Haven IQ

Mentions légales

Politique de confidentialité

Haven IQ existe pour conserver les informations les plus sensibles de votre vie. Cette politique explique — en langage clair — ce que nous collectons, comment ces données sont utilisées, qui peut les voir, combien de temps elles sont conservées et le contrôle dont vous disposez sur l'ensemble.

Le titre et le résumé de cette page sont affichés en français pour votre confort. Le texte juridique complet ci-dessous est maintenu en anglais, et la version anglaise est la version officielle qui prévaut en cas de divergence.

Dernière mise à jour : July 20, 2026

1. Who we are

Haven IQ is operated by Haven IQ Solutions("Haven IQ," "we," "us"). The service is available at haveniqsolutions.com (public website) and app.haveniqsolutions.com (the application). For anything in this policy, you can reach us at [email protected].

2. Information you provide

Haven IQ is a place you deliberately put information, so most of what we hold is there because you added it:

  • Account information — your name, email address, and password. Passwords are handled by our authentication provider (Supabase Auth) and are never visible to us in plain text.
  • Profile and household information — names, birthdays, relationships, and other details you record about yourself and the people (and pets) in your household.
  • Documents and images — files you upload, such as insurance policies, medical records, financial statements, legal paperwork, and identity documents.
  • Structured records — calendar events, tasks, reminders, contacts, assets, bills, financial accounts (masked to the last four digits — full account numbers are never stored), insurance details, and medical information you enter or approve.
  • Credentials and secrets — passwords and codes you save in the vault. These are encrypted with an additional layer of AES-256 encryption and are decrypted only when you explicitly reveal them. Government ID numbers (such as SSNs and passport numbers) get the same treatment.
  • AI conversations — messages you exchange with the assistant, and the suggestions it produces for your review.
  • Communications — messages you send us through the contact form or by email.

3. Information collected automatically

  • Security and log data — when you sign in or perform sensitive actions, we record security events (for example: sign-ins, password changes, secret reveals) including limited device and network information such as IP address. IP addresses shown back to you in your security activity feed are partially masked.
  • Server logs — our infrastructure providers keep short-lived operational logs (requests, errors) that can include IP addresses. We deliberately exclude document contents, passwords, tokens, and email addresses from our application logs.
  • Cookies — a small set of first-party cookies for sign-in, theme, and onboarding preferences, plus — only with your consent — Google Analytics cookies on the public marketing website only. We use no advertising cookies, and no analytics of any kind inside the app — where your documents and records live, nothing measures you. See the Cookie Policy for the complete list.
  • Website analytics — the public marketing pages use Google Analytics to count visits and traffic sources, and only after you allow it in the consent banner; declining loads nothing from Google. The application itself sends usage events nowhere. If we ever enable a product-analytics service inside the app, this policy and the Cookie Policy will be updated first.

4. How we use your information

  • To provide the service: storing, organizing, and displaying what you add.
  • To power features you invoke: extracting details from documents you upload, answering assistant questions, generating reminders and insights.
  • To send the emails you've chosen: reminders, document-processing notices, household invitations, security alerts, and product updates — each controllable in Settings → Preferences, and reminder emails carry a one-click unsubscribe link.
  • To keep accounts secure: authentication, abuse prevention, and security logging.
  • To respond when you contact us.

We do notsell your information, rent it, use it for advertising, or use it to train AI models. There is no "data monetization" in this business model: you are the customer, not the product.

5. How AI processing works

AI is central to Haven IQ, so it deserves its own section — this is our AI transparency statement.

