Legal

Privacy Policy

Last updated September 23, 2026

This policy explains what data Harpoon ("we") collects, how we use and protect it, and the choices you have. It covers our website, application, APIs, Mend by Harpoon extension and Audit Helper.

1. What we collect#

  • Account information — your name, email, and (for social sign-in) the provider you used.
  • Billing information — handled by Stripe. We store a customer/subscription reference, not your full card number.
  • Performance captures (HAR files) — the network recordings you upload or we capture at your direction. These can contain URLs, request/response headers, cookies, tokens, and other personal data present in the captured session. Referred to as "captures" throughout this policy.
  • Capture artifacts — screenshots and step metadata from a capture run.
  • Accessibility evidence — when you save an extension audit or run a hosted scan, we store the audited URL, page title, timing, rule and severity, WCAG references, affected-element selectors, bounded HTML snippets, failure summaries and coverage status. Manual audits may also contain author-entered checks, findings and private screenshots.
  • Credential vault secrets — any login credentials you save for authenticated capture, stored encrypted.
  • Operational metadata — request logs (without bodies), and AI usage records (token counts and cost — not the content of your data).
  • Anonymous results — if you analyze a page or a capture without an account, we store that result on our servers so you can return to it and claim it if you sign up. We also store a one-way hashed form of your IP address with it, which we use to investigate abuse of the free capture service. We do not store the raw IP alongside these results.

1a. Using Harpoon without an account#

You can analyze a page without signing up: paste a URL and we load it in a headless browser from our servers, or drop in a .har file you already have. Either way the result is stored on our servers — not only in your browser — so that a refresh doesn't lose it and so you can move it into a workspace if you later create an account.

  • The capture is deleted as soon as the analysis finishes, exactly as it is for an account. The anonymous result itself — the findings, score and timeline — is held for 7 days and then deleted automatically. Creating an account and claiming a result moves it into your workspace, where the normal retention rules in section 4 apply instead.
  • Access is by a secret link token generated for you and held in your browser. We store only a hash of that token, so we cannot re-issue it — if you clear your browser storage, the result becomes unreachable and is deleted at the end of the 7 days.
  • When we capture a URL you give us, our browser requests that page from our servers, not from your device. The page owner sees our request, not yours.
  • Anonymous results are never sent to the AI model — they get the deterministic explanation only.

1b. Mend by Harpoon extension#

Mend audits the page you choose in your browser. No Harpoon account is needed for a local audit. The extension keeps settings on your device and caches the current audit for the browser session. A local audit does not upload page content or results to Harpoon.

  • If you connect a Harpoon website project, completed audits can be saved to that project. The extension sends the page URL and title, timing, rules and affected-element evidence described above over HTTPS. Auto-save can be switched off, so uploads happen only when you choose Save.
  • The extension can use an endpoint you configure instead of Harpoon. In that case, uploads go to that endpoint under its own data practices; reconnecting a former Mend account to Harpoon is an explicit action.
  • Optional all-sites access is requested through Chrome only if you choose that setting. It lets you audit multiple tabs without invoking the extension on each tab; it does not start background browsing or upload audits by itself.

Our use of information received from Chrome APIs follows the Chrome Web Store User Data Policy, including its Limited Use requirements. We use that information to provide the local audit and optional project save you choose, not for advertising or sale.

2. How we use your capture data#

We store your captures so we can produce analyses and let you compare runs and track trends over time. Our deterministic engine derives performance findings from them entirely on our servers.

Only the engine's derived findings are ever sent to our AI subprocessor to generate plain-language explanations. Your captured cookies, tokens, headers, and page contents are not sent to the AI model.

3. AI processing#

To explain and prioritize findings, we send a curated, findings-only summary to OpenAI's API. We do not send raw capture data, credentials, or your account details. Accessibility evidence is processed deterministically and is not sent to the AI model. Data sent to OpenAI's API is not used to train their models. If AI processing is unavailable, Harpoon falls back to a deterministic report with no external call.

4. Retention & deletion#

  • New saved Performance and Accessibility results are limited to 200 per product and retained for 30 days on Free, or 5,000 per product and retained for 365 days on Premium. The retention policy is prospective; it does not immediately delete older results created before the policy took effect.
  • Raw captures can hold personal data — URLs, and headers other than the credentials we strip on arrival — so we delete yours as soon as the analysis finishes, usually within seconds, on every plan. What we keep is the derived record: the findings, score, and request timeline (URLs, domains, sizes and timings). Comparing two runs uses that derived record, so any analysis stays a valid baseline for as long as you keep it.
  • You can delete an individual result, your whole organization, or your account at any time — this removes your data from our systems (backups are rotated on their own schedule). Private Accessibility evidence and screenshots follow the result lifecycle; object cleanup may finish after access has been removed.
  • Public share links are opt-in and revocable; revoking one takes the link offline.
  • Results created without an account are deleted 7 days after they are made, unless you claim them into an account first — see section 1a.

You can delete your organization or account from your account settings.

5. Capture credentials#

Credentials you save for authenticated capture are encrypted with AES-256-GCM and stored write-only — they are never displayed back to you or returned by our API, and are used only to replay the capture flow you configured. Captures are scrubbed of known secret values before storage.

6. How we share data#

We do not sell your data. We share it only with the subprocessors below (to run the Service), when you explicitly ask us to (e.g. connecting a repository or creating a public share link), or where required by law.

SubprocessorPurposeData shared
StripePayments & subscriptionsBilling contact & subscription data (no card numbers stored by us)
OpenAIAI explanations of findingsCurated engine findings only — never the raw capture
RailwayApplication hosting & databaseAll stored application data
ResendTransactional emailYour email address & message content
PostHog (EU)Product analytics (cookieless) & masked session replayAnonymous usage events (pageviews, funnel steps) and masked recordings of app layout & interaction — never capture content
Object storage (S3-compatible)Capture and private evidence storageYour uploaded/captured files and manual-audit screenshots

7. Security#

  • Data is encrypted in transit (HTTPS); vault secrets and connected-repo tokens are encrypted at rest with AES-256-GCM.
  • Every request is scoped to your organization; one organization cannot read another’s data.
  • Automated capture runs in a sandboxed, non-root browser with egress restrictions to reduce the blast radius of a malicious page.

8. Your rights#

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. You can export any analysis or comparison from the app, and delete your data yourself as described above. For anything else, contact us and we'll help.

9. Cookies#

We use only strictly-necessary cookies — the session cookie that keeps you signed in. We do not use advertising or cross-site tracking cookies, so there's no consent banner to click. Our product analytics (PostHog, EU) run cookieless — usage events are held in memory for the page session only and set no cookies or persistent local storage.

To understand how the app is actually used, we may record masked session replays. Page text and everything you type into a form are masked in your browser before anything is sent, so a replay shows layout and interaction — where a page was scrolled or clicked — and not the contents of your captures, your inputs, or the network requests the app makes. Replays are not recorded on shared-report links, and they set no additional cookies or persistent storage.

10. International transfers & changes#

Our subprocessors may process data in the United States and the EU. When we make material changes to this policy we'll update the date above. Continued use after a change means you accept the update.

11. Contact#

Questions or requests about your data? Get in touch. To report a security issue, see /.well-known/security.txt. This document is not legal advice; some specifics (legal entity, data-protection contact) are finalized as we complete our production launch.