VideoHarbor
Privacy Policy
VideoHarbor parses and downloads user-authorized public, non-DRM media on Android. Parsing runs on your device without a Toolensa parsing backend, while browsing and downloads connect directly to the sites and media CDNs you choose.
1. Scope
This policy applies to VideoHarbor for Android, package com.videoharbor.video_harbor, distributed by Toolensa. Browsing and parsing do not require sign-in. Purchasing or restoring Pro requires email verification. The app has no advertising SDK; limited failure reports are described below.
VideoHarbor accepts a pasted or shared web address, or opens a site in an embedded Android WebView. It analyzes public page information on the device and saves media selected by the user to Android's downloads collection.
2. Data processing
The app can process URLs, page titles, thumbnails, durations, public page data, media manifests, formats, resolutions, resource URLs, user agent, referer, request headers, signature parameters, and cookies required for the requested page or download.
Task records can include source and media URLs, title, format, filename, progress, status, request headers, and temporary cookies or tokens needed to pause, resume, or recover a task. Theme, Wi-Fi-only, recovery, and quality preferences are also stored locally.
Pro accounts, payments, and devices
Supabase Auth processes your email address, verification code, user ID, and login session. Session tokens are stored in secure device storage. Toolensa uses Cloudflare to process plan, order/subscription ID, payment and refund status, and timestamps for payment verification and purchase restoration. PayPal processes payment details in your system browser. With your consent, Pro binds to one device using a SHA-256 digest of the app-scoped Android ID, device model, and consent/binding records. These services do not receive your media URLs, browser cookies, or downloaded files.
Configuration, updates, and failure reports
The app contacts Toolensa services hosted on Cloudflare for site configuration, update checks, and APK downloads. Failure reports contain site identifier, release environment, app build, parser version, processing stage, error code, duration, event ID, and a random identifier that changes daily. They exclude URLs, titles, cookies, accounts, media files, and raw error stacks. Local failure queues retain up to 100 records for up to 7 days; server records are retained for up to 14 days. Network service providers may process connection IP addresses and operational logs.
Feedback you submit
If you use the in-app feedback form, Toolensa receives the email address and message text you type, plus a random submission ID. The email address is not verified and is used only to reply. Feedback is stored on Cloudflare for up to 90 days. The form does not attach your account token, device identifier, payment details, media URLs, or browsing history, and IP addresses are not stored with the submission. Do not include passwords or other sensitive information in the message.
3. Websites, media CDNs, and third parties
VideoHarbor does not use a Toolensa parsing server. Your device connects directly to websites you open, their public endpoints, and the media origins or CDNs that serve the selected file. Those parties can receive IP address, user agent, cookies, URL, referer, page requests, form contents, account activity, download requests, and normal access logs.
Web pages may load their own advertising, analytics, login, player, or other third-party resources. Their privacy policies and terms govern that processing. VideoHarbor does not bypass login, payment, membership, private access, regional, age, or DRM controls.
Use VideoHarbor only for public, non-DRM media you have the legal right and the source site's permission to access and save.
4. Cookies, tokens, and browser sessions
Android WebView stores cookies, site storage, and cache in the app sandbox so sites can function. When you ask the app to parse or download, the on-device engine may use the current site's cookies, referer, user agent, and required request headers.
If you sign in to a third-party website, credentials and form data are submitted to that site, not to Toolensa. Temporary session data can be sensitive. Do not share app-data backups or diagnostic material containing task metadata.
5. Permissions, storage, and security
- Internet: loads pages, inspects public media information, and downloads selected files.
- Android sharing: reads only the text link you intentionally share to VideoHarbor.
- MediaStore or legacy storage: saves completed downloads in Download/VideoHarbor.
Task metadata is kept in app-private storage and sensitive task fields are protected with a device key. Completed media in the shared downloads collection is no longer protected by the app sandbox and may be accessible to other authorized apps or device users.
6. Retention, deletion, and Toolensa sharing
Task and browser data remains until removed in the app, app storage is cleared, or the app is uninstalled. Completed media must be deleted separately from Android's downloads collection. Clearing local data does not erase logs retained by websites or CDNs.
Toolensa account, payment, configuration, update, and failure-report services are separate from on-device media parsing. Uninstalling the app does not delete server-side account, purchase, or device-binding records. Contact support for account or transaction deletion requests.
7. Children, changes, and contact
VideoHarbor is a general utility and is not directed to children. Material policy changes will be posted here with a revised effective date.
Privacy questions: [email protected]. Product help: [email protected].