Legal

Privacy Policy

Last updated: June 15, 2026

This document is a general description of our privacy practices and does not constitute legal advice. Its final wording is subject to legal review.

At TheNodeHarbor we deeply value the privacy of your corporate and personal information. This Privacy Policy describes how we collect, use, and protect information through our home page (thenodeharbor.com) and our application (app.thenodeharbor.com).

1. Information we collect

TheNodeHarbor works as an intelligence engine that processes user-authorized interactions. We collect and process the following:

  • Voice notes and meeting audio: audio files streamed through our WebSocket server or recorded from our in-person recording PWA, for transcription and speaker identification.
  • WhatsApp messages: chats, images, and voice notes from the WhatsApp account you link by scanning a QR code.
  • Email content (Gmail): subjects, body, and basic metadata of emails obtained under the authorized permissions.
  • GitHub data: repository events, pull requests, issues, and comments sent via GitHub webhooks.

2. How we use your information

All captured information is used exclusively to:

  • Clean out noise and transcribe/identify speakers in recordings.
  • Split the information into vector chunks and index it securely in PostgreSQL with per-company isolation (Row-Level Security).
  • Extract tasks and actions using language models (LLMs).
  • Present the extracted tasks on an internal board (Kanban) for your review, approval, or dismissal (human in the loop).

3. Data retention and deletion

  • Raw audio: unprocessed audio files are automatically deleted from our servers approximately 48 hours after they are received.
  • Processed audio (transcription): audio converted for transcription is kept for up to 30 daysand then deleted automatically. The media is stored on our servers' disk (not in publicly accessible third-party storage).
  • History deletion: text interactions and their vector indexes are stored encrypted and isolated per company. You can request or execute the immediate deletion of any project or record at any time.

4. Compliance with Google API data policies

Limited Use disclosure

TheNodeHarbor's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell, transfer, or share your Gmail data with advertisers, ad platforms, or data brokers.

5. Data security

We implement robust security measures to protect your data against unauthorized access, alteration, or destruction. This includes row-level security (RLS) policies in the database, SSL encryption in transit for all web and WebSocket requests, and signature- or token-based authentication on incoming webhooks.

6. Contact

If you have questions about this Privacy Policy or wish to request the deletion of your information, write to us at: legal@thenodeharbor.com.