Privacy-first, always watching, never surveilling. Here is how OneHaven collects, uses, and protects your data.
Effective date: July 30, 2026.
We collect the following categories of data when you use OneHaven:
Registration Data. Name, email address, phone number, and account credentials collected when you create an account.
Activation Data. Device pairing codes, invite tokens, and onboarding information collected when linking caregiver and protected member devices.
Personal Data. Profile information including name, date of birth, and relationship designations (for example, parent, child, co-caregiver).
Location Data. Precise GPS coordinates, approximate address, and location history from devices where location permission has been granted. Location is collected in the foreground and, when "Allow all the time" permission is granted, in the background while the app is closed. Location data is used to display family members on the family map, enable real-time location sharing within your care group, and support SOS alerts. Location data is shared only with members of your care group and is never sold or shared with third parties.
Device & Usage Data. Device identifiers, operating system version, app usage statistics, screen time data, and app activity collected from protected member devices to support monitoring and reporting features.
Managed User Data. Information about protected members (children or seniors) added to your account, including their device activity, app usage, and account settings.
Monitored Communications Data. App access requests, alert history, and activity logs generated by protected member devices.
Financial Monitoring Data. Payment information processed securely through our payment provider. We do not store full card numbers or payment credentials on our servers.
Notification & Contact Data. Emergency contacts, notification preferences, and caregiver contact information used to deliver alerts and SOS notifications.
Assessment Recipient Data. Where a verified caregiver arranges a Family Threat Assessment, we collect limited information about the person who receives it. This is described in full in section 18.
You are the data controller of monitored data. OneHaven acts as data processor for the purpose of providing Services.
We process data based on consent, contract, legal obligations, and legitimate interests.
We use data to provide and improve Services, display family member locations, deliver alerts and SOS notifications, enforce screen time and app controls, detect fraud, and communicate with you.
We share data only with trusted third-party service providers (for example, payment processors, analytics providers, security services). We do not sell personal data.
Data is stored in the United States unless otherwise stated. Monitoring logs are retained only as long as necessary for business, legal, or security purposes before secure deletion.
When data is transferred outside your country, safeguards such as Standard Contractual Clauses are applied.
Parental consent is required for accounts involving minors. No child may independently create an account. No person under 13 may be added as a protected member or named as the recipient of a Family Threat Assessment.
Enhanced security applies for seniors and other managed adults. Caregivers must verify their authority for managed senior accounts. Before enabling protection for any adult protected member, the caregiver must obtain that adult's prior, informed consent to the review of their outgoing content and to the use of the OneHaven keyboard, and the adult may withdraw consent at any time. OneHaven relies on the caregiver's representation that this consent has been obtained.
Individual users may manage their own accounts and monitoring preferences.
Depending on location, you may access, correct, delete, restrict, or port your data, or withdraw consent.
California residents have rights under the CCPA and CPRA, including: (a) right to know, (b) right to delete, (c) right to opt-out of sale or sharing of personal data, (d) right to limit sensitive data use. Residents of other states (VA, CO, CT, UT) have similar rights. To make a request, please contact us.
We use encryption, monitoring, and audits to protect your data.
Some Services use AI models to process communications, browsing, and fraud detection data. When enabled, the OneHaven keyboard or text input feature processes only the outgoing content the protected person composes or sends, so our AI can generate safety alerts, and it does not read incoming messages. AI outputs may not be fully accurate, may miss or misclassify content, and should be reviewed by caregivers rather than relied on as the only means of protection. Personal data is not used to train external AI models except in anonymized or aggregated form where legally permitted.
We will notify users of material changes to AI-driven features or privacy practices that affect how monitored data is processed.
Personal data is retained only as long as necessary for legitimate business or legal purposes. Deletion requests may be submitted by contacting us.
The link checker runs entirely in your own browser. When you paste a web address into it, that address is analysed by code running on your own device. It is not transmitted to OneHaven, it is not sent to any third party, it is not written to any server, and it is not stored or logged anywhere. We never see it. We also do not open, visit, or request the website you paste.
