Privacy Policy

Last Updated: August 12, 2026

Our Commitment to Your Privacy

At HarkenAI, we understand that your conversations, contacts, and business relationships are deeply personal and confidential. We are committed to protecting your privacy and handling your data with the utmost care and transparency.

🎙️ Recording Consent & Your Responsibility

Inform Participants: As a HarkenAI user, you are responsible for informing all participants before recording any conversation. Transparency builds trust and is the foundation of ethical recording.

Know Your Local Laws: Recording consent requirements vary by jurisdiction. Some areas require all-party consent (every participant must agree), while others require only one-party consent. We encourage you to familiarize yourself with the laws in your area.

Best Practice: We recommend always letting others know when you're recording, regardless of legal requirements. A simple "I'm using HarkenAI to take notes — is that okay with everyone?" goes a long way.

🔒 Data Security

Encryption: Your data is encrypted both in transit (TLS 1.3) and at rest (AES-256). Passwords are one-way hashed and never stored in plain text, and credentials for connected third-party accounts (such as Zoom or Notion) are protected with envelope encryption — AES-256-GCM keys wrapped by an AWS KMS customer-managed key that rotates automatically.

Secure Sign-In: Sign in with email verification, Google, or Sign in with Apple. Accounts lock automatically after repeated failed login attempts, session tokens rotate continuously with built-in reuse detection, and the mobile app supports Face ID / Touch ID for an extra layer of local protection.

Private Storage: Recordings, transcripts, and photos are stored in access-controlled cloud storage (AWS S3) that is never publicly reachable; playback and upload links are generated on demand and expire automatically after a short window. Structured data is stored in MongoDB Atlas with encryption at rest.

Access Control: At the application level, every request is scoped to your account — there is no cross-account access path. Our admin dashboard is limited to high-level status indicators (for example, whether a transcript exists), not the content of your conversations.

📊 What Data We Collect

Account Information: Email address, name, and authentication credentials.

Event Data: Event names, dates, and notes you create.

Location Data (if authorized): If you grant location permission, we collect location data when you record so events can be tagged with where conversations happened.

Audio Processing: We capture audio that you choose to record in order to transcribe it. Recorded audio is automatically deleted on a fixed retention schedule — raw audio segments within 28 days and full conversation recordings within 30 days — while your transcripts and insights remain available until you delete them.

Transcripts & AI Insights: Text transcriptions and AI-generated summaries, action items, and insights from your recordings.

Contact Information: Names, companies, roles, and other details about people you meet.

🤖 AI Processing & Third Parties

Deepgram: We use Deepgram's API to transcribe audio. Deepgram is SOC 2 compliant and does not retain your audio after processing.

OpenAI: We use OpenAI's API to generate insights. OpenAI does not use your data to train their models. Transcripts are processed securely and are not retained by OpenAI beyond the processing period.

AWS: We use Amazon Web Services for secure cloud storage. AWS complies with SOC 2, ISO 27001, and other security standards.

No Training on Your Data: We never use your conversations, recordings, or contacts to train AI models or for any purpose other than providing you with the service.

🗑️ Your Data, Your Control

Delete Anytime: You can delete individual recordings, events, contacts, or your entire account at any time. Deletion is permanent and irreversible.

Export Your Data: You can request a copy of all your data in a portable format.

Data Retention: We retain your data only as long as your account is active. Recorded audio is automatically removed on a fixed retention schedule — raw audio segments within 28 days and full conversation recordings within 30 days — enforced independently by both our application and our cloud storage, while transcripts and insights persist until you delete them. When you delete a conversation or your account, its audio, transcript, and related content are permanently removed from our systems.

🌍 Data Location

Your data is stored on secure servers in the United States. We comply with applicable data protection laws including GDPR and CCPA.

📧 How We Use Your Data

We use your data solely to provide and improve the HarkenAI service:

  • Transcribe your audio recordings
  • Generate AI insights and summaries
  • Help you manage contacts and follow-ups
  • Improve app functionality and user experience
  • Send you important service updates

We will never sell, rent, or share your personal data with third parties for marketing purposes.

👥 Sharing & Collaboration

Your data is private by default. We do not share your recordings, transcripts, or contacts with anyone unless you explicitly choose to do so through sharing features.

🔐 Administrative Access

HarkenAI administrators have technical access to backend systems, including databases and cloud storage where your data is stored. This access may be used for:

  • Troubleshooting technical issues
  • Providing customer support when requested
  • Responding to legal requirements
  • Ensuring service security and integrity

We do not routinely review, listen to, or read user recordings, transcripts, or personal data. Access is limited to what is necessary for the purposes described above.

🔔 Recording Consent

Your Responsibility: You are responsible for obtaining consent from all participants before recording conversations. Laws regarding recording consent vary by location. Please ensure you comply with applicable laws in your jurisdiction.

🛡️ Security Measures

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Envelope encryption (AWS KMS) for connected-account credentials
  • One-way hashed passwords — never stored in plain text
  • Automatic account lockout and session-token rotation with reuse detection
  • Face ID / Touch ID support on the mobile app
  • Per-account request scoping with no cross-account access path
  • Access-controlled storage that is never publicly reachable
  • Regular security updates and monitoring
  • Independently verified in a code-level security audit (August 2026)

📱 Children's Privacy

HarkenAI is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children.

🔄 Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by email or through the app. Your continued use of HarkenAI after changes constitutes acceptance of the updated policy.

📞 Contact Us

If you have questions about this privacy policy or how we handle your data, please contact us:

Email: privacy@harkenai.com

Website: www.harkenai.com

⚖️ Your Rights

Depending on your location, you may have the following rights:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data (right to be forgotten)
  • Export your data (data portability)
  • Object to data processing
  • Withdraw consent

To exercise these rights, please contact us at privacy@harkenai.com.

By using HarkenAI, you agree to this Privacy Policy and our Terms of Service.