๐Ÿš€HarnessRouter was #5 Product of the Day Thanks for the Product Hunt support๐Ÿš€#5 Product of the Day
HarnessRouter
PricingRankingDocs
PricingRankingDocs
Sign up

Effective date: 2026-07-30

HarnessRouter Privacy Policy

Version: 2026-07-30 ยท v1.0

Scope: This notice explains how we handle Personal Data in connection with the HarnessRouter website, accounts, Workspaces, and API and Harness Runtime (generate, in-page authenticated preview, and download). This Policy describes current processing only; it does not describe data flows for services that we do not currently offer. It also applies to new or modified features that process the categories of Personal Data described here for the same or reasonably compatible purposes; we will provide additional notice, and obtain consent where required, before materially different processing begins.

1. Who We Are and How to Contact Us

HarnessRouter is provided by Lumentree Corporation, a California corporation ("we," "us," or "our").

For Personal Data we control, the controller or business is:

Lumentree Corporation<br> 201 Spear Street, Suite 1100, San Francisco, California 94105 (United States)<br> Privacy contact: contact@harnessrouter.ai

Data Protection Officer: Where applicable law requires us to designate a data protection officer, we will identify that contact here and on our Legal Hub at https://harnessrouter.ai/legal. You may contact us on any privacy matter at contact@harnessrouter.ai.

This Privacy Policy is a notice. It does not form part of the HarnessRouter Agreement, and an acknowledgment of this notice is not consent to processing or a waiver of privacy rights. Where we rely on consent for a particular activity, we request that consent separately.

In this Policy, "Personal Data" means information relating to an identified or identifiable individual, and includes "personal information," "personal data," and equivalent terms as defined under applicable data protection law and in the DPA, Section 2.3. Capitalized terms used but not defined in this Policy have the meanings given in the Terms of Service and the DPA.

2. Scope and Our Privacy Roles

This Privacy Policy applies when you visit a HarnessRouter website we operate, create or use an account or Workspace, contact us, or use the API or Harness Runtime, to the extent we determine the relevant purposes and means of processing.

We process the Personal Data described in this Policy for our own purposes โ€” including operating the website and accounts, billing, security, fraud prevention, support, service administration, and legal compliance โ€” as a controller or business. Where we process, on a Customer's behalf, Personal Data contained in Customer Content or in the Output, Artifacts, and manifests generated for that Customer, the Data Processing Addendum governs that processing (it is incorporated under Section 2.6 of the Terms and covers organizations and individuals using the Services for commercial or professional purposes); the Customer is responsible for its own notices, lawful bases, instructions, and end-user requests. Any Processing of Personal Data by us that is not governed by the DPA is processed as described in this Policy. Providers we use on managed routes process Customer Personal Data on our behalf as our subprocessors under the DPA. By contrast, identity providers, payment processors, and integrations that you or a Customer separately connect โ€” and, if we later make a customer-directed Provider account configuration available, providers used through it โ€” are governed by their own agreements with you or the Customer, as independent controllers or as the Customer's own processors, and are not our subprocessors for that use; their own privacy notices apply to their independent activities. This Policy does not govern a Customer's own Customer Applications; Customers must provide their own privacy notices for their applications and End Users.

3. Personal Data We Handle

We handle the following categories of Personal Data. We describe them at a category level; the specific fields we process depend on how you and, where applicable, a Customer use HarnessRouter. As used in this Section, capitalized terms have the meanings given in the Terms of Service; Output, Artifacts, and manifests are a distinct category and are not Customer Content.

