Google access
Harbor uses Google OAuth with the scopes needed to identify the connected account and operate its Drive. The current beta requests openid, email, profile, and full Google Drive access because creating, editing, moving, trashing, and seeing existing files cannot work with narrower file-only access.
OAuth tokens are stored in the macOS Keychain. Harbor uses the Google account’s stable identifier internally and shows the account email so you can distinguish connected accounts.
Data on your Mac
Harbor keeps account information, file metadata, transfer state, and bounded diagnostic records locally in its app-group container. Downloaded content is managed through Apple’s File Provider system and appears in Finder.
Cloud-only placeholders can remain visible without storing the complete file locally. Opening a file asks macOS and Harbor to retrieve the content from Google Drive.
Network path
The Harbor app communicates directly with Google Drive from your Mac. The current beta architecture does not route your Drive files through a Harbor-hosted storage service. The File Provider extension itself reads local state and delegates network work to the app-side sync engine.
Diagnostics
Harbor records operational details needed to explain transfers, retries, connection health, and recovery. Diagnostic records are intended to describe operations without requiring private file contents. If support asks for information, review what you share and never send OAuth tokens.
Your control
You can revoke Harbor’s Google access from your Google Account. Removing or reconnecting an account in Harbor affects its local Finder connection; deleting a file through Harbor sends it to Google Drive trash rather than permanently deleting it immediately.
Questions about the beta can be sent to support@harbor.direct. A final legal privacy policy, including any website-level processing and retention terms, must be approved before broad public distribution.