Privacy Policy
Effective date: September 26, 2026
Havn.ai, a product of Webs Spun Right, LLC (“Havn.ai,” “we,” “us”), helps homeowners organize and understand their property-insurance claims. Because that means you trust us with sensitive documents, this policy is written to be read: what we collect, why, who touches it, and how you delete it.
1. Information we collect
On this website
- Waitlist signups. If you join the waitlist, we keep your email address (and your name, if you share one) to notify you about availability, together with basic submission context — the page the signup came from and your browser's user-agent string — used only for spam triage. You can ask us to remove you at any time.
- Website analytics. We use Google Analytics to understand how this website is used — pages visited, general region, and device type. It sets analytics cookies; we do not use advertising features, and this data never identifies you to us. We set no advertising cookies.
- Fonts. This website loads its typeface (Nunito) from Google Fonts. Your browser requests the font files from Google's servers (fonts.googleapis.com and fonts.gstatic.com), and that request carries your IP address and browser details, as any web request does. The app does not do this — it bundles its own fonts.
In the app
- Account information. Your email address, used to sign you in and send you sign-in codes.
- Claim information you enter. Property address, type of loss, date of loss, insurance carrier, policy and claim numbers, deductible, expenses, mileage, timeline events, and payments you record.
- Documents you upload. Insurance policies, receipts, letters, contractor and insurer estimates, and photos — along with text and structured fields extracted from them (for example, a receipt's vendor, date, and amount), which you review and confirm. Photos may carry metadata your camera embeds in the file (such as capture time and location); it is stored and processed with the file like the rest of its content, and removed with it when you delete the document or claim.
- Assistant conversations. Questions you ask about your claim and the answers generated from your documents.
- Usage and technical data. Basic usage counts (for example, documents uploaded and messages sent, used to enforce plan limits), app version, and audit records of privileged access to your data.
- Feature-usage analytics. Counts of screens visited and features used (with platform and app version), linked to your account so we can count active users. These events never include your documents, amounts, addresses, or any claim content, and you can turn them off any time in Settings → Privacy. The web app additionally uses Google Analytics (analytics cookies only, no advertising features or Google signals), which honors the same setting.
- App updates. When the mobile app launches, it checks Expo's update service (u.expo.dev) for a newer version of the app's code and downloads one if it exists. That request carries the app's version and platform, the update channel, and an identifier for the installation — no account, claim or document data.
- Crash and error reports. When the mobile app crashes, or a screen fails with an error (even one it recovers from when you tap “Try again”), it sends a report to our error-monitoring provider, Sentry: the error message and where in the app's code it happened, the app version, device details (such as model, operating-system version, language and time zone), and a short trail of what led up to it — the addresses of recent network requests, without their query details. As with any web request, Sentry sees the network address such a report is sent from. When the web app hits the same kind of error, whether or not you are signed in, it sends a smaller report through our own server instead: the kind of error, its message with email addresses, identifiers and long numbers removed, where in the app's code it happened, the screen it was on (without the identifiers in its address), the app version and your language. Our server passes it on to Sentry, so Sentry does not see your network address; to limit how many reports one source can send, our server keeps a one-way, salted hash of that address with a daily count, for a week. We configure all of these reports to leave out your name, email address and account identity, and any link to your stored files; they are used only to find and fix bugs. When one of our servers hits an unexpected error, it reports only the kind of error, which function it was in and the status it returned.
2. How we use your information
- To provide the product: organizing documents, extracting fields for your confirmation, tracking expenses, comparing estimates, answering your questions from your own documents, and generating reports.
- To operate accounts, enforce plan limits, prevent abuse, and keep the service secure.
- To respond when you contact support or report a problem.
- To send service messages (like sign-in codes and, if you enable them, deadline reminders). We do not send marketing without your consent.
3. AI processing
Havn.ai uses AI service providers to read documents you upload and to answer questions you ask. When you use those features, the relevant document text or question is sent to the provider to generate the result, then returned to your claim.
- Our AI providers process your content solely to provide the service. We use provider settings under which your content is not used to train their models.
- AI answers are grounded in your documents and cite their sources; extracted values are shown to you for confirmation before your claim relies on them.
- AI output is informational — it is not legal, financial, or insurance advice.