CategoryExamplesSourcePurposesRecipients or route
Website and campaign dataInformation about your visits to and interactions with our marketing website, which may include pages viewed, funnel and activation events (such as landing, sign-up, and replay interactions), general device and browser information, referring source, and campaign or UTM attribution parametersYou, browser, device, referring sourceOperate the site, measure conversion, prevent abuse, understand campaignsWebsite hosting and website-analytics provider and waitlist datastore; additional subprocessors are listed on our Subprocessors page
Account, identity, and Workspace dataInformation used to create, identify, and secure your account and Workspace, which may include your email address and account and Workspace identifiers and, where applicable, profile, organization, role, and invitation information provided by you or a Workspace AdministratorYou, Workspace Administrator, identity providerCreate and secure accounts, administer Workspaces, authenticate, communicateCloud hosting and infrastructure provider; additional subprocessors are listed on our Subprocessors page
Service inputs, outputs, and contentService inputs that constitute Customer Content (such as text, structured parameters, prompts, files, code, and input references) and, as a distinct category that is not Customer Content, Output, Artifacts, and manifests, together with related content, but only as actually processedYou, Customer, Authorized Users, Customer Application, End UsersProvide Runs, Sessions, routing, file handling, rendering, Continue/Revise, support, safety, and abuse preventionThe cloud and AI-model infrastructure used for the applicable route; route-level recipients and data modes are described on our Subprocessors page
Run, Session, Task, and technical recordsRecords generated when the service runs, which may include session and run identifiers, timestamps, run state and status, selected and actual route metadata (such as provider, model, region, data mode, and policy version), input references, artifact manifests, traces, and usage information; these records are designed to exclude API keys, secrets, and unnecessary personal dataService activity, you, Customer configuration, ProvidersExecute and troubleshoot the service, enforce eligibility, meter usage, maintain security, preserve route evidenceCloud hosting and infrastructure provider; additional subprocessors are listed on our Subprocessors page
Device, network, log, and telemetry dataTechnical and usage information collected automatically, which may include general device and browser characteristics, API-client information, diagnostic and event data, and cookie or similar-technology data; where feasible we minimize this data, for example by retaining a minimized region-decision result rather than a raw IP addressBrowser, device, API client, systemsSecurity, authentication, rate limiting, diagnostics, analytics, service improvementCloud hosting, infrastructure, and website-analytics providers; additional subprocessors are listed on our Subprocessors page
Billing and transaction dataSubscription and transaction information, which may include subscription and plan status, payment-processor identifiers and payment-state references, invoice, tax, refund, and dispute information, and information our payment processor requires to process subscription payments; we do not receive or store full payment-card numbers or payment-processor secretsYou, Customer, payment processorProcess subscriptions, promotional credits, invoices, tax, refunds, accounting, fraud preventionPayment processor; additional subprocessors are listed on our Subprocessors page
Support, legal, privacy, and security communicationsInformation you provide when you contact us or make a request, which may include the content of your communications, attachments, and information used to verify your identity or authority and to investigate and resolve the matterYou, Customer, reporter, claimant, authorized agentRespond to requests, investigate issues, protect rights, comply with lawCloud hosting and infrastructure provider and, where engaged, professional advisers; additional subprocessors are listed on our Subprocessors page
Third-party integration dataInformation exchanged when you or a Customer connect a third-party integration currently made available in the Services, or if we later make a customer-directed Provider account configuration available, information exchanged through that configuration. This may include integration identifiers, scopes, tokens, account metadata, and content necessary to operate the integration or configurationYou, Customer, integration or ProviderConnect and operate the integration or configuration at your directionThe integration you authorize, and if such a Provider account configuration is later made available, the Provider account you or a Customer authorizes; our cloud hosting and infrastructure provider; additional subprocessors are listed on our Subprocessors page
Inferences and derived dataLimited data we may derive from the categories above, such as security, fraud-prevention, and usage signalsDerived from the categories aboveSecuring the service, preventing fraud and abuse, and operating and improving the serviceCloud hosting and infrastructure provider; additional subprocessors are listed on our Subprocessors page

Do not put secrets, API keys, private keys, OAuth tokens, full payment-card data, or other prohibited sensitive data into a Prompt, File, Trace, source file, or other general-purpose field. Use only a documented secrets channel where one is expressly made available for that purpose. Prohibited and restricted data categories are set out in Terms of Service Section 11.

3.1 Cookies and Similar Technologies

We and our service providers use cookies and similar technologies (such as local storage and SDKs) on our website and Services. They fall into the following categories:

  • Strictly necessary. Required to operate the site and Services โ€” for example, authentication and session cookies, security and fraud-prevention measures, and load balancing. These cannot be switched off through a consent control because the Services do not function without them.
  • Functional or preference. Remember choices you make (such as interface preferences) to provide enhanced features. You can disable these, but some features may not work as intended.
  • Performance or analytics. Help us understand how the site and Services are used โ€” for example, pages viewed and funnel and activation events measured through our website-analytics provider identified on our Subprocessors page. We use this information to operate and improve the Services.

