Overview
Haven is built privacy-first. Your journal entries and sensitive health data are encrypted on your device. We cannot read them. We do not sell your data. We never will.
This Privacy Policy explains how Haven, a product of MODEX Apps (Tirana, Albania), collects, uses, and protects information when you use our mobile application or visit this website. By using Haven, you agree to this policy.
Haven is designed to help people manage their mental health. We understand the sensitivity of this information and treat it with the highest level of care.
What we collect
Information you provide
- Account information — email address and a display name, if you choose to create an account. An account is optional; see Anonymous Mode.
- Mood logs — the mood ratings and optional notes you record in the app.
- Journal entries — your private written entries. These are encrypted end-to-end on your device before any data leaves it.
- In-app responses — answers you give during CBT/DBT exercises, breathing sessions, or AI companion conversations.
Information collected automatically
- Basic usage analytics — screens visited, features used, session length. This data is aggregated and never tied to your identity.
- Crash reports — anonymous crash logs to help us fix bugs. No personal data is included.
- Device type and OS version — used only to ensure compatibility.
Information we do not collect
- We do not collect your precise location.
- We do not read your contacts, microphone, or camera unless you explicitly grant a specific permission for a feature.
- We do not build an advertising profile about you.
How we use your information
We use the information we collect only to operate, improve, and support Haven:
- To provide the app's core features — mood history, journal, exercises, and AI companion.
- To send important service messages (e.g. account-related emails). We do not send marketing emails without your explicit consent.
- To analyze aggregated, anonymous usage patterns so we can improve the product.
- To investigate and fix technical issues and security incidents.
We will never use your data to serve you advertising, sell you to data brokers, or make inferences about you beyond what is necessary to provide the app.
Encryption & security
Your journal entries are encrypted on your device using AES-256 before they are stored or synced. MODEX Apps holds no decryption keys.
We implement the following security measures:
- Client-side encryption — sensitive content (journal, AI conversations) is encrypted locally on your device before any data is transmitted.
- TLS in transit — all network communication uses TLS 1.2 or higher.
- Encrypted at rest — data stored on our servers is encrypted at the infrastructure level.
- Minimal data collection — the best way to protect your data is not to collect it in the first place.
No security system is perfect. If you discover a vulnerability, please report it to security@modexapps.com.
Anonymous mode
You can use Haven without creating an account. In anonymous mode:
- No email address or name is required.
- All your data is stored locally on your device only.
- We receive only anonymous crash reports and usage analytics (which are collected regardless of account status).
- If you uninstall the app, your data is deleted from your device.
Anonymous mode is permanent — you cannot later link an anonymous session to a new account and retain your history.
Sharing & third parties
We do not sell, rent, or trade your personal information. We may share data only in these limited circumstances:
- Service providers — trusted infrastructure partners (e.g. Supabase for database and auth, Cloudflare for hosting) who process data on our behalf under strict data processing agreements.
- Legal requirements — if required by law or valid legal process. We will notify you if legally permitted.
- Safety — if we have a good-faith belief that disclosure is necessary to prevent imminent harm to you or others.
Crisis resources (phone numbers, websites) displayed in the app are provided as information only. Calling or clicking them connects you directly with third-party organizations; their privacy policies apply.
Data retention
We keep your data for as long as your account is active or as needed to provide the service.
- You can delete your account and all associated data at any time from the app's Settings screen.
- Upon deletion, your personal data is removed from our systems within 30 days, except where we are required to retain it by law.
- Aggregated, anonymised analytics data (which cannot identify you) may be retained indefinitely.
Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Correction — request that inaccurate data be corrected.
- Deletion — request that your data be deleted ("right to be forgotten").
- Portability — request your data in a machine-readable format.
- Objection — object to certain types of processing.
- Withdrawal of consent — withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at privacy@modexapps.com. We will respond within 30 days.
If you are in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.
Children's privacy
Haven is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected data from a child under 13, please contact us immediately at privacy@modexapps.com and we will delete it promptly.
Users between 13 and 18 should use Haven only with the knowledge and consent of a parent or guardian.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will notify you through the app or by email if you have an account.
Your continued use of Haven after changes are posted constitutes your acceptance of the updated policy.
Contact
If you have questions or concerns about this Privacy Policy or how we handle your data, please reach out:
- Email: privacy@modexapps.com
- Company: MODEX Apps, Tirana, Albania
- Website: modex-page.pages.dev