HavnOS — Haven Operating System
← HavnOS

Privacy Policy

What we collect, why we collect it, and the things we will not do with it.

Last updated 27 August 2026

Plain-English draft. This describes accurately what the software does today, written by the people who built it rather than by a lawyer. It has not yet been through legal review. If you need a contractual guarantee before uploading something sensitive, write to privacy@havnos.com and wait for the reviewed version.

What we collect

Your email address and the documents and details you give us about your home — inspection reports, contracts, policies, warranties, receipts, and anything you type in yourself. We also keep a record of actions you take in the product, like completing a task or filing a document, because that history is the product.

Why we read your documents

To build your record: the systems and appliances in your home, the maintenance they need, and the dates and obligations your paperwork contains. Reading happens when you ask for it, on the document you chose.

AI processing

Documents are read using Anthropic's Claude models through their API. Anthropic does not train on data sent through the API. We do not train any model on your documents and we do not build a shared model from customer data.

What we never do

  • We do not sell your data. Not to anyone, at any price.
  • We do not show advertising and do not let anyone pay to influence what the product tells you.
  • We do not share your documents with other users, including any inspector or realtor who referred you. An affiliate sees that you signed up. They do not see your house.

Who can see your files

You. Access is enforced in the database itself, per row, against your account — not only in the interface. A small number of staff can access production systems where it is necessary to operate or debug the service.

Our infrastructure providers necessarily hold the data to serve it: Supabase (database, sign-in, file storage), Vercel (hosting, and the first place an uploaded document is stored), Anthropic (document reading), Postmark (email), Stripe (payments — card details go directly to Stripe and never reach our servers), and Google Sheets, which receives the email address and report link of anyone who asks us to email them their report.

Sensitive information in your documents

Real estate paperwork often contains social security numbers, bank details and signatures. Treat everything you upload as something worth protecting, because it is. Turning on two-factor authentication is the single most effective thing you can do, and we will keep asking you to once you are on a paid plan.

Redaction now runs on every document we read. Before anything is stored or shown, we scan what the reader extracted for social security numbers, bank and card numbers and similar identifiers, mask them, and flag the document so you can see what was found. If you would rather the file itself were gone, you can shred it from the document view and keep the record without the original.

Being exact about the limit, because the difference matters: we redact what the reader returns. The original file is still uploaded and still passes through the reading service intact. So redaction protects what we keep and display — it does not mean a social security number was never transmitted. If a document contains something you do not want leaving your machine at all, black it out before uploading.

Keeping and deleting

We keep your data while your account exists. Cancelling a paid plan does not delete anything — you move to the free plan and your record stays.

You can delete your account yourself, from Account → Deleting your account. Every property, document, photo, task and vendor goes, and the files themselves are removed from storage — not just the records pointing at them. There is no bin and we cannot get it back. If you would rather a person did it, write from the address on the account to privacy@havnos.com. You can also ask for a copy of what we hold.

If you never made an account. Upload a report without signing up and we keep it for 30 days so your link works, then delete the file and the reading. Ask us to email you the link and we keep it the same 30 days.

What we cannot pull back. A document read by our AI provider is sent to them to be read. We ask them to delete it, but we cannot promise what a third party has already logged. If a document is sensitive enough that this matters, do not upload it.

Cookies

Session cookies to keep you signed in, a cookie remembering which of your homes you are looking at, and a referral cookie for ninety days if you arrived through an affiliate link. No advertising trackers.

Changes

Material changes will be announced by email to account holders rather than by quietly editing this page. See also our terms.