Privacy Policy
Last updated: September 2, 2026
The short version
You give PairHarbor text about yourself (a résumé or CV, a bio, any text you choose) and we turn it into a skill cloud. The text itself is analyzed once and never stored. Only the derived skill list is kept, and you control it. We don't sell data, we don't run ads, and we don't use your submissions to train AI models.
What we collect
Waitlist: your email address and when you joined.
Text and files you submit for analysis: pasted memory or bio text, and uploaded documents (PDF, DOCX, TXT, MD). These are processed in memory to build your skill cloud and are not saved to any database or file store. Before the text is analyzed, we automatically strip strings that look like passwords, API keys, or other credentials.
Derived skills: the output of the analysis: skill names, an estimated depth for each, and a category. This is the only thing that persists: building a cloud while signed in automatically publishes it as a share link (see “What's public”) and keeps a saved copy on your account. Both are yours to delete. Anonymous builds stay in your browser unless you explicitly share them.
Account: if you sign in, we receive your account identifier and email from Google, GitHub, or LinkedIn, or store your email if you use a sign-in link. We keep that email to notify you when you receive a message (you can turn message emails off in Settings) and to check its domain when you join a domain-restricted company workspace; the address is never shown to other users. Sign-in uses an essential session cookie. We use no tracking cookies. You can optionally add profile details in Settings (display name, headline, city, country, website, your full-/part-time availability, and your remote/hybrid/on-site work mode). Every field is voluntary, editable, and clearable at any time. The display name titles your share links, and your country, availability, and work mode are shown publicly with your published clouds and filterable in the Harbor. Project postings can likewise carry optional country, city, remote, and full-/part-time details, shown publicly with the project.
Usage analytics: two things, neither used for advertising and neither sold. First, our own cookieless counters: aggregate event counts (a page was viewed, a cloud was built, a link was shared) stored in our own database, recording at most a page path and the referring site's domain: no IP address, no device details, no identifiers. Second, PostHog, a third-party analytics service that records pageviews and interaction events so we can see how the product is actually used. PostHog keeps a random identifier in your browser's local storage (not a cookie) to group events from the same browser; anonymous visitors are never profiled, and share-link addresses are rewritten to a placeholder before anything is sent, so neither system can be used to enumerate live share links. If you mark your account as a test account in Settings, your events carry a flag (a single yes/no, no identity) so our statistics reflect real usage.
API tokens: if you create personal API tokens in Settings, we store only their hashed form, plus the label and usage times you see there. A token can read and update your own cloud, nothing else, and you can revoke it at any time.
Messages: signed-in users can message the owner of a published cloud. We store each message (the sender and recipient account identifiers, the cloud it concerns, the text, and timestamps) so both sides can read the conversation. Messaging is pseudonymous: the other party sees the cloud's title and your words, never your account identity. You reveal only what you write; the composer warns you when a message looks like it contains contact details, and credential-shaped strings (API keys, passwords) are removed automatically before storage. Your availability status (“open to projects” / “exploring”), if you set one on a listed cloud, is shown publicly with that cloud.
GitHub enrichment (optional): if you signed in with GitHub and click “Enrich from my GitHub,” we fetch a summary of your public repositories (names, descriptions, languages, topics) from GitHub's API and place it in the import box for you to review and edit before submitting. It then follows the same analyzed-once path as pasted text. Nothing is fetched without that click, and we never access private repositories.
How analysis works
Your submitted text is sent, after credential redaction, to Anthropic, our AI processing provider, whose API terms do not permit training on customer data. The response is returned to you and holds only derived data: your skill list, an estimate of your years of experience, and a short professional headline (like “Senior Backend Engineer”) used to name your cloud. The submitted text is then discarded.
To prevent abuse, analysis is limited per day: per account when you are signed in, per IP address otherwise. IP addresses are used only for this counting, kept solely as a salted hash that expires within 24 hours, and are never stored with your content.