We do not currently use cookies or similar technologies for cross-context behavioral or targeted advertising; Section 11.1 describes how we would handle that if it changes.

Where applicable law requires consent for non-essential cookies or similar technologies, we request that consent through a banner or similar control before they are set, and you can withdraw it through the same control. You can also refuse or delete cookies through your browser settings (see your browser's help pages or allaboutcookies.org); blocking strictly necessary cookies may prevent parts of the Services from working. We honor qualifying Global Privacy Control signals as described in Section 11.1.

4. Sources of Personal Data

We may obtain Personal Data:

  • directly from you when you visit, register, configure, upload, submit, purchase, contact us, or exercise a right;
  • from a Customer, Workspace Administrator, Authorized User, Customer Application, or End User that provides or generates data through the service;
  • from an identity provider, payment processor, Provider, Harness, integration, or Customer-owned account that you or a Customer connects;
  • automatically from browsers, devices, API clients, systems, logs, and service activity; and
  • from public sources, professional advisers, rights holders, security researchers, authorities, or fraud and security sources, but only if and as actually used.

Where we are required to provide notice under Article 14 of the GDPR or similar law for Personal Data not obtained directly from you, we provide the required information within the applicable period, subject to statutory exceptions; where we act as processor, the relevant Customer is responsible for its own notice obligations.

5. Why We Process Personal Data and Our Legal Bases

The applicable legal basis depends on the purpose, location, and context. We do not treat this Policy as blanket consent.

PurposeTypical legal basis where GDPR or UK GDPR applies
Create and administer an account or Workspace; authenticate; provide requested service featuresNecessary to enter into or perform a contract; legitimate interests for related administration
Process Customer Content and execute Runs, Sessions, routing, files, Artifacts, and enabled integrationsContract where we are controller; Customer's documented instructions where we are processor
Bill, account, process subscription activity, administer refunds, and meet tax dutiesContract; legal obligation; legitimate interests in accounting and fraud prevention
Secure the service; prevent fraud, abuse, and unauthorized access; debug and maintain reliabilityLegitimate interests; contract; legal obligation where applicable
Provide support and respond to privacy, security, legal, and IP requestsContract; legitimate interests; legal obligation
Measure website or product performance and improve the serviceLegitimate interests for strictly necessary or appropriately balanced measurement; consent where required for non-essential technologies
Send marketing communications or use non-essential advertising technologiesConsent where required; otherwise legitimate interests subject to opt-out rights
Comply with law, enforce rights, respond to valid process, and protect persons or the serviceLegal obligation; legitimate interests; establishment, exercise, or defense of legal claims

Where we rely on legitimate interests, those interests include operating and securing HarnessRouter, preventing abuse, communicating about the service, improving reliability, and protecting us, Customers, End Users, and others. We assess whether those interests are overridden by the individual's rights and interests. You may request information about an applicable balancing assessment through the privacy contact above.

Service, security, billing, and administrative communications are not marketing communications and may be sent as needed to operate your account; the marketing opt-out does not affect them.

6. AI Providers, Training, Service Improvement, and Human Review

We do not use Customer Content to train our own AI models unless the Customer actively opts in to that distinct use, as set out in Terms Section 7.3. This applies to Customer Content in any form: the aggregated and de-identified data we create (such as usage and performance statistics) does not include the substance of your content, and de-identifying or aggregating content does not let us train models on it. An opt-in, if offered, will identify the data, purpose, benefit, and withdrawal effect. Safety classification, abuse detection, debugging, and providing the service are not treated as model training merely because automated systems are involved.

Providers may have their own logging, retention, abuse-monitoring, human-review, and training practices. Those practices can differ by Provider, channel, model, region, credential owner, and data mode. We do not promise that every route is zero-retention or that every Provider never trains on data. A route that shares inference data with a model Provider is subject to the required Workspace Administrator disclosure and authorization before enablement.

Route-level recipients and data modes are reflected, at a category level, in this Policy and on our Subprocessors page at https://harnessrouter.ai/legal/subprocessors. Any human access to Customer Content by our personnel, including for support, safety, or incident review, is limited to authorized personnel on a need-to-know basis, subject to access controls and confidentiality obligations, and is used only for purposes such as providing the service, maintaining security, detecting and preventing abuse, and responding to valid legal requests.

