Skip to content
Harbor

Privacy

Last updated 7 September 2026

The short version

Harbor runs on your computer. You can play local media without a Harbor account. Optional online features are different: accounts, profiles, sync, community features, and bug reports can send information to the services that provide them. Sources you connect have their own data practices.

This page explains that distinction. For general questions, ask in the GitHub repository. Issues are public, so please do not include private account information, credentials, or source URLs.

How we handle your information

  • A Harbor account is optional. Local playback does not require one.
  • We do not sell or rent your personal information or use it for advertising.
  • Account and profile identifiers are used by the optional account and sync features. Those features can keep information between sessions and across devices.
  • The built-in bug report forms are opt-in. Submitting one sends the report and its included diagnostics.
  • We do not voluntarily give private account or settings data to copyright complainants merely because they ask. Providing requested features, sharing at your direction or with consent, and complying with applicable law or valid legal process are separate matters. See privacy and disclosure.
  • Configured-key diagnostics use presence flags, but text, error messages, and attachments can still contain sensitive information. Do not submit secrets or private links.

What stays on your device

Harbor stores local app settings, libraries, watch history, addon configuration, and credentials on your device. There is no mandatory Harbor account or sync service. Local storage does not mean a value can never be transmitted: using connected services, turning on sync, or submitting a report can send relevant information outside your device.

  • Credentials and API keys are used to authenticate requests for services you connect. Their use depends on the service and feature.
  • Downloads, cached artwork, and downloaded subtitles are files on your disk. Backups and other copies may remain after you delete a file.
  • Uninstalling the app may leave app data, downloads, or backups behind. It does not delete an online account, an uploaded report, or data already stored by a connected service.

What Harbor sends, and to whom

Online features make network requests for things such as metadata, configured sources, account access, sync, community features, reports, and updates. Enabled features can also make background requests. You can inspect the source or use a network inspection tool to review them.

Some requests go to a provider you connect; others go to the endpoints that run Harbor's optional services. Operators and their infrastructure may receive your IP address and other request information. Their own privacy policies apply. Harbor cannot promise that those services keep no logs.

Peer-to-peer transfers also communicate with other participants and may upload data. Other participants can see network information such as your IP address. Harbor is not an anonymity service. Use only sources you have the legal right to use.

The optional Harbor profile

Harbor's account and social features are optional. Creating an account sends registration information to the account service; signing in uses authentication information and session tokens.

Profile information and things you choose to publish are stored online to provide those features. Public items can be seen by other people. Visibility settings affect what is shown publicly; they do not mean the service has no stored record.

Use the available account and visibility controls for the feature you use. Deleting a local profile, signing out, or uninstalling the app should not be treated as confirmation that every server-side copy, report, or backup has been removed.

Syncing across your devices

Sync is optional and uses an authenticated account to share supported information across devices. Depending on the version and features you enable, that includes profile details, selected settings, layout and theme information, and markers recording which profile watched a title. It is not limited to visual preferences.

Turning sync on sends supported data to the sync service so another device can fetch it. A watched-title marker identifies a title and profile; it is different from uploading the media file or a playable stream.

You do not need sync for local playback. Turning it off stops using that feature; it does not by itself establish that previously uploaded information has been deleted.

Reporting a bug

The form in settings and the button on the error screen let you submit a bug report. Both are opt-in.

A settings report includes what you wrote, files you attach, and diagnostics such as app version, operating system, browser engine, window size, language, setup flags, player availability, and recent error messages. Display name, GitHub handle, and contact details are optional report fields.

Configured-key flags indicate whether a key exists instead of deliberately listing its value. That is not a guarantee that every report is free of sensitive information: your text, files, and recent error messages can contain paths, URLs, tokens, or other private details. Both report paths can include recent errors.

Reports are stored online to investigate problems with Harbor. Deleting the app does not delete a submitted report. Please review what you submit and leave out secrets and unrelated personal information.

Addons and services you connect

Harbor is a client. The addons and sources you add are chosen by you and run on infrastructure we do not control. Harbor does not host the media you access or operate a public index of playable media sources. Please abide by all applicable laws and only access sources you have the legal right to use.

Connecting a service can send requests, account information, title identifiers, and other data needed for that service. Its operator decides what it logs and how it handles that information. Read the service's terms and privacy policy before connecting it.

Kids profiles

Harbor has a kids mode. It is a restricted local profile an adult can configure and optionally protect with a PIN. These controls help an adult manage a child's use of the app; they do not replace supervision or establish that every connected source is suitable.

If an adult enables profile sync, supported child-profile information and restrictions can sync alongside other profiles. The current sync format includes profile names, avatars, age and restriction settings, and watched-title markers. Local PIN hashes are not included in that profile sync format.

Please consider what profile information you enter and which online services you enable. A child using a connected service is also subject to that service's data practices. A local restricted profile is not a promise that no information can leave the device.

Where online data is handled

The optional profile services use infrastructure operated by ElfHosted. Linux package repository hosting is provided by Cloudsmith. Repository access and public issues use GitHub.

Hosting and service providers process the requests sent to their infrastructure and may keep operational or security records under their own policies. A free service or an account-free download does not mean the host receives no information.

Retention and deletion depend on the feature, the operator, backups, and applicable legal requirements. This page does not promise that uninstalling Harbor, signing out, or deleting a public item removes all copies immediately. Harbor cannot make retention or disclosure promises on another operator's behalf.

Changes

If this policy changes, we will change the date at the top.

Questions

For general questions, open an issue on GitHub. Please keep private information out of public issues. For information held by a connected service or hosting provider, use that operator's published privacy channels. Copyright reporting routes are listed on the legal page.

Harbor is an independent, open source project and a client for the open Stremio addon protocol. It is not affiliated with, endorsed by, or associated with Stremio Ltd. Harbor is just code on a repo. It is not a company it is not a entity nor is it a organization we do not profit from Harbor. You are responsible for choosing lawful sources and complying with the laws that apply to your use. See the legal notice for warranty and liability terms, which apply only to the extent permitted by law. We believe in the freedom of speech and right to privacy.

Feature availability can vary by version. This page will be updated as the app and its optional services change.

Back to Harbor