Effective September 5, 2026

Privacy Policy

This policy explains how Harbor Retirement handles information used for personal financial and retirement planning. Harbor is currently a single-owner application.

Information Harbor handles

You may provide planning information directly to Harbor. If you choose to connect a financial account through Plaid, Harbor may receive institution and account names, account types, masked identifiers, balances, investment holdings and related security details, liabilities when explicitly requested, connection and refresh status, consent timestamps, and provider metadata needed to maintain the connection. Harbor does not receive the financial-institution username or password you enter in Plaid Link. Harbor does not currently request or use transaction data.

How Harbor uses information

Harbor uses information to display your financial position and investments, support retirement and personal financial-planning calculations, identify missing or stale information, maintain the connection you requested, and respond to support or security needs. Harbor does not initiate payments, place trades, move money, or use connected financial information for advertising.

Plaid

Harbor uses Plaid as a service provider and data-connectivity provider. Plaid Link lets you choose an institution and authorize access. Plaid presents its own consent and privacy information. Plaid’s handling of information is governed by its policies; this policy supplements and does not replace Plaid’s notices.

Disclosure and sale

Harbor does not sell consumer financial data. Harbor exchanges connection instructions and authorized data with Plaid for the planning purposes described above. Harbor may disclose information when required by law or when reasonably necessary to protect the application, its user, or others.

Security

Harbor keeps Plaid credentials and access tokens on the server. Access tokens and sensitive provider-derived consumer financial fields are protected using authenticated application-level encryption at rest. Harbor also uses authenticated user sessions, owner- and household-scoped records, HTTPS transport, CSRF protection, and exact-origin checks. No security measure eliminates all risk.

Retention, disconnection, and deletion

You may disconnect a connected provider account through Harbor. Harbor requests remote revocation, destroys its encrypted access token after confirmed revocation, and schedules provider-derived financial records for deletion. Under Harbor’s current enforced schedule, provider financial records are deleted after 30 days and limited connection or operational history after 90 days, unless a documented scoped hold applies. Failed revocation remains pending and can be retried rather than being represented as complete.

An explicit, re-verified Harbor-account deletion removes the user’s provider, authentication, and Saved Harbor data as intended, while preserving another household member’s separately owned records when applicable. Deletion tombstones are used to prevent restored backups from permanently restoring deleted accounts.

Your choices

Connecting an account is optional. You may use separately saved Harbor planning data without connecting an institution. You may disconnect provider access, request correction of saved information, or request an export or deletion review through the Support page.

Changes and contact

This policy may be updated when Harbor’s practices or legal obligations change. The effective date above will be revised. For privacy questions or requests, email retirementharbor@gmail.com or visit the Support page.