How we handle your data.
Plain-language privacy across every Harness Health surface — co-op.care, SurgeonValue, ComfortCard, SolvingHealth, chanio, Fill Forward, Sh-Room, SweatSciences, and the rest.
What we collect
We collect only what we need to deliver the service you came for:
- Account data — email, name, role, brand-of-entry. Used to authenticate you and personalize the experience.
- Operational data — what you click, what you ask Sage, what you skip. Used to make the product better, not to sell.
- Health data — only when you explicitly provide it (e.g. via ComfortCard, CareGoals, or SurgeonValue). We treat this as PHI under HIPAA. See the HIPAA page for details.
- Cooperative data — for co-op.care members and worker-owners, the data needed to operate the cooperative (care logs, hours, payments). Held in trust by the LCA.
What we don't do
- We don't sell your data. Ever. Not de-identified, not aggregated, not "anonymized."
- We don't run third-party advertising trackers. No Facebook pixel, no Google ads tracking, no surveillance retargeting.
- We don't train AI models on your private data without explicit consent. Our chat widget (Sage) runs on Anthropic's Claude with zero retention by default.
Where your data lives
Operational and account data is stored in Supabase (US-East). Health data (where applicable) is stored in HIPAA-compliant infrastructure with audit logs. Chat conversations with Sage are processed by Anthropic's API under their enterprise privacy terms.
Your rights
- Request a copy of all data we hold about you.
- Correct inaccurate data.
- Delete your account and all associated data within 30 days (some legal-hold exceptions apply for clinical attestation records).
- Export your data in a portable format.
To exercise any of these, email privacy@harnesshealth.ai.
Children
Our services are not intended for users under 18. We do not knowingly collect data from minors except through a verified parent/guardian account in the family-care surfaces (co-op.care, ComfortCard).
Changes
If we change this policy materially, we'll notify you via email and surface a banner on the site for 30 days. Past versions are archived at /legal/privacy/archive.
Quick contact: privacy@harnesshealth.ai · general inquiries