Is Harvey safe with your data?
Harvey
Weak disclosure · high confidence
Harvey earns a D (46/100) because it leaves much about its data practices unstated.
#129
of 211 apps ranked
46
score · Legal avg 49
-3
vs category average
Harvey's global privacy policy is detailed on data categories, legal bases, sharing recipients and transfer safeguards, but it is silent on whether customer inputs train models, gives no retention numbers, and states its rights list only as conditional entitlements exercised by emailing the company.
What Harvey's privacy policy and terms of service say about your data
Two quoted passages were not Harvey's
The deletion quote ("the right to request that we delete personal data collected from you") and the de-identification quote ("We apply aggregation and de-identification techniques where appropriate as part of our data minimization practices") appear nowhere in Harvey's documents; both are Anthropic wording. Harvey's own text is weaker on each point.
Rights list is conditional, not a granted mechanism
Every right sits under one hedge: "Subject to certain exceptions and exemptions provided by law and where applicable, you may have the right to", exercised only by contacting the company at section 12. No portal, timeframe or named tool backs access, deletion, portability, correction or objection.
No shorter retention for AI logs
The service terms mention a workspace retention setting only to carve features out of it: "Your workspace retention setting will not apply to certain features, as outlined in our Documentation". No period or number appears anywhere, so this limits retention control rather than shortening it.
Nothing adverse is explicitly reserved
Harvey is silent on training with customer inputs rather than claiming the right, states "IP ownership ... is not impacted by its use in the Services" rather than taking a perpetual licence, and pairs its CCPA sale/share admission with a named opt-out ("Your Privacy Choices" plus Global Privacy Control), so no indicator is marked adverse.
What the policy is silent or vague on
- Not stated: keeping user inputs out of model training
- Not stated: a way to opt out of training
- Not stated: whether training use differs by plan
- Not stated: a deletion timeline after closure or request
Harvey privacy rating
Details
- Category
- Legal
- Modalities
- text
- Processes biometrics
- No
- Policy last updated
- 2026-07-13
- Region scored
- Global / US-default
- Last assessed
- 2026-08-13
Documents examined
Other legal apps
Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.