Trust HavenPrivate sharing for real life
Get started

Privacy policy

Privacy is the product boundary.

Last updated: May 29, 2026. This policy explains how Trust Haven collects, uses, discloses, retains, and protects personal data.

We will NEVER sell data

We do not sell, rent, trade, license, barter, or broker personal data for money or any other value.

No targeted advertising

We do not share personal information for cross-context behavioral advertising or ad network profiling.

No AI training

Private profiles, posts, identity evidence, and activity data are not licensed for AI training or retrieval systems.

Access is scoped

Private content is shown only through authenticated sessions and server-side permission checks.

We will NEVER sell your personal data.

Who this privacy promise covers

This policy applies to Trust Haven, including the web application, API, invite links, registration flow, and authenticated workspace. If a separate written agreement applies to a specific deployment, that agreement controls only where it gives users stronger privacy protections.

01

What we collect to run private spaces

Account data: legal name, email address, verification status, passkey credential metadata, session records, and basic account timestamps.

Identity verification data: verification method, document type when provided, evidence status, provider references, review status, and related timestamps. The current MVP records verification metadata; production identity evidence must use private storage or a restricted verification provider.

Profile and content data: display names, handles, bios, profile posts, media URLs, groups, access levels, person notes, and invite metadata.

Security and access data: hashed invite tokens, hashed session tokens, recipient lookup hashes, IP lookup hashes, encrypted user-agent data, resource views, audit logs, and abuse-prevention signals.

Payment data if monetized later: subscription state, Stripe customer and subscription identifiers, and payment confirmation records. Payment card numbers must stay with the hosted payment processor and must not be collected by this app.

02

How we use your data

Create and protect accounts with passkeys, so people can sign in without reusable passwords that can be guessed, phished, or leaked.

Verify identity, prevent impersonation, and decide whether access should be granted.

Operate private profiles, groups, invites, posts, viewing history, and access controls.

Detect abuse, investigate security events, preserve audit trails, and protect private spaces from automated access.

Communicate service, security, account, legal, or policy notices.

Comply with law, enforce rights, respond to valid legal process, and protect users or the service.

03

What you can control

Access or know what personal data is associated with your account.

Correct inaccurate account or profile information.

Delete your account from the Profile section or request deletion of personal data, subject to security, fraud-prevention, legal, audit, processor, and backup-retention limits.

Export or receive a copy of account data where required by law and technically feasible.

Object to or limit certain processing where applicable law gives that right.

Exercise privacy rights without discrimination.

04

How we protect access

Trust Haven uses passkeys, scoped access checks, expiring invites you can turn off, protected session cookies, audit logs, bot deterrence controls, and encryption or keyed lookup hashes for sensitive fields where implemented. No policy can guarantee perfect security, so access is designed to be limited, reviewable, and removable.

Data is kept only as long as needed for the service, security, audit, legal, backup, and dispute-resolution purposes. Invite tokens expire, refresh, and can be turned off; invite and session secrets are stored only as hashes. Identity verification, audit, access, and payment records may be retained longer where necessary to prevent abuse, prove consent, comply with law, or protect users.

To make a privacy request, contactprivacy@trusthaven.app