All apps

Is Harvey safe with your data?

D
Harvey icon

Harvey

46/100

Weak disclosure · high confidence

Harvey earns a D (46/100) because it leaves much about its data practices unstated.

#129

of 211 apps ranked

46

score · Legal avg 49

-3

vs category average

Grade scaleA · 70–100B · 60–69C · 48–59D · 35–47F · 0–34

Harvey's global privacy policy is detailed on data categories, legal bases, sharing recipients and transfer safeguards, but it is silent on whether customer inputs train models, gives no retention numbers, and states its rights list only as conditional entitlements exercised by emailing the company.

What Harvey's privacy policy and terms of service say about your data

Two quoted passages were not Harvey's

The deletion quote ("the right to request that we delete personal data collected from you") and the de-identification quote ("We apply aggregation and de-identification techniques where appropriate as part of our data minimization practices") appear nowhere in Harvey's documents; both are Anthropic wording. Harvey's own text is weaker on each point.

Rights list is conditional, not a granted mechanism

Every right sits under one hedge: "Subject to certain exceptions and exemptions provided by law and where applicable, you may have the right to", exercised only by contacting the company at section 12. No portal, timeframe or named tool backs access, deletion, portability, correction or objection.

No shorter retention for AI logs

The service terms mention a workspace retention setting only to carve features out of it: "Your workspace retention setting will not apply to certain features, as outlined in our Documentation". No period or number appears anywhere, so this limits retention control rather than shortening it.

Nothing adverse is explicitly reserved

Harvey is silent on training with customer inputs rather than claiming the right, states "IP ownership ... is not impacted by its use in the Services" rather than taking a perpetual licence, and pairs its CCPA sale/share admission with a named opt-out ("Your Privacy Choices" plus Global Privacy Control), so no indicator is marked adverse.

What the policy is silent or vague on

  • Not stated: keeping user inputs out of model training
  • Not stated: a way to opt out of training
  • Not stated: whether training use differs by plan
  • Not stated: a deletion timeline after closure or request

Harvey privacy rating

Training-data use0 of 4 disclosed
Keeps user inputs out of model training, or makes training opt-inSilent
Names a way to opt out of or into trainingSilent
Says whether training use differs by plan or tierSilent
Lets the user keep ownership of generated outputsPartial
Data-subject rights0 of 5 disclosed
Grants a right to access your dataPartial
Grants a right to delete your dataPartial
Offers data portability in a usable formatPartial
Grants a right to correct your dataPartial
Grants a way to object to or opt out of processingPartial
Retention and deletion0 of 4 disclosed
States a retention period for your dataPartial
States a deletion timeline after closure or requestSilent
Sets a shorter retention for AI conversation logsSilent
Commits to collecting only the data it needsPartial
Third-party sharing3 of 5 disclosed
Lists the categories of third parties it shares withDisclosed
References a sub-processor list or data processing agreementDisclosed
Does not sell or share data for advertising, or offers opt-outPartial
Names a safeguard for international data transfersDisclosed
States a standard for government and law-enforcement accessPartial
Transparency2 of 4 disclosed
Discloses that you are interacting with AIPartial
Marks AI-generated or synthetic outputNot applicable
Enumerates the categories of data it collectsDisclosed
Maps processing purposes to legal basesDisclosed
Is versioned and dated, with change noticePartial
Sensitive data and children1 of 3 disclosed
Discloses automated decisions and a human-review pathPartial
Limits the use of special-category dataPartial
Governs biometric data specificallyNot applicable
States protections for children's dataDisclosed
Security and accountability1 of 3 disclosed
Describes its security safeguardsPartial
Commits to breach notificationSilent
Names a certification or a privacy contactDisclosed
DisclosedPartialSilentAdverseNot applicable

Details

Category
Legal
Modalities
text
Processes biometrics
No
Policy last updated
2026-07-13
Region scored
Global / US-default
Last assessed
2026-08-13

Documents examined

Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.

Is Harvey safe with your data? Grade D | AI App Trust & Transparency Index