Privacy Policy
What we store, where it physically sits, why we need it, who else can see it, and how to make us delete it.
Effective 29 September 2026 · Version 1.0 · Controller: Harvoworkz
In one paragraph
We store an account only if you choose to create one. If you use the API anonymously, we store nothing about you. We do not sell data, run advertising, or use third-party trackers. Our servers run on Cloudflare, so account records physically sit in data centres Cloudflare operates, not on a personal computer. Everything we keep is listed below with the reason it exists.
Contents
1. Who is responsible
Harvoworkz is the data controller for the personal data described here. We decide what is collected and why. Our contact address is harvoworkz@gmail.com.
Cloudflare, Google, and every search or data provider named in section 7 act as independent controllers or processors for the data they handle themselves. Their policies govern that data, not this one.
2. Where the data is stored
This is the question most policies dodge, so here is the plain answer: the Service runs entirely on Cloudflare's network. The public site is Cloudflare Pages, the API is a Cloudflare Worker, and the database is a Cloudflare Durable Object attached to that Worker.
We do not operate our own servers, and no personal data is stored on a computer at the operator's home or office. Data is written to Cloudflare's storage services, which replicate across data centres Cloudflare chooses, and it is transferred and processed wherever Cloudflare's network routes the request. That means it may be processed in any country Cloudflare operates in, which is why we do not claim a single storage country.
Concretely:
- the site and dashboard are static files served from Cloudflare Pages, so visiting them stores nothing on a server;
- API responses are computed on a Cloudflare Worker and are not written down;
- accounts, keys, and usage counts live in a SQLite database inside a Cloudflare Durable Object, which is Cloudflare-hosted storage;
- the search index also lives in that Durable Object and contains public web pages, not personal data.
3. What we collect, and why
We collect the minimum needed to run an API with accounts. Nothing here is optional except the account itself.
| Data | Why we need it | Legal basis | Retention |
|---|---|---|---|
| Email address | Identifies your account, and is where we send security notices if you use Google sign-in. | Performance of a contract | Until you delete your account |
| Display name | Labels the account in your own dashboard. | Performance of a contract | Until deletion |
| Password hash | Verifies your password. We store a salted PBKDF2 hash, never the password, and cannot recover it. | Performance of a contract | Until deletion |
| Google account ID, name, email, picture | Returned by Google at sign-in so you do not have to type them again. | Performance of a contract | Until deletion |
| API keys | Stored only as a one-way hash to authenticate your requests. We cannot read a key back. | Performance of a contract | Until revoked or deleted |
| Request counts per key, per day and month | Enforces your quota. Counts only, never query text. | Performance of a contract; legitimate interest in protecting the service | Rolled up and kept in aggregate |
| Last sign-in time | Lets you spot a sign-in you did not make. | Legitimate interest in account security | Until deletion |
| Your search queries | Not collected. See section 5. | — | — |
| IP address | Held only in memory while a request is in flight, to apply rate limits and block abuse. Never written to a database we control. | Legitimate interest in security | Not persisted |
Children's data, precise location, health, biometric, political and religious views, and any special-category data under the GDPR are not collected and must not be submitted to us. If you send such content in a query, it is forwarded to third-party search providers under their own policies and we have no control over it.
4. Google sign-in, specifically
You asked how the account is held, so precisely:
- your Google password is never sent to us and never touches our servers. Authentication happens on Google's own domain;
- we use Google's standard OpenID Connect sign-in, which returns a short-lived identity token over TLS;
- we then call Google's userinfo endpoint over a secure connection to read your name, email address, and profile picture;
- we store those three fields plus Google's account identifier, in our Cloudflare database, so you are recognised when you return;
- if you disconnect your Google account from us, we can no longer read anything from Google about you, and any account we still hold is managed by password instead;
- deleting your account here does not delete your Google account, and Google's own retention rules govern the data Google itself holds.
5. What happens to a search
Your queries are not stored and cannot be. A query arrives, is expanded in memory, fanned out to the providers we query, and the result is returned. Nothing is written to a query log.
The only numbers tied to a request are the rate-limit counter used to stop abuse, and the quota counter used to bill your plan. Neither contains your query. That means we cannot tell you what you searched for, and we cannot hand such a history to anyone who asks.
Two exceptions to be aware of:
- third-party providers keep their own logs. Your query reaches them, and they may retain it under their own policies. We do not control or see that.
- the index and page fetches. If you ask the Service to crawl a URL, that URL is stored in our index, because an index of public pages is the product. Those pages are public documents and may contain personal data published by others; we do not attempt to identify people in them.
