Legal

Privacy Policy

Last updated: September 8, 2026

1. Introduction

Harmony is an AI-powered relationship app for individuals and couples. This Privacy Policy explains what we collect, how we use it, who processes it on our behalf, and the rights you have over your data. By using Harmony you agree to the practices described here.

2. Information We Collect

We collect only what we need to run the app. Categories include:

  • Account information: name, email address, account identifiers, in-app display handle, authentication records, and any invite, referral, or professional code you choose to enter. We do not store account passwords; sign-in uses a one-time email code, Apple, or Google.
  • Email preferences: if you choose optional Harmony emails, we record your account email, the wording you agreed to, when and where you opted in, and any withdrawal of that consent.
  • Billing information: subscription and payment identifiers, purchase history, plan and renewal status, invoices, refunds, and limited payment-method details used to manage your subscription. For website purchases, Stripe collects payment and billing details through its embedded payment form; Harmony receives identifiers and limited card details such as the brand, last four digits, and expiration date, not your full card number or security code. We share your account email and an internal account identifier with Stripe to associate payments with your Harmony account. Stripe may also process transaction and device information to secure payments and prevent fraud, as described in Stripe's Privacy Policy. Harmony does not send your quiz answers, journals, or coaching conversations to Stripe.
  • Profile and onboarding signals: birthday, optional anniversary and birth location, relationship details, sign-up reasons, onboarding answers, and quiz results such as love language, attachment style, and conflict style.
  • Session data: messages and voice-session transcripts from Solo and Couples coaching sessions, private coaching, softened messages, AI-generated titles, summaries, insights, and scores. Voice audio is streamed to our voice provider for real-time response and is not stored as audio after the session ends.
  • Reflections and relationship activity: journal entries and insights, moods, goals and progress, check-ins and predictions, nudges, appreciations, Handoffs, Sunday Letters, milestones, streaks, Chapters and Plans, and Our Story activity.
  • Partner and professional data: partner connections, sharing choices, counselor exports, professional connections, access permissions, professional questions, Harmony's answers, and professional guidance.
  • Device data: Apple Push Notification Service (APNs) device tokens, app version, iOS version, device model, and diagnostic information used to deliver notifications, secure the service, and investigate problems.
  • Usage and attribution data: feature activity, session lengths, product events, internal account or device identifiers, and install-attribution results used to understand and improve the service. Sensitive relationship text is masked from analytics recording. We do not collect contacts or precise location. AppsFlyer receives Apple's advertising identifier only if you grant tracking permission; otherwise attribution uses privacy-preserving methods such as SKAdNetwork.

3. How We Use Your Information

  • To provide AI coaching during solo and couples sessions and to translate tense couples messages before they reach your partner.
  • To generate personalized insights, session summaries, journal reflections, and your Connection Score.
  • To operate check-ins, Handoffs, letters, goals, plans, widgets, partner sharing, counselor exports, and professional connections you choose.
  • To deliver session invites, partner activity, and reminder notifications.
  • If you separately opt in, to email date ideas, practical ways to reconnect, and occasional Harmony offers. This choice is optional and does not affect sign-in, purchases, or access to Harmony. You can withdraw it at any time using the unsubscribe link in a marketing email or by contacting privacy@talkharmony.app. We do not use your private journals, coaching conversations, or quiz answers to target these emails. Essential account, security, and billing messages are separate from marketing preferences.
  • To detect and respond to crisis-language patterns (see Section 7).
  • To process subscription billing through Apple for App Store purchases or Stripe for website purchases, verify access, and manage renewals, cancellations, invoices, and payment support.
  • To diagnose bugs and improve the product.

Website Analytics

We use PostHog for cookieless website page counts, visit duration, broad device information, and referring websites. PostHog uses a rotating server-side hash derived from connection information to estimate visitors without storing analytics cookies or browser-storage identifiers. We do not link these page events to your Harmony account. We remove URL query strings and fragments and do not send names, email addresses, quiz answers, payment details, or private relationship content. Website session recording and automatic form and click capture are disabled, and authenticated program portals are excluded. Global Privacy Control or Do Not Track signals disable this website analytics collection. Advertising measurement remains a separate choice below.

Website Advertising Measurement

With your advertising measurement choice, public website pixels may also share website visits and marketing-page interactions with Google, TikTok, Pinterest, Snapchat, X and Reddit. These providers process that activity under their own privacy policies. The payment-event integration described below sends payment amounts only to Meta.

If you allow advertising measurement, our public website uses advertising cookies and pixels. For Meta ads, we associate campaign, ad-set and ad identifiers from the link you followed with your account and actual website payments. We may send Meta browser and click identifiers, payment dates, currency and amounts through its server-side Conversions API. This includes the introductory payment and eligible renewals, not an assumed future subscription value. Meta processes information under its Privacy Policy.

We do not include your Apple or Google sign-in details, name, email, birthday, quiz answers, relationship profile, journals, sessions, or coaching content in these payment events. Advertising pixels are not loaded on web onboarding, checkout, or private portals. We do not send payment advertising events for accounts known to be under 18.

