Privacy Policy - Harker
Last Updated and Effective Date: 17th March 2026
1. Introduction
This Privacy Policy describes how Ourfires Ltd ("we," "us," or "our") collects, uses, and protects your information when you use our Harker application and website (collectively, the "Service"). Harker is a voice-to-text transcription application that processes your voice locally on your device, with optional AI-powered text transformation features.
Contact Information:
- Company: Ourfires Ltd
- Location: London, United Kingdom
- Email: support@getharker.com
2. Information We Collect
2.1 Account Information
When you create a Harker account, we collect:
- Email Address: Used for authentication (magic link sign-in), account management, and communications about the Service.
- Authentication Tokens: Session tokens stored in cookies to keep you signed in.
2.2 Subscription and Payment Information
When you subscribe to Harker Premium, payment processing is handled entirely by Stripe. We do not store or have access to your payment card details. We receive from Stripe:
- Your email address
- Subscription status (active, canceled, etc.)
- Stripe customer and subscription identifiers
2.3 Automatically Collected Information
We use PostHog analytics to collect:
- Technical Data: Device information, operating system, browser type, and version
- Usage Data: How you interact with our application and website (anonymized)
- Error Logs: Technical information when errors occur to help us improve the Service
2.4 Voice Data — Important Privacy Protection
Your voice recordings never leave your device. Harker processes all voice-to-text transcription locally on your computer using AI models that run entirely on your hardware. We do not collect, store, transmit, or have access to any voice recordings or transcribed text.
2.5 AI Text Transformation
If you use Harker Premium's AI text transformation features, your transcribed text is sent to our servers for processing (e.g., formatting, summarisation, or rephrasing). This text is processed in real time and is not stored on our servers. We do not retain, log, or use your text content for training or any other purpose beyond fulfilling the transformation request.
3. How We Use Your Information
We use the collected information for the following purposes:
- Authentication: To verify your identity and manage your account session
- Subscription Management: To manage your Premium subscription status and entitlements
- Product Updates: To send you notifications about Harker updates and new features (if you opted in)
- Service Improvement: To analyse usage patterns and fix technical issues
- Error Resolution: To identify and resolve bugs and technical problems
- Legal Compliance: To comply with applicable laws and regulations
4. Cookies and Session Data
We use cookies for the following purposes:
- Authentication Cookies: To maintain your signed-in session across page visits. These are essential for account functionality.
- Analytics Cookies: PostHog uses cookies to collect anonymised usage data.
You can manage cookie preferences through your browser settings. Disabling authentication cookies will require you to sign in again on each visit.
5. Information Sharing and Disclosure
5.1 Third-Party Service Providers
- PostHog: Analytics data is processed by PostHog and stored on their European servers. PostHog is GDPR-compliant and provides data anonymisation. Learn more at posthog.com/privacy
- Stripe: Subscription and payment processing is handled by Stripe. We do not store your payment details. Review Stripe's privacy policy at stripe.com/privacy
- Supabase: Account authentication and session management is handled by Supabase. Learn more at supabase.com/privacy
- AI Providers: Text transformation requests are processed by third-party AI providers (e.g., Anthropic). Only the text content is sent — no personal information is included. Text is not stored or used for training.
5.2 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing or any other purposes.
5.3 Legal Requirements
We may disclose your information if required by law, court order, or to protect our rights, safety, or the safety of others.
6. Data Storage and Security
- Location: Analytics data is stored on PostHog's European servers. Account data is stored on Supabase's infrastructure.
- Security: We implement appropriate technical and organisational measures to protect your information, including encrypted connections (HTTPS) and secure authentication flows.
- Local Processing: All voice processing happens locally on your device and is never transmitted.
- AI Processing: Text sent for AI transformation is processed in real time and is not stored.
7. Your Rights and Choices
7.1 GDPR Rights (EU Users)
If you are in the European Union, you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your personal data and account
- Portability: Request transfer of your data
- Objection: Object to processing of your data
- Restriction: Request restriction of processing
7.2 CCPA Rights (California Users)
If you are a California resident, you have the right to:
- Know what personal information we collect and how we use it
- Request deletion of your personal information
- Opt out of the sale of personal information (note: we do not sell personal information)
7.3 How to Exercise Your Rights
- Account Deletion: Contact us to delete your account and all associated data
- Email Deletion: Contact us to remove your email from our communications
- Data Requests: Email us at support@getharker.com for any privacy-related requests
- Analytics Opt-Out: We are implementing an opt-out feature for analytics — will be available soon
8. Children's Privacy
Harker is suitable for all ages. We do not knowingly collect personal information from children under 13 without parental consent. If we discover we have collected information from a child under 13, we will delete it promptly. Parents or guardians may contact us to request deletion of their child's information.
9. International Data Transfers
Since we use PostHog's European servers and Supabase infrastructure, and you may use Harker from various countries, your data may be transferred internationally. All transfers comply with applicable data protection laws, including GDPR.
10. Data Retention
- Account Data: Your email and account information are retained for as long as your account is active. You may request deletion at any time by contacting us.
- Subscription Data: Billing records are retained as required by applicable tax and accounting laws (typically 7 years).
- Analytics Data: Retained according to PostHog's data retention policies
- Voice Data: Never stored — processed locally and immediately discarded
- AI Transformation Text: Never stored — processed in real time and immediately discarded
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by:
- Posting the updated policy on our website
- Sending an email notification (if you provided your email address)
- Including a notification in the Harker application
12. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
- Email: support@getharker.com
- Company: Ourfires Ltd
- Address: London, United Kingdom
13. Effective Date
This Privacy Policy is effective as of 17th March 2026 and will remain in effect except with respect to changes in its provisions in the future, which will be in effect immediately after being posted on this page.