How productharvest.org handles the data you give us when you visit the site, request hosted-Winnow access, contact us, or sign up for a workspace. Last updated: [DECIDE: launch date].
This policy applies to productharvest.org — the public marketing site for Harvest and its open-source reference implementation, Winnow. It also covers the hosted-Winnow workspaces operated at usewin.now, which are run by the same team using the same infrastructure provider.
What "harvest" means here. Harvest is a methodology that operates on first-party evidence your team has authored — sales notes, research transcripts, decision memos, support tickets — not on customer data harvested from anywhere else. The full version is at where the data comes from, where it goes.
It does not cover self-hosted Winnow installations. When you run Winnow on your own machines, your raw evidence, wiki, and configuration are processed inside your infrastructure. We never see them and have no ability to. The only data we receive from a self-hosted install is whatever you choose to send us through the contact form or the waitlist.
Triple P Digital is the controller of personal information collected through productharvest.org and usewin.now. Our registered address is 28 Westland Wallace Way, Hucknall, Nottingham, NG15 6XU. You can reach us at hello@productharvest.org for any privacy-related question.
We try to be specific here, because vagueness is what regulators care about.
Information you give us directly:
checkout.session.completed, customer.subscription.deleted, etc.).Information collected automatically when you visit the marketing site:
hubspotutk cookie that stitches any subsequent form submission back to the marketing session that brought you to it (including UTM tags on the URL). This lets us see which campaigns are working without needing to ask you anything.Each category of data has a specific purpose:
raw/, wiki/, or configuration is read by us, used for analytics, or shared with anyone.We rely on the following legal bases under UK GDPR / EU GDPR (whichever applies to you):
We use a small number of third-party processors. Each one receives only the data they need to do their job.
| Processor | What they receive | Why |
|---|---|---|
| Vercel | Site hosting; receives requests and serves pages. Server logs sit on their infrastructure. | Hosting productharvest.org and the hosted-Winnow orchestrator. |
| Vercel Web Analytics | Anonymised page-view counts, referrer, country-level location, device class. Cookieless by default — visitors are identified by a daily-rotated hash, not a persistent cookie. | Aggregate traffic analytics on productharvest.org so we can see which content brings people in. |
| Fly.io | Per-customer hosted-Winnow containers and persistent volumes. Workspace data lives here. | Container hosting for usewin.now workspaces. |
| Clerk | Email, name, hashed password, session metadata. | Authentication for usewin.now. |
| Stripe | Card details, billing address, subscription state. | Payment processing for hosted Winnow. We don't see your card. |
| HubSpot | Form submissions from /request-access and /contact, plus marketing-attribution cookie data. | CRM and waitlist management. |
| Resend | Email addresses needed to deliver transactional and waitlist emails. | Email delivery. |
| Anthropic / OpenRouter | If you bring your own LLM key (BYOK), your prompts and your wiki context are sent to whichever provider you've configured, on your account, billed to you. | Synthesis. We pass through; we don't reroute or store. |
For self-hosted Winnow installations, the only processor in this list that's relevant is whichever LLM provider you configure. Everything else stays inside your infrastructure.
Some of these processors operate outside the UK / EEA. Where personal data is transferred internationally, we rely on the safeguards each processor has put in place — Standard Contractual Clauses, the UK / EU adequacy frameworks, or equivalent. You can read each processor's data-processing terms on their website.
hubspotutk cookie is valid for 13 months by default; HubSpot's contact records persist until you ask us to delete them.Hosted-Winnow workspaces are isolated containers; we don't read your workspace data as part of normal operation. There are narrow exceptions:
We log operator access to customer infrastructure and can show you the audit trail on request.
Under UK GDPR / EU GDPR you have the right to:
To exercise any of these, email us via the contact route — we aim to respond within 30 days.
We follow standard practice: encrypted transport (HTTPS everywhere), credentials stored in secret stores rather than environment files, principle of least privilege for operator access, and regular dependency updates. Nobody can promise zero risk. If we ever discover a breach affecting you, we'll tell you and the relevant supervisory authority within the timeframes the law requires.
productharvest.org and hosted Winnow are not intended for, or directed at, anyone under 16. We don't knowingly collect data from children.
If we change this policy materially, we'll update the Last updated date at the top, and where the change affects existing users, we'll notify you directly by email. Minor wording fixes happen without notification.
Questions about this policy, or to exercise any of your rights: hello@productharvest.org, or use the contact page.