Legal

Privacy Policy

Last updated July 6, 2026

This policy explains what data Harpoon Performance ("Harpoon", "we") collects, how we use and protect it, and the choices you have. It covers our website, apps, and APIs.

1. What we collect#

  • Account information — your name, email, and (for social sign-in) the provider you used.
  • Billing information — handled by Stripe. We store a customer/subscription reference, not your full card number.
  • Performance captures (HAR files) — the network recordings you upload or we capture at your direction. These can contain URLs, request/response headers, cookies, tokens, and other personal data present in the captured session. Referred to as "captures" throughout this policy.
  • Capture artifacts — screenshots and step metadata from a capture run.
  • Credential vault secrets — any login credentials you save for authenticated capture, stored encrypted.
  • Operational metadata — request logs (without bodies), and AI usage records (token counts and cost — not the content of your data).
  • Anonymous results — if you analyze a page or a capture without an account, we store that result on our servers so you can return to it and claim it if you sign up. We also store a one-way hashed form of your IP address with it, which we use to investigate abuse of the free capture service. We do not store the raw IP alongside these results.

1a. Using Harpoon without an account#

You can analyze a page without signing up: paste a URL and we load it in a headless browser from our servers, or drop in a .har file you already have. Either way the result is stored on our servers — not only in your browser — so that a refresh doesn't lose it and so you can move it into a workspace if you later create an account.

  • The capture is deleted as soon as the analysis finishes, exactly as it is for an account. The anonymous result itself — the findings, score and timeline — is held for 7 days and then deleted automatically. Creating an account and claiming a result moves it into your workspace, where the normal retention rules in section 4 apply instead.
  • Access is by a secret link token generated for you and held in your browser. We store only a hash of that token, so we cannot re-issue it — if you clear your browser storage, the result becomes unreachable and is deleted at the end of the 7 days.
  • When we capture a URL you give us, our browser requests that page from our servers, not from your device. The page owner sees our request, not yours.
  • Anonymous results are never sent to the AI model — they get the deterministic explanation only.

2. How we use your capture data#

We store your captures so we can produce analyses and let you compare runs and track trends over time. Our deterministic engine derives performance findings from them entirely on our servers.

Only the engine's derived findings are ever sent to our AI subprocessor to generate plain-language explanations. Your captured cookies, tokens, headers, and page contents are not sent to the AI model.

3. AI processing#

To explain and prioritize findings, we send a curated, findings-only summary to OpenAI's API. We do not send raw capture data, credentials, or your account details. Data sent to OpenAI's API is not used to train their models. If AI processing is unavailable, Harpoon falls back to a deterministic report with no external call.

4. Retention & deletion#

  • Free tier shows only your most recent analyses; older runs are automatically set aside (their raw captures are deleted, the derived analysis is retained) and restored if you upgrade. Paid plans retain according to your plan.
  • Raw captures can hold personal data — URLs, and headers other than the credentials we strip on arrival — so we delete yours as soon as the analysis finishes, usually within seconds, on every plan. What we keep is the derived record: the findings, score, and request timeline (URLs, domains, sizes and timings). Comparing two runs uses that derived record, so any analysis stays a valid baseline for as long as you keep it.
  • You can delete an individual analysis, your whole organization, or your account at any time — this removes your data from our systems (backups are rotated on their own schedule).
  • Public share links are opt-in and revocable; revoking one takes the link offline.
  • Results created without an account are deleted 7 days after they are made, unless you claim them into an account first — see section 1a.

You can delete your organization or account from your account settings.

5. Capture credentials#

Credentials you save for authenticated capture are encrypted with AES-256-GCM and stored write-only — they are never displayed back to you or returned by our API, and are used only to replay the capture flow you configured. Captures are scrubbed of known secret values before storage.

6. How we share data#

We do not sell your data. We share it only with the subprocessors below (to run the Service), when you explicitly ask us to (e.g. connecting a repository or creating a public share link), or where required by law.

SubprocessorPurposeData shared
StripePayments & subscriptionsBilling contact & subscription data (no card numbers stored by us)
OpenAIAI explanations of findingsCurated engine findings only — never the raw capture
RailwayApplication hosting & databaseAll stored application data
ResendTransactional emailYour email address & message content
PostHog (EU)Product analytics (cookieless) & masked session replayAnonymous usage events (pageviews, funnel steps) and masked recordings of app layout & interaction — never capture content
Object storage (S3-compatible)Raw-capture backup storageYour uploaded/captured files

7. Security#

  • Data is encrypted in transit (HTTPS); vault secrets and connected-repo tokens are encrypted at rest with AES-256-GCM.
  • Every request is scoped to your organization; one organization cannot read another’s data.
  • Automated capture runs in a sandboxed, non-root browser with egress restrictions to reduce the blast radius of a malicious page.

8. Your rights#

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. You can export any analysis or comparison from the app, and delete your data yourself as described above. For anything else, contact us and we'll help.

9. Cookies#

We use only strictly-necessary cookies — the session cookie that keeps you signed in. We do not use advertising or cross-site tracking cookies, so there's no consent banner to click. Our product analytics (PostHog, EU) run cookieless — usage events are held in memory for the page session only and set no cookies or persistent local storage.

To understand how the app is actually used, we may record masked session replays. Page text and everything you type into a form are masked in your browser before anything is sent, so a replay shows layout and interaction — where a page was scrolled or clicked — and not the contents of your captures, your inputs, or the network requests the app makes. Replays are not recorded on shared-report links, and they set no additional cookies or persistent storage.

10. International transfers & changes#

Our subprocessors may process data in the United States and the EU. When we make material changes to this policy we'll update the date above. Continued use after a change means you accept the update.

11. Contact#

Questions or requests about your data? Get in touch. To report a security issue, see /.well-known/security.txt. This document is not legal advice; some specifics (legal entity, data-protection contact) are finalized as we complete our production launch.