Haven — Privacy Policy
Last updated: 5 July 2026
⚠️ Draft for legal review. This is a working draft prepared from Haven's actual technical stack (Supabase, RevenueCat, Apple/Google Sign-In, Expo push notifications, AWS S3, OpenAI, Vercel) and its Swedish/EU launch market. It is not legal advice and must be reviewed by a qualified data-protection lawyer for GDPR compliance before publication. Confirm the third-party list against the shipping build, and complete all text in [square brackets].
1. Introduction
This Privacy Policy explains how Atlan Insights AB, org. no. 559425-1398, Brantingsgatan 51, 113 53 Stockholm, Sweden ("Haven", "we", "us") collects, uses, and protects your personal data when you use the Haven meditation and sleep app and related services (the "Service").
We are the data controller for the personal data described here. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Swedish data-protection law.
By using the Service you acknowledge this Policy. Where we rely on your consent, we ask for it separately.
2. The personal data we collect
We collect only what we need to run the Service.
2.1 Data you provide
- Account data. When you sign in with Apple or Google, we receive your name and email address (or, with Sign in with Apple, a private relay email if you choose to hide yours). We store a user identifier for your account.
- Communications. If you contact support, we keep your messages and contact details.
2.2 Data created through your use of the Service
- Usage and content data. Your activity in the app — meditations and sleep stories played, sessions completed, streaks, favourites, reminder settings, and preferences.
- Subscription and purchase data. Which plan you have, trial status, renewal and cancellation status, and purchase history, received via RevenueCat and the app stores. We do not receive or store your full payment-card details — payments are processed by Apple or Google.
2.3 Data collected automatically
- Device and technical data. Device model, operating-system version, app version, language, time zone, and a device/installation identifier, used for delivering the Service, security, and diagnostics.
- Push-notification token. If you enable notifications, we store a push token so we can send reminders (for example, the trial-ending reminder and practice reminders).
- Log data. Basic technical logs generated when the app communicates with our backend.
We do not use the Service to collect special-category health data about you. Haven is a wellness product, and your meditation activity is used to operate the app, not to infer medical conditions.
3. How and why we use your data, and our legal bases
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and manage your account; authenticate you | Account, device data | Performance of a contract (Art. 6(1)(b)) |
| Provide the Service — deliver content, save progress and preferences | Usage/content, account, device | Performance of a contract |
| Manage subscriptions, trials, renewals, and refunds | Subscription/purchase data | Performance of a contract |
| Send service messages and reminders (incl. trial-ending reminder) | Account, push token, subscription data | Performance of a contract / consent for push notifications |
| Keep the Service secure, prevent fraud and abuse | Device, log data | Legitimate interests (Art. 6(1)(f)) |
| Fix bugs, improve and develop the Service | Usage, device, log data | Legitimate interests |
| Comply with legal, accounting, and tax obligations | Purchase, account data | Legal obligation (Art. 6(1)(c)) |
| Marketing communications, if any | Contact data | Consent (Art. 6(1)(a)) — where required |
Where we rely on legitimate interests, we have balanced those interests against your rights. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
4. Push notifications
If you allow notifications, we use them to send reminders — including the reminder before a free trial ends and any wind-down or practice reminders you set. You can turn notifications off at any time in your device settings; doing so may mean you no longer receive the trial-ending reminder, and you remain responsible for cancelling in time (see the Terms).
5. Who we share your data with
We do not sell your personal data. We share it only with service providers ("processors") who process it on our behalf under data-processing agreements, and with the app stores. Our main providers are:
| Provider | Purpose | Notes |
|---|---|---|
| Supabase | Authentication, database, and backend hosting | Stores your account, usage, and preference data. Hosted in the EU (European region). |
| Apple (Sign in with Apple, App Store) | Authentication and payment processing | Governed by Apple's privacy policy. |
| Google (Google Sign-In, Google Play) | Authentication and payment processing | Governed by Google's privacy policy. |
| RevenueCat | Subscription management and purchase status | Receives a user identifier and purchase events. |
| Expo (Expo Application Services) | Delivery of push notifications | Handles push tokens/messages. |
| Amazon Web Services (S3) | Storage and delivery of audio/media content | Hosted in the EU (European region). |
| Vercel | Hosting of our website/web services |
We use OpenAI to generate meditation and sleep content in advance (from generic themes, not from anything about you). No personal data is sent to OpenAI, so it is not a processor of your personal data.
We may also disclose data where required by law, to enforce our Terms, or in connection with a corporate transaction (e.g. merger or acquisition), in which case we will notify you where required.
6. International data transfers
Your core account, usage, and content data is stored on infrastructure located in the EU/EEA (Supabase and AWS S3, both in a European region). Some other providers we use — for example RevenueCat, Expo, Vercel, Apple, and Google — may process certain data outside the EU/EEA, including in the United States. Where that happens, we rely on appropriate safeguards under the GDPR — such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You can request more information using the contact details below.
7. How long we keep your data
We keep personal data only as long as necessary for the purposes above:
- Account and usage data — for as long as your account is active. When you delete your account, this data is deleted within 30 days, unless we must keep specific items longer to meet a legal obligation.
- Purchase and transaction records — retained as required by Swedish accounting and tax law (generally 7 years).
- Support communications — up to 24 months.
- Logs — up to 90 days.
(Retention periods are our current policy; adjust with your data-protection adviser if your practices differ.)
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict or object to certain processing, including processing based on legitimate interests and any direct marketing;
- data portability — receive your data in a portable format;
- withdraw consent at any time where processing is based on consent.
To exercise any right, contact us at support@gethaven.io. We will respond within one month. You can also delete your account and all associated data directly in the app under Profile → Delete Account.
Right to complain. If you believe we have mishandled your data, you may lodge a complaint with the Swedish data-protection authority, Integritetsskyddsmyndigheten (IMY) — Box 8114, 104 20 Stockholm, www.imy.se — or with the authority in your EU country of residence. We would appreciate the chance to address your concern first.
9. Children
The Service is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided us data without appropriate consent, contact us and we will delete it.
10. Security
We use technical and organisational measures to protect your data, including encryption in transit, access controls, and secure credential storage on your device (Apple Keychain / Android Keystore via secure device storage). No system is completely secure, but we work to protect your information and will notify you and the authorities of a data breach where the law requires.
11. Cookies and our website
The Haven mobile app does not use cookies. Our website uses only strictly necessary cookies to function and keep you signed in; it does not use advertising or third-party analytics cookies. Full details are in our Cookie Policy. If we ever introduce non-essential cookies, we will ask for your consent first.
12. Changes to this Policy
We may update this Policy. If we make material changes, we will notify you by reasonable means (in-app notice or email) before they take effect. The "Last updated" date above shows the latest revision.
13. Contact
Atlan Insights AB — Data Controller Brantingsgatan 51, 113 53 Stockholm, Sweden Organisation number: 559425-1398 Privacy enquiries: support@gethaven.io General support: support@gethaven.io
This Policy should be read together with Haven's Terms and Conditions.