6. Pages we fetch for you
The content-packaging and index routes fetch a URL you supply so they can read it. Two things follow from that:
- the operator of that site sees a request arriving from Cloudflare's infrastructure, not from your device, and may log it under their policy;
- private and internal network addresses are refused, so the feature cannot be pointed at your router, a database host, or a local service.
Do not use these routes to fetch anything you are not authorised to request.
7. Who else receives your data
We do not sell, rent, or share personal data for money. These categories of recipient receive data as part of running the service:
| Recipient | What they receive | Why |
|---|---|---|
| Cloudflare | Everything we store, as the hosting and database provider. | It is the infrastructure the service runs on |
| Your sign-in, and OAuth data if you use Google sign-in. | Authentication only | |
| Search and data providers | The query or symbol you asked about. Never your name, email, or account. | They supply the results |
| Page operators you fetch | An HTTP request from Cloudflare to the URL you supplied. | To retrieve that page |
| Law enforcement or regulators | Whatever we are legally required to disclose. | Only where compelled by valid process |
None of these are used by us for advertising. We do not embed advertising, analytics, or third-party tracking pixels anywhere on this site.
8. Cookies
We set exactly two cookies, both strictly necessary to sign you in:
__Host-harvo_session— a random session identifier.HttpOnly, so scripts cannot read it;Secure;SameSite=Lax.__Host-harvo_csrf— a random token that proves a write request came from this site and not another one.
Neither is used for advertising or profiling. The __Host- prefix is a browser-enforced guarantee that a cookie cannot be set on a domain other than the exact one that created it, which blocks subdomain cookie injection.
The dashboard keeps your current playground conversation in your browser's sessionStorage. That never leaves your device and disappears when you close the tab.
9. How long we keep it
Account data is kept for as long as your account exists. You can delete an API key yourself at any time and it stops working immediately. Request counters are kept in monthly totals for billing and abuse investigation, with old periods rolled up rather than discarded line by line.
When you ask us to delete your account, or when we close it, we remove your profile, your keys, and the counters tied to you from our database. Backups held by Cloudflare age out on their own retention cycle, which is why deletion can take up to a few weeks to be complete everywhere.
10. Your rights
If you are in the EEA, the UK, Switzerland, California, or a jurisdiction with similar law, you hold rights over your personal data. We extend the same handling to everyone regardless of where you are, because it is the right thing to do and simpler to operate.
- Access. Ask what we hold about you and get a copy. Write to us and we will send it.
- Rectification. Fix anything wrong. You can change your name yourself; tell us about an email address and we will correct it.
- Erasure. Ask us to delete your account and everything attached to it.
- Restriction and objection. Ask us to pause processing, or to object to processing we rely on legitimate interest for. This mainly concerns the abuse-prevention counters.
- Portability. Get your data in a structured, machine-readable format. We will send JSON.
- Withdraw consent. Where we rely on consent, you can withdraw it at any time without affecting prior processing.
- Non-discrimination. We will not treat you worse for exercising a right.
California residents. Under the CCPA/CPRA you have the right to know what personal information is collected, to request deletion, to correct it, to opt out of sale or sharing, and to limit use of sensitive personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do not knowingly collect the personal information of anyone under 16.
European and UK residents. Our lawful bases are performance of a contract for anything needed to run your account, and legitimate interests in securing the service and enforcing quotas. We do not use automated decision-making or profiling that produces legal effects. You may complain to your local supervisory authority, for example the ICO in the UK.
We respond within 30 days and usually much sooner. We may ask you to confirm control of the account before acting, which is a security measure and not an excuse for delay.
11. How we protect it
- all traffic is encrypted with TLS, and cookies are
Secure; - passwords are stored as salted PBKDF2 hashes and are never recoverable, by us or anyone;
- API keys are stored only as one-way SHA-256 hashes;
- write requests require a CSRF token, so another site cannot make your browser act as you;
- the database is not publicly reachable and is only accessible from our Worker;
- we do not log request bodies or query text.
No system is perfect. If a breach affects your personal data we will notify you and the relevant regulator without undue delay as the law requires.
12. Children
The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us personal information, write to us and we will delete it.
13. Changes to this policy
We will update this page when what we do changes. The version and effective date at the top identify the current version. Where a change materially affects your rights we will tell you by email or in the dashboard before it takes effect.
14. Contact
Privacy questions, access requests, and deletion requests all go to harvoworkz@gmail.com. Please say what you want and include enough detail for us to find the account. For a deletion request, telling us the account email is enough.
Our Terms of Service cover how the service itself may be used.