What’s public
Building a cloud while signed in automatically publishes it at one permanent page with a random handle (pairharbor.com/u/…) showing its title and skills, visible to anyone with the link. That page is live: it always shows your current cloud, and edits appear there automatically until you unpublish it. Project postings are separate pages that keep the skills they were posted with. The link is shown to you the moment it's created, with one-click removal right there and in Settings. Signed-out visitors publish only if they explicitly choose to share; those anonymous profiles are deleted automatically after 90 days. Clouds and pages on signed-in accounts are kept until you delete them.
The Harbor: clouds you build while signed in are additionally shown in the Harbor by default, a directory where any signed-in user can discover them without needing the link, grouped with similar clouds. A control to turn this off appears next to the link the moment it's created, and in Settings at any time. Anonymous clouds are never shown there. The Harbor displays only what the public page already shows: the cloud's title, skills, location and work-preference facts, and (if you set one) your availability status. Similarity scores you see there are computed in your own browser; your cloud is never uploaded by that page.
Company workspaces
A workspace is a private space for a company: its name, member list, and internal projects (a title and a derived skill list) are stored in our database and visible only to the workspace's members. Nothing in a workspace appears in the Harbor, on any public page, or to any other account. Joining a workspace shows other members a display label for you, but it does not share your skill cloud: that is a separate switch inside the workspace, off by default, and you can turn it off again at any time. Leaving a workspace removes your membership; deleting a workspace (admins) permanently removes its projects and memberships, while members' own clouds are untouched. Project descriptions are analyzed the same way as everything else: the text is analyzed once and never stored, and only the derived skill list is kept.
A workspace admin can restrict joining to a company email domain. In that case, the domain of your sign-in email is checked when you use an invite link, and workspace admins can see whether a member's sign-in email matches the workspace's domain (a yes or no, never the address itself).
Where data lives
PairHarbor runs on Vercel (hosting), Neon (Postgres database), and Redis Cloud (short-lived cache). Sign-in emails are delivered by Resend; OAuth sign-in involves Google, GitHub, or LinkedIn; analysis is performed by Anthropic; usage analytics are processed by PostHog in the United States. When something breaks, a technical error report (the failure's stack trace and page, never your submitted text or skills) goes to Sentry, our error monitoring service. These providers process data only to run the service.
Retention
Waitlist emails: until launch, or until you ask to be removed.
Submitted text and files: not retained. Analyzed once, discarded.
Anonymous published profiles: 90 days, then deleted automatically.
Signed-in saved clouds and account records: until you delete them.
Messages: kept while both accounts exist; contact us to have your conversations removed.
Delete your account
You can delete your PairHarbor account and its data yourself, at any time:
1. Sign in at pairharbor.com and open Settings.
2. Scroll to the Danger zone and choose Delete my account.
3. Confirm. Deletion runs immediately and signs you out.
This permanently removes your account record and profile details, your saved clouds, your published share pages and project postings, your messages (sent and received), and your API tokens. There is no recovery window: deleted data is gone from the live database at once, not retained for a holding period. What survives is only what was never tied to your account: aggregate usage counts with no identity in them, and, if you separately joined the waitlist, that email (ask us to remove it). If you prefer, or if you can no longer sign in, email privacy@pairharbor.com and we'll do it for you.
Delete some data, keep your account
You don't have to delete your PairHarbor account to remove data from it:
1. Sign in at pairharbor.com and open Settings.
2. Your published share pages, project postings, and saved clouds are listed there, each with its own unpublish or delete control. Removal is immediate and permanent, with no retention period.
For anything without a Settings control (your message history, a waitlist email, or your optional profile details beyond clearing the fields yourself), email privacy@pairharbor.com and we'll remove it.
Your rights
You can ask for a copy of your data, correct it, or have it deleted. email privacy@pairharbor.com. Saved clouds can be deleted directly in the app. If you are in the EU/EEA or UK, these rights are backed by the GDPR; we honor them for everyone regardless of location.
Children
PairHarbor is not directed at children and may not be used by anyone under 16.
Changes
If this policy changes, we'll update this page and the date at the top. Material changes to how your data is handled will be called out, not buried.