  • What is sent to the AI provider. When you upload a document, its contents are sent to our AI provider (Anthropic) to extract structured details — dates, amounts, policy numbers, renewal deadlines. When you use the assistant, your question and a narrow, relevant slice of your records are sent to generate the answer.
  • What is never sent. Vault passwords, household secret codes, and other encrypted values are withheld from AI processing by construction, with an additional automated filter that scrubs secret-shaped values from anything bound for the model.
  • The AI only sees what you can see.Assistant retrieval is scoped to the asking user — it cannot access another household member's private records.
  • Nothing is saved without your approval. The AI proposes; you decide. Extracted details and suggestions only become part of your records after you review and approve them, and your approval decisions are recorded.
  • No training on your data.We use Anthropic's commercial API, which does not use customer content to train models. AI providers may retain inputs briefly for abuse monitoring under their own policies.
  • AI can be wrong.Extraction and answers are assistive, not authoritative — that's why the review step exists, and why it's permanent.
  • You can turn it down. AI suggestions can be disabled in Settings → Preferences. Document extraction runs only on documents you choose to upload.

6. When information is shared

Your information is shared in exactly three situations:

  • With your household, on your terms.Records you mark shared are visible to members you've invited; records you keep private are not. Access is checked on our servers on every request.
  • With service providers who run the platform. These processors handle data only to provide the service to us: Supabase (database, authentication, file storage), Vercel (hosting), Anthropic (AI processing), Resend (email delivery), Inngest (background job processing), Google (visit analytics on the public marketing website only), and Stripe (payment processing, once paid plans launch). Each is bound by its own data-protection commitments.
  • When the law requires it. We may disclose information to comply with a valid legal obligation, or to protect the rights, safety, or security of users or the service.

That's the whole list. There are no data brokers, ad networks, or "partners."

7. Data retention and deletion

  • While your account is active, we keep what you've stored — that's the product.
  • Documents and records you deleteare immediately removed from your household's view and are permanently deleted no later than when your account is deleted. We are working toward automatic permanent purging of deleted items on a fixed schedule.
  • When you delete your account(Settings → Security), your household's records, uploaded files, and your sign-in identity are permanently deleted right away. There is no recovery window — deletion is immediate and irreversible.
  • What survives deletion:a minimal security audit trail (for example, "this account was deleted, when, by whom") retained for security and legal purposes, records we must keep to meet legal obligations (such as billing records once paid plans exist), and copies in our providers' encrypted backups, which age out over a limited period.
  • Operational logs are short-lived and rotate automatically.

8. Your rights and controls

Most control is built directly into the product:

  • Access and correction — everything you store is visible and editable in the app.
  • Deletion — delete individual records and documents anytime, or delete your entire account in Settings → Security.
  • Email choices — per-category email toggles in Settings → Preferences, plus one-click unsubscribe in reminder emails.
  • AI choices — disable AI suggestions in Settings → Preferences.
  • Sharing choices — per-record private/shared visibility, and an activity-visibility preference.

Depending on where you live — including the EU/UK (GDPR), California (CCPA/CPRA), Canada (PIPEDA), Australia, and New Zealand — you may also have legal rights to access, correct, delete, restrict, or receive a portable copy of your personal information, and to complain to your local data-protection authority. To exercise any right you can't complete in-app — including requesting an export of your data, which is currently handled by our team rather than self-serve — email [email protected]. We respond to verified requests within the timelines your local law requires, and we never discriminate against you for exercising them.

9. Where your data lives

Haven IQ is hosted in the United States(our database, file storage, and application infrastructure run in US regions). If you use the service from outside the US, your information is transferred to and processed in the US. Where local law requires safeguards for that transfer, we rely on our providers' standard data-protection terms and are building toward jurisdiction-specific mechanisms as we grow internationally.

10. Children's privacy

Haven IQ accounts are for adults (16+, or the minimum age in your jurisdiction), and we don't knowingly let children open accounts. Parents and guardians do, of course, store information about their children — school records, immunizations, birthdays. That information belongs to the account holder, is protected like everything else, and is deleted with the household.

11. How we protect it

Everything is encrypted in transit and at rest; genuine secrets (vault passwords, secret codes, government ID numbers) carry an additional layer of AES-256 encryption; access is verified server-side on every request; multi-factor authentication is available on every account; and security events are logged. The full picture — written in plain English — is on our Security page. To report a security concern, email [email protected].

12. Changes to this policy

When this policy changes, we'll update the date at the top and, for material changes, notify you by email or in the app before they take effect. Earlier versions are available on request.

13. Contact