contact, and suppression controls where available.
  • Process App Store purchase status, send transactional messages, troubleshoot issues, prevent abuse, and secure the service.
Harvest does not sell customer data. Harvest does not use customer data to train Harvest-owned general AI models.
04

AI Processing

AI features are user-triggered. Relevant listing, contact, note, audio, transcript, team, or account context may be sent to supported AI providers to fulfill the requested feature.

When you generate a follow-up message, post-call summary, campaign draft, text, email, or calling script, Harvest may send the relevant context needed to supported third-party AI providers solely to fulfill that request.

Harvest does not sell customer data and does not use customer data to train Harvest-owned general AI models. We configure supported AI providers, where available, to process customer data for the requested feature and not to train their public models. Third-party AI providers process data under their applicable terms and data-processing commitments.

AI output may be wrong, incomplete, outdated, biased, or unsuitable. Users should not enter unnecessary sensitive information and must review AI output before use.

05

Sharing

We share information with service providers that help us operate Harvest and with legal or safety authorities when required.
Supabase
Database, authentication, and file storage.
Apple
App Store payments, push notifications, and sign-in.
Anthropic & OpenAI
For user-triggered AI, transcription, summaries, scripts, and draft assistance.
Resend
To send transactional emails only.
Sentry
Crash reporting and diagnostics to improve the app.
Property, contact, and skip-trace providers
To provide property context, homeowner records, contact data, match information, and suppression signals where available.

We may also disclose information when required by law, court order, or to protect the rights and safety of Harvest, our users, or the public.

Harvest does not sell customer data for money and, based on the current launch implementation, does not share personal information for cross-context behavioral advertising.
06

Retention

We retain information as needed to provide Harvest, honor suppression requests, secure the service, and meet legal, tax, audit, and abuse-prevention obligations.
  • Account data is retained while your account is active.
  • If you delete your account (Settings → Account & Security → Delete my account), we remove or de-identify account data within a reasonable period, except where retention is needed for legal, tax, audit, payment, backup, security, fraud-prevention, abuse-prevention, or dispute-resolution purposes.
  • Team workspace data may remain available to a team, brokerage, or administrator where appropriate.
  • Suppression, unsubscribe, opt-out, and do-not-contact records may be retained as needed to honor those requests.
  • Raw audio, transcripts, or summaries are retained according to the feature behavior and user/team settings available in the app, subject to backup, audit, legal, and security retention.
07

Your Rights

You may export, delete, correct, or request help with privacy, suppression, unsubscribe, or homeowner contact records.
Export
Settings → Account & Security → Export my data
Delete
Settings → Account & Security → Delete my account
Change email
Settings → Account & Security → Change email
Other
Email Joe@harvest-app.net for access, correction, privacy requests, unsubscribe requests, or homeowner/contact suppression requests.

Residents of certain jurisdictions, including California and other U.S. states, may have additional privacy rights. If you use Harvest as part of a team, some workspace data may be controlled by your team, brokerage, or administrator.

08

California Privacy Rights (CCPA / CPRA)

California and certain state residents may request access, deletion, correction, portability, or opt-out of certain sale, sharing, targeted advertising, or profiling activities.

If you are a California resident, you have the right to:

  • Know what personal information we collect about you.
  • Request deletion of your personal information.
  • Correct inaccurate personal information.
  • Opt out of certain sale, sharing, targeted advertising, or profiling activities where applicable.
  • Limit certain uses of sensitive personal information where applicable.

The categories of information we may collect include identifiers, account/profile information, commercial information, internet or device activity, geolocation information if you grant location permission, audio information if you use voice features, professional information, inferences or product analytics, and property/contact/prospecting information. Sources and purposes are described above.

Harvest does not sell personal information for money and, based on the current launch implementation, does not share personal information for cross-context behavioral advertising.

To exercise these rights, email Joe@harvest-app.net. We will respond within 45 days. We will not discriminate against you for exercising your rights.

09

EU / UK Privacy Rights (GDPR)

Individuals in the EU, UK, and Switzerland have data-protection rights under the GDPR and applicable national law.

If you are in the European Economic Area, United Kingdom, or Switzerland, you have the right to:

  • Access your personal data.
  • Request rectification or erasure.
  • Restrict or object to certain processing.
  • Data portability.
  • Withdraw consent at any time.
  • Lodge a complaint with your local supervisory authority.

The legal bases on which we process your data:

  • Contract: to provide the service you signed up for.
  • Legitimate interest: to improve, secure, and protect the service.
  • Consent: for optional features you explicitly enable, such as AI summaries, location, and notifications.
  • Legal obligation: when required by law.

To exercise any GDPR right, email Joe@harvest-app.net.

10

Security

Encrypted in transit and at rest. We follow standard industry practices.
  • All data is encrypted in transit using HTTPS / TLS.
  • Data at rest is encrypted by our infrastructure providers (Supabase, Apple).
  • Authentication is handled by Supabase Auth with industry-standard password hashing.
  • We review the security practices of our infrastructure providers annually.
  • No system is perfectly secure. Use a strong, unique password and enable device-level biometrics.

If you discover a security vulnerability, email Joe@harvest-app.net. We review responsible reports and may follow up for additional detail.

11

Children's Privacy

Harvest is for licensed real estate professionals. The Service is not directed to children under 13.

Harvest is a business tool for licensed real estate professionals and is not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children under 13. If you believe a child has provided data to Harvest, email Joe@harvest-app.net and we will delete it promptly.

12

International Data Transfers

Your data may be stored on US servers. We rely on Standard Contractual Clauses where required.

Harvest's primary infrastructure (Supabase, Anthropic, OpenAI, and Resend) operates from the United States. If you are in the EU or UK, your data may be transferred to and processed in the US. Where required by law, we rely on Standard Contractual Clauses approved by the European Commission and the UK ICO.

13

Changes to This Policy

Material changes will be communicated in-app or by email at least 7 days before they take effect.

We may update this Privacy Policy from time to time. Material changes will be announced in-app or by email at least 7 days before they take effect. The "Effective" date at the top of this page always reflects the latest revision.

14

Contact

Direct privacy, legal, support, security, suppression, unsubscribe, and accessibility requests to Joe@harvest-app.net.
Address
Mailing address available upon request. Email Joe@harvest-app.net
International

Still have questions?

Send privacy, suppression, unsubscribe, legal, or security requests to the contact email below.

Email Joe@harvest-app.net