4. Who we share information with
We never sell your personal information, and we don't share it for advertising. We share it only with:
- Service providers that run the product on our behalf: cloud hosting and database/storage (Supabase), AI processing (Anthropic and OpenAI; document OCR via AWS Textract), document-pipeline orchestration (n8n Cloud, which document text and processing instructions pass through), transactional email delivery (Brevo), address search and driving distances (Esri/ArcGIS and the US Census geocoder — these receive the addresses you type or save when you use address suggestions and mileage features), and replacement-price lookups (DataForSEO — it receives the item name you search for, never your claim details), contractor billing (Stripe — when a Havn Pro workspace turns on billing, card details are entered on Stripe's own pages and never touch our servers; we receive the subscription's status, seat count, amount and billing period), website analytics (Google Analytics, described in section 1), and crash and error reporting (Sentry — it receives the error reports described in section 1, never your documents or claim details). Each receives only what its function requires.
- Payments. When you buy a Claim Pass or Plus, the purchase is made through the Apple App Store and validated through our subscription provider (RevenueCat). We receive your purchase and entitlement status; we never see your card number, which is handled by Apple.
- People you choose. If you email a report to someone, or link a contractor's Havn Pro workspace to a claim (section 5), they see what you shared.
- Legal requirements. If required by law or valid legal process, or to protect the rights, safety, and security of Havn.ai and its users.
5. Havn Pro and contractors
Havn Pro is the version of the Service for restoration contractors. A Pro workspace holds what its clients choose to share, and information flows through it in three ways.
- If you are a homeowner who links a contractor. Only a claim's owner can link a contractor's workspace to it, from an invite link the contractor gives you, and the app shows you exactly what will be shared before you confirm. Once linked, the workspace's members can see the claim's details and coverage summary (carrier, policy and claim numbers, deductible and limits), its documents and photos except receipts, its estimates and their line items, scope decisions, the payments and disbursements you've recorded, timeline events, the contacts recorded on the claim (names, emails and phone numbers), and a message thread shared with them. They never see your expenses, mileage, belongings inventory, receipts, assistant conversations or generated reports. They can add their own estimates, photos and messages to the claim, which you can see and delete; they can't edit or delete anything of yours, and they can't share the claim onward. You can unlink them at any time from the claim's Contacts screen — their access ends immediately, and anything they added stays on your claim.
- If you are a contractor. We collect your business email address, your company's name, and the email addresses and roles of the team members you invite. Client claim data you can see remains the homeowner's: it is shared with your workspace under the rules above and withdrawn when they unlink you. When your workspace turns on billing, Stripe processes it (section 4).
- Invite links. If you created your Havn.ai account through a contractor's invite link, we record that you arrived through that link — the workspace and your account, nothing about your claim.
6. How we protect your information
- Encryption in transit and at rest.
- Per-account isolation enforced in the database itself (row-level security), so your claim data is only reachable by you and people you've invited.
- Documents live in private storage; they are never publicly accessible and are only served through short-lived, membership-checked links.
- Administrative access to customer content is restricted, gated, and audit-logged.
7. Retention and deletion
- Your data is retained while your account is active so your claim history stays available to you — claims often run for months.
- You can permanently delete a claim at any time from inside the app. Deletion is a hard delete: claim records, documents, extracted text, and stored files are all removed.
- You can permanently delete your account from inside the app (Settings → Delete account) or by emailing info@myhavn.ai. Deletion removes every claim you own — their records, documents, extracted text and stored files — along with your generated reports, any bug-report screenshots you sent us, and your sign-in account itself. We keep a record that the deletion happened (counts only, no content). A purchase you made through Apple stays in Apple's and RevenueCat's records under their policies. Residual copies in encrypted backups are purged on the backup rotation schedule.
8. Your rights
Depending on where you live (for example, under the California Consumer Privacy Act), you may have rights to access, receive a copy of, correct, or delete your personal information, and to not be discriminated against for exercising those rights. We extend these rights to all users regardless of location: contact info@myhavn.ai and we'll respond within 30 days. We do not sell or share personal information as those terms are defined under the CCPA.
9. Children
Havn.ai is not directed to children and is intended for users 18 and older. We do not knowingly collect personal information from anyone under 13; if you believe a child has provided us information, contact us and we will delete it.
10. Changes to this policy
If we make material changes, we will update the effective date above and notify you in the app or by email before the changes take effect.
11. Contact
Questions, requests, or concerns: info@myhavn.ai. See also our Terms of Service.