7. When We Disclose Personal Data

We disclose Personal Data only for a described purpose and subject to the role and safeguards applicable to that recipient. Categories may include:

  • hosting, infrastructure, database, authentication, communications, support, analytics, security, fraud-prevention, and professional-service providers;
  • our corporate affiliates, if any, which may process Personal Data consistent with this Policy;
  • the Harness, model, cloud, or other Provider selected or permitted for the applicable route;
  • payment processors, financial institutions, and tax providers for subscription billing;
  • third-party integrations that a Customer authorizes and, if we later make a customer-directed Provider account configuration available, the Customer-owned Provider accounts a Customer authorizes through it;
  • the Customer, its Workspace Administrators, Authorized Users, and relevant End Users according to account permissions and the service workflow;
  • a successor, acquirer, investor, or transaction participant (including counterparties and advisers in due diligence) in a merger, reorganization, financing, acquisition, divestiture, sale of all or part of the HarnessRouter business, bankruptcy, receivership, or similar proceeding, or a transition of the Services to another provider, subject to appropriate confidentiality and applicable law;
  • other users or recipients where you or a Customer use a current feature designed to share content with those recipients;
  • authorities, courts, advisers, rights holders, or other persons where disclosure is required by law or reasonably necessary to protect rights, safety, and the service โ€” including to enforce our agreements and policies and to detect or prevent fraud and abuse; and
  • other recipients at your direction or with separate consent where required.

We also create aggregated and de-identified data from use of the Services, such as usage volumes, model and provider usage statistics, and performance trends. Once data is aggregated or de-identified so that it does not identify and cannot reasonably be used to identify you, it is not Personal Data, and we may use and publish it โ€” for example, as usage statistics, rankings, or trends โ€” for any lawful purpose, as described in the Terms (Section 7.6). We do not attempt to re-identify this data, except as required by law or as necessary to test whether our de-identification measures satisfy applicable law; we publish metrics only at a level of aggregation from which no individual user or non-public configuration is identifiable; and we do not publish the substance of your content or your identity.

The current Subprocessor List is available at https://harnessrouter.ai/legal/subprocessors. The list identifies each subprocessor's legal entity (or, for a subprocessor whose identity is confidential commercial information, its category, with the legal entity name available to DPA customers on request), the service it provides, its location, and the applicable data purpose, and we update it from time to time. A link to a list does not authorize undisclosed processing.

We disclose Personal Data to service providers and other recipients only as described in this Policy. We do not currently sell Personal Data for monetary or other valuable consideration and do not currently share Personal Data for cross-context behavioral advertising; if that changes, we will update this Policy and provide any legally required notices and opt-out mechanisms before the new practice takes effect; see Section 11 for the CCPA/CPRA treatment.

8. International Data Transfers

Personal Data may be processed in countries other than the country where it was collected. Currently, Personal Data processed for HarnessRouter is primarily processed in the United States by the subprocessors identified on our Subprocessors page at https://harnessrouter.ai/legal/subprocessors; where processing occurs in additional countries, it is described on that page, which we update from time to time.

Where we transfer Personal Data outside the EEA, the UK, or Switzerland, we rely on an adequacy decision or on Standard Contractual Clauses (and their UK and Swiss equivalents) where required. For Customer Personal Data we process as a processor on a business customer's behalf, the specific transfer terms are in our Data Processing Addendum.

9. Retention, Deletion, and Backups

We retain each category of Personal Data for as long as needed for the purposes described in this Policy, taking into account the account and service lifecycle, legal, tax, security, and fraud-prevention requirements, dispute needs, Provider constraints, and our backup architecture.

After you close your account, we take steps to delete account Customer Content that we hold as controller from active systems we control, generally within 30 days (for Customer Personal Data processed under the DPA, the DPA's retention schedule governs, as stated below), subject to the exceptions below. This is a target rather than a guarantee that every item is removed from every system on a single uniform schedule. In particular: copies held by a Provider are governed by that Provider's own terms and are not controlled solely by deleting a HarnessRouter account; and billing and tax records, security and fraud-prevention logs, dispute records, and data in routine backups follow their own retention periods and are deleted or overwritten on their own cycles.

