Harvey AI — privacy & data policy

Provider: Harvey. PromptPrivacy score: 76/100. Last verified August 26, 2026.

What happens to your data?

Harvey collects account, usage, device, and log data to operate, maintain, secure, and market its services. User inputs and uploaded files on the AI platform are treated as Customer Data under separate enterprise agreements where Harvey functions as a Data Processor.

Does it train on your data?

Harvey trains and develops its AI models using publicly available information (such as public filings, judgments, and legal decisions). Customer inputs, outputs, and uploaded documents are handled separately as Customer Data governed by enterprise Customer Agreements rather than general training under this policy.

Can you opt out?

Yes. Users can opt out of marketing communications via email links or by contacting privacy@harvey.ai. Users can also opt out of targeted advertising using the 'Your Privacy Choices' controls or by broadcasting a Global Privacy Control (GPC) signal.

Data retention

Personal data is kept for as long as necessary to fulfill the purposes described in the policy, satisfy legal, tax, or accounting requirements, and comply with Customer Agreements. When no longer needed, data is deleted or anonymized.

Encryption & security

Harvey states that it applies technical and organizational security measures appropriate to the risk to protect personal data from unauthorized access, loss, alteration, or disclosure. Specific encryption algorithms or third-party certifications are not detailed in this policy document.

Is it safe for work?

Yes. Harvey is built specifically for business and professional use (law, tax, finance) and acts as a Data Processor for customer inputs and uploaded content under formal Customer Agreements and Data Processing Addenda (DPAs).

Source policy: https://www.harvey.ai/legal/privacy-policy