Advertising measurement is optional and separate from email preferences. Use the privacy choices on this page to allow or decline it. We honor Global Privacy Control and Do Not Track signals. Browser and click identifiers expire after 30 days; campaign-level acquisition and billing records may remain for financial reporting. Declining does not affect payment or access. If you are signed in, withdrawing here also stops future server-side advertising events for that account; otherwise, sign in first or contact privacy@talkharmony.app to withdraw account-level permission. Withdrawal cannot recall events already shared with Meta.

4. AI Processing and Training

When you request an AI feature, Harmony temporarily decrypts and sends only the content and context needed for that request to our paid AI providers, currently Anthropic and Google. Under their commercial API terms, those providers do not use API prompts or responses to train their models. They may retain or log API data for limited periods for abuse prevention, security, legal compliance, or as otherwise described in their terms. Harmony does not use intimate relationship content to train a general-purpose model, and we do not sell your data.

5. Subprocessors

We rely on a limited set of third-party subprocessors to operate the service. The current list and each provider's role are published at talkharmony.app/subprocessors. They include Anthropic and Google for requested AI features, Supabase for database, authentication, and edge functions, Apple for app distribution, billing, sign-in, and notifications, Stripe for website payment processing and subscription billing, Google for optional sign-in, PostHog for masked product analytics, AppsFlyer for install attribution, Vercel for websites and portals, and Resend for account and program email and optional marketing email. Journal dictation runs on-device when available; Google may process a one-time transcription when the on-device path is unavailable.

6. Authentication

Harmony supports three sign-in options: Sign in with Apple, Sign in with Google, and a passwordless one-time code sent to your email. We do not store passwords. When you use Apple or Google sign-in, we receive a limited set of profile information (name, email address, account identifier) to create and identify your Harmony account. If you separately choose optional Harmony emails, we also use that email address for the communications you opted into. Signing in alone does not subscribe you to marketing emails.

We do not request access to any other Google data (such as Gmail, Drive, Calendar, or Contacts), and we do not sell the data we receive from Google. Our service providers process only what is needed to provide Harmony and communications you separately choose, as described above. You can revoke Harmony's access to your Google Account at any time at myaccount.google.com/permissions.

Harmony's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Apple sign-in is governed by Apple's privacy practices.

7. Crisis Safety

Harmony runs deterministic, on-server pattern matching for self-harm and crisis language alongside the AI safety layer. When a message matches, we surface 988 (Suicide & Crisis Lifeline) and 741741 (Crisis Text Line) inline and prevent the message from being broadcast to a partner during couples sessions. We retain these matches as part of the session record so the AI can recognize patterns across sessions; we do not share crisis flags with third parties beyond the subprocessors listed in Section 5. Harmony is not a substitute for professional care. If you or someone you know is in danger, call or text 988, or call 911.

8. Couples and Shared Data

Pairing does not give your partner access to everything in your account. A partner may see the shared portion of a Couples session, check-in answers after the feature reveals them, Handoffs and quick touches sent to them, and journals, moods, goals, or other items you choose to share. Private coaching, Solo sessions, private journal entries, and unshared moods remain private to you. If you connect a professional, that professional receives only the areas and date range you authorize. You can change or remove professional access, and removed material is excluded from future portal views and AI answers. Unpairing ends new cross-partner access; content remains attributed to its original author and any recovery controls shown in the app still apply.

9. Data Security

Harmony encrypts intimate relationship content, including session messages, journals, moods, check-ins, Handoffs, letters, and professional workspace content, before it is stored in the database. Stored ciphertext cannot be read as ordinary content from the database or routine staff tools. Harmony decrypts content only when needed to show it to an authorized person or provide a feature that person requests, including AI processing described in Section 4. Operational metadata such as account identifiers, dates, status, sharing settings, and usage totals remains available to the systems that operate and secure the service. We also use encrypted transport, passwordless authentication, row-level database policies, scoped access controls, and audit records. No online service can promise perfect security.

10. Data Retention and Deletion

We keep account and relationship data while your account is active and as otherwise needed for the feature, security, legal obligations, or disputes. Use the deletion controls available for individual items in the app. To delete your entire account and associated data, open Profile, Privacy & Security, Delete Account; the request is processed within 30 days. Limited security, payment, agreement, and audit records may remain where legally or operationally required, and isolated encrypted backups expire through their normal cycle. You can also email privacy@talkharmony.app to request deletion or an export.

11. Children

Harmony is not intended for users under the age of 13. We do not knowingly collect data from children under 13. If we learn that we have, we will delete the account and the associated data.

12. International Users

Harmony is operated from the United States. If you use the app from outside the U.S., your data will be transferred to and processed in the U.S. (and any other country where our subprocessors operate). Where required, we rely on Standard Contractual Clauses or equivalent transfer mechanisms.

13. Your Privacy Rights

Depending on where you live, you may have the right to access, correct, delete, or port your data, and to object to or restrict processing. You can exercise most of these directly in the app. For anything else, contact privacy@talkharmony.app and we will respond within 30 days.

14. Changes to This Policy

We may update this policy as the product changes. When we make a material change, we will update the "Last updated" date at the top and, where appropriate, notify you in-app or by email.

15. Contact Us

Questions or comments about this Privacy Policy: privacy@talkharmony.app.