Deletion may be limited or delayed where data must be retained for legal obligations, security, fraud prevention, billing, dispute resolution, or the establishment, exercise, or defense of legal claims, or where it remains in protected backups pending scheduled overwrite. Where we retain Personal Data under such an exception, we restrict further processing to those purposes.

For Customer Personal Data we process on a Customer's behalf under the DPA, retention and deletion periods are governed by the DPA, Section 12 (and its retention Annex), which is the single source of retention timing for that data. For Personal Data we process as a controller โ€” including website, account, billing, security, and log data โ€” the periods and category-specific cycles described in this Section apply. You may also request information through the privacy contact above. Aggregated or de-identified data that no longer identifies you may be retained and used as described in Section 7 for as long as it remains aggregated or de-identified.

10. Security

We use administrative, technical, and organizational measures designed to protect Personal Data. Depending on the system, risk, and data involved, these measures may include encryption of data in transit and at rest, access controls and authentication, per-user and per-tenant isolation, secure server-side storage of API keys and other secrets, and logging and monitoring. These measures are described in more detail in the technical and organizational measures in the DPA (Annex 2) at https://harnessrouter.ai/legal/dpa. The transmission of information over the internet is not fully secure; we are not responsible for circumvention of security measures by third parties, and you are responsible for safeguarding your account credentials.

No security method can eliminate every risk. Please report suspected security issues through the channel described in our Security and Vulnerability Disclosure Policy at https://harnessrouter.ai/legal/security or at contact@harnessrouter.ai.

11. Your Privacy Rights and U.S. State Disclosures

Depending on where you live and subject to legal conditions and exceptions, you may have rights to:

  • know or access Personal Data and information about its processing;
  • correct inaccurate Personal Data;
  • delete Personal Data;
  • obtain a portable copy;
  • restrict or object to processing;
  • withdraw consent at any time for future processing based on consent;
  • opt out of sale, sharing, targeted advertising, or certain profiling;
  • limit certain uses or disclosures of sensitive Personal Data;
  • appeal our refusal of a request; and
  • lodge a complaint with a supervisory authority or other data-protection authority.

For individuals in the EEA or UK, the rights above include the full set of data-subject rights under the GDPR and UK GDPR, to the extent applicable and subject to the conditions and exceptions of that law: access, rectification, erasure, restriction of processing, data portability, objection to processing, the withdrawal of consent for future processing based on consent, and the right to lodge a complaint with a supervisory authority (such as the UK Information Commissioner's Office or an EEA member-state supervisory authority).

Submit a request at contact@harnessrouter.ai. We may verify identity and authority in a proportionate way. An authorized agent may submit a request where the law permits, subject to verification of the authorization and, where permitted, the individual's identity. We do not discriminate against a person for exercising a privacy right.

If we act only as a processor, service provider, or contractor for the relevant Personal Data, we may direct the request to the Customer that controls the data and assist that Customer as required by the Data Processing Addendum and applicable law.

11.1 U.S. state-specific disclosures

As used in these U.S. state disclosures, "consumer" has the meaning given under the applicable U.S. state privacy law (for example, the CCPA/CPRA), and is distinct from the capitalized term "Consumer" defined in the Terms of Service, Section 25.1.

The categories of Personal Data, sources, purposes, and recipient categories described in Sections 3 through 7 cover our practices in the preceding 12 months.

TopicCurrent disclosure
Sale of Personal DataWe do not currently sell Personal Data for monetary consideration. Some U.S. state laws define "sale" broadly; to the extent any disclosure described in Section 7 falls within such a definition, we treat it accordingly and honor applicable opt-out rights.
Sharing or targeted advertisingWe do not currently share Personal Data for cross-context behavioral or targeted advertising and do not currently use Personal Data for that purpose.
Global Privacy ControlWhere required by applicable law, we treat a Global Privacy Control or similar opt-out preference signal as a request to opt out for the browser or device that sends it, where technically supported.
Sensitive Personal DataOur policies prohibit submitting sensitive categories of data (such as government-issued identifiers, health, biometric, or full payment-card data) into general-purpose fields such as prompts, files, or traces. We do not seek to collect sensitive Personal Data in order to infer characteristics about you. Where any sensitive Personal Data is nonetheless processed, we handle it consistent with applicable law and, where required, offer applicable rights to limit its use or disclosure.
Profiling with legal or similarly significant effectsWe do not make decisions that produce legal or similarly significant effects about you through solely automated processing; this is addressed in Section 12.2. Ordinary service functions such as routing, recommendations, and security scoring are not used for that purpose.
Financial incentives or price/service differences related to Personal DataWe do not offer financial incentives and do not charge different prices or provide a different level of service in exchange for the retention or sale of Personal Data.
Categories collected, disclosed, sold, or shared in the preceding 12 monthsThe categories of Personal Data we collect and the recipients to whom we disclose them are described in Section 3 and Section 7; our sale and sharing treatment is addressed in the Sale of Personal Data and Sharing or targeted advertising rows above.