Nothing you type into the tool is retained once you clear the field or close the page. There is no account, sign-in, or submission involved in using it.
There is one optional step that does send something, and it is clearly marked and never automatic. After the on-device check, you may choose to look up when the domain was first registered and by which registrar. If you press that button, your browser sends the domain name only to a public domain registry lookup service operated by a third party. It does not send the full web address, the path or code at the end of it, or anything else you pasted. The request goes from your device directly to that registry service. It does not pass through OneHaven, we do not receive it, and we do not log it. If you never press that button, nothing is ever sent. The registry service will see your device's IP address and the domain you asked about, as it would for any ordinary web request, and its own handling of that is governed by its policies rather than ours.
As with any page on our website, ordinary web analytics may record that a visit to the page occurred, along with the standard technical information described in section 1. Analytics never receive the content of anything you type into the link checker, because that content never leaves your device in the first place.
Our educational pages, including the scam library, are ordinary web pages. They contain no forms and collect no information you enter.
This section is about you if someone arranged an assessment for you, rather than about the person who arranged it. You may not have a OneHaven account, and you may never have visited this website before the exercise brought you here. This section explains what we hold about you, why, and how to have it removed. You do not need an account to exercise any right described here.
Who can be a recipient. A Family Threat Assessment may only be arranged by a caregiver who has verified their identity through our identity provider and has typed a statement confirming their authority to act for you. Recipients must be in the United States or Canada and must be at least 13 years old. If you are an adult, nothing is scheduled and nothing is sent until you have replied to agree. If you are between 13 and 17, the exercise is arranged by the adult responsible for you and you receive advance notice from us that it is coming.
What we collect about you. Your first name as the caregiver entered it, an age range rather than a date of birth, and the phone number or email address the caregiver provided for you. We also record what happened during the exercise: whether the introduction was delivered, whether you agreed to take part, whether you replied, whether you opened the link, at what point the exercise revealed itself, and the outcome. Where the exercise is delivered by text message or email, we retain the messages exchanged within that exercise so that a record exists of exactly what was sent to you.
What we do not collect. We do not read, receive, or store any other message on your device. We see only what is exchanged inside the exercise itself. Using the assessment does not install anything, does not give anyone access to your phone, and does not connect your device to a OneHaven account. The link inside a simulated message leads to an ordinary educational page on this website. It collects nothing, contains no form, and asks you for nothing.
What we use it for. To run and deliver the exercise, to honour your decision to take part or to stop, to show the caregiver who arranged it what happened and what to talk to you about, and to keep a record that authority and consent existed at the time. We also use aggregated, de-identified counts to understand which exercises teach best. That aggregated data cannot identify you.
What the caregiver can see. The caregiver who arranged the assessment can see the exercise and its outcome. They cannot see anything else about you, anything on your device, or any message you did not send inside the exercise.
What we never do with it. We do not sell it. We do not share it for advertising, marketing, or promotional purposes. We do not use it to train external AI models. We do not add you to a mailing list, and receiving an assessment never signs you up for anything.
How long we keep it. Assessment records are retained for no longer than twelve months after the assessment completes or is cancelled, after which they are deleted or irreversibly de-identified. If you ask us to delete your record sooner, we will.
How to stop it, and how to be removed. Replying STOP to any message from us ends the exercise immediately and permanently, and no further message is sent. You can also ask us at any time to delete everything we hold about you and to prevent any future assessment being sent to your number or address, whether or not one has already been arranged. Contact us here and say that you received an assessment. You do not need to explain yourself, prove anything, or contact the person who arranged it.
If you believe this was sent without your authority. Tell us, using the same route. We will remove your details, block future assessments to you, and review the account that arranged it.
Our Services may include links to third-party sites. We are not responsible for their practices.
We may update this Privacy Policy from time to time. Users will be notified of significant changes as required by law.
We do not sell or share mobile or personal data with third parties, affiliates, or partners for marketing or promotional purposes. We only share data with third parties when it is strictly necessary to deliver our service and only under binding agreements that ensure confidentiality. Under no circumstances will mobile data be shared or sold for advertising or promotional use.
For privacy inquiries, please contact us.