Where required, the Legal Hub or privacy request page will provide a "Do Not Sell or Share My Personal Information" or equivalent mechanism. We will treat a qualifying GPC signal as a request for the browser or device that sends it to the extent required by applicable law and where technically supported.

12. Data You Must Provide and Automated Decision-Making

12.1 Whether providing data is required

Some Personal Data is necessary to enter into or perform a contract, comply with law, or provide a requested feature. Other Personal Data is optional.

Data or actionWhy it may be requiredWhat happens if it is not provided
Account and authentication data necessary to register or sign inNecessary to create, authenticate, secure, and administer an account or WorkspaceWe cannot create or authenticate the account or provide account-only features
Customer Content and configuration needed for a requested Run or featureNecessary to execute the instruction and route the requested serviceWe cannot execute that Run or feature; you may choose not to submit optional content
Billing data required for a paid PlanNecessary to enter into and perform the paid transaction and meet applicable financial dutiesWe cannot activate the paid Plan or transaction
Security or verification data requested to investigate fraud, abuse, account recovery, or a rights requestMay be necessary to protect the account, verify authority, comply with law, or prevent improper disclosureWe may be unable to complete the request, restore access, or continue the affected activity
Optional profile, marketing, analytics, or feedback dataUsed only for the disclosed optional purposeYou may decline optional data; doing so may limit communications, personalization, or features for which that data is reasonably necessary, and we do not condition unrelated core features on it where prohibited by law

The specific fields required at registration, checkout, and for support or verification are presented to you at the point of collection, and any consequence of not providing required data is described above or at that point.

12.2 Decisions based solely on automated processing

We do not make decisions that produce legal or similarly significant effects concerning you based solely on automated processing, including profiling, within the meaning of Article 22 of the GDPR. Automated functions such as service routing, recommendations, usage metering, and security or fraud scoring support human decision-making and the operation of the service and are not used to make solely automated decisions with legal or similarly significant effects.

If we introduce any such decision-making in the future, we will, before that processing takes effect, provide the information and rights required by applicable law, including the identification of the decision, meaningful information about the logic involved, the significance and envisaged consequences, the legal basis, applicable safeguards, and the ability to obtain human intervention, express a view, and contest the decision. For Personal Data not obtained directly from you, we will provide the same applicable information under Article 14 of the GDPR at the required time.

Where an automated safeguard materially restricts your account, you may contest the action and obtain human review through the contact in Section 1.

13. Children, Changes, and Additional Information

HarnessRouter is a general-audience service, is not directed to children, and we do not knowingly collect Personal Data from children. Account eligibility (including the 18+ requirement) is set out in Terms of Service Section 1.4. If a Customer Application is directed to, or used by, minors, the Customer is responsible for its own notices, consents, age-appropriate safeguards, and compliance with children's-privacy law for those end users.

If you believe a child has provided Personal Data to us contrary to these rules, contact contact@harnessrouter.ai. If we learn that we have collected Personal Data from a child in violation of these rules, we will take steps to delete that information and address the matter as required by applicable law.

We may update this Policy to reflect changes in law, our services, or our processing. We will post the current version at https://harnessrouter.ai/legal/privacy and indicate its effective date. For a material change, including a new purpose or controller, we will provide notice appropriate to the change and applicable law before the change takes effect where required. We will request consent separately if the law requires consent.

Questions, privacy requests, and complaints may be sent to the contact in Section 1. Individuals in the EEA or UK may also complain to their supervisory authority as described in Section 11. You may also reach us at contact@harnessrouter.ai.

HarnessRouterยฉ 2026 HarnessRouter

Product

PricingRankingDocs

Legal

TermsPrivacyDPASubprocessorsSecurity

Social

DiscordGitHubLinkedInX