Privacy Policy
Little Haven is a pixel companion for daily well-being practice, provided by Thomas Tjaja, trading as Thomas Tjaja – UX Design & Consultancy, a sole proprietorship registered in the Netherlands (“we,” “us,” “our”). This Privacy Policy explains what information the App processes, why, and the rights you have. It should be read together with our Terms of Service.
The short version:
- Without an account, nothing you write leaves your device. Little Haven works fully without signing in. Your journal, mood, gratitude, focus, routine, and pet data stay on your phone.
- Cloud Sync is optional. If you are a Little Haven Pro member and choose to sign in and turn on Cloud Sync, we store a copy of your App data — including what you write — on servers in the European Union so you can restore it and use it on more than one device.
- Cloud Sync is not end-to-end encrypted. Your synced data is encrypted in transit and at rest, but it is not encrypted with a key only you hold. Section 3.5 explains what that means.
- We never sell your data, never show ads, and never use what you write for analytics.
If you have questions about this policy, email support@littlehaven.app.
1. The principles we built around
- Local-first. By default, your personal content is stored only in your device’s local storage. It is never uploaded unless you sign in to Cloud Sync.
- Accounts are optional. You never need an account to use Little Haven. An account exists only to power Cloud Sync, and you can delete it — and everything stored with it — from inside the App.
- Minimal analytics. The product-analytics and crash data we receive is tied to an anonymous install ID, not to your account or email address. The contents of what you write are excluded.
- No selling, no advertising. We do not sell or rent any data, do not run advertising in the App, and do not share data for marketing purposes.
2. Information Little Haven does NOT collect
We do not collect, store, or transmit any of the following:
- Your phone number or postal address.
- Payment-card or bank information (handled entirely by Apple or Google — see Section 3.4).
- Precise or coarse location data.
- Contacts, calendar entries, photos, or files from your device.
- Health data from Apple Health, Google Fit, or any other health platform.
- Microphone, camera, or biometric data.
- Your advertising ID.
If you do not use Cloud Sync, we also do not receive your email address, any name you enter in the App, or any content you write. Analytics and crash reports are designed to exclude anything you write, whether or not you use Cloud Sync (Section 3.3 explains the one limit on that).
If a feature requires a permission (for example, notifications), the App will ask you in the standard system prompt, and you can revoke it at any time from your device settings.
3. Information Little Haven DOES collect
3.1 Anonymous install ID
When you first open the App, a random identifier (the “install ID”) is generated on your device and stored locally. It is not linked to your email address, device serial number, advertising ID, or Cloud Sync account. Its purpose is to let our analytics, crash-reporting, and subscription tools recognize that two events came from the same App installation.
If you reinstall the App, a new install ID is generated and the old one becomes orphaned.
3.2 Product-analytics events
We send a limited set of in-app events — for example, “completed a breathing session,” “opened the mood tool,” “sync completed,” or “signed in with Apple” — to PostHog, our analytics provider, hosted in the European Union. Each event includes:
- The anonymous install ID.
- The event name and a small set of safe metadata fields (for example, which breathing exercise, or the word count of a journal entry — never the text itself). For sign-in and sync events, this is limited to the sign-in method and technical error codes. Your email address and account ID are not sent.
- Optional answers you give in onboarding, such as your goals or where you heard about Little Haven, which you choose from a fixed list of options.
- The build type and basic app/device metadata (App version, OS version, device model).
We use these events to understand which features are useful, which are confusing, and where the App breaks.
3.3 Crash reports and performance data
When the App crashes or hits a serious error — including a sign-in or sync failure — a diagnostic report is sent to Sentry, our crash-reporting provider, hosted in the European Union. The report includes the anonymous install ID, a stack trace, technical tags (such as which sync step failed), basic device/OS information, and the build type.
Sentry session replay is disabled, and the App is configured not to send personal data by default. Before any report leaves your device, we automatically strip property names that could carry personal content or credentials — including journal and note text, pet and tag names, email addresses, passwords, and sign-in tokens. We design these reports to exclude your content. However, technical error messages are generated automatically and we cannot guarantee that they will never contain a fragment of data. Any such fragment is kept only for Sentry’s limited retention period (Section 8).
3.4 Subscription status
If you purchase Little Haven Pro, your purchase is processed by Apple (App Store) or Google (Google Play). They share a subscription receipt with RevenueCat, our subscription-management provider, which tells the App whether your subscription is active. RevenueCat receives an anonymous app-user ID based on your install ID. It does not receive your name, email address, Cloud Sync account, or payment details.
We never see your card number, your Apple ID or Google account email, or your billing address.
3.5 Cloud Sync account and synced data (optional, Pro)
Cloud Sync is an optional Little Haven Pro feature, currently in beta. It is off unless you create an account or sign in. If you do, we process the following through Supabase, our database and authentication provider, on servers located in the European Union (Frankfurt, Germany).
Account information
- Email and password sign-in: your email address and a password. Your password is stored by Supabase only in hashed form, and we cannot see it.
- Sign in with Apple: a unique identifier from Apple and the email address Apple shares with us. This may be a private relay address if you choose “Hide My Email.”
- Sign in with Google: a unique identifier from Google, your email address, and the basic profile information Google provides at sign-in (usually your name and profile picture). We do not use the name or picture in the App.
- Technical and security data: the date you created your account, when you last signed in, and short-lived technical logs (such as IP address and device/browser type) that Supabase keeps to operate the service securely and prevent abuse.
We use your email address only to run your account. For example, we use it to confirm sign-up and to send password-reset emails. We do not send marketing emails to your Cloud Sync address.
Synced App data
While Cloud Sync is active, the App uploads and keeps up to date a copy of:
- What you write and record: journal and Worry Chest entries, mood entries and notes, custom mood tags, gratitude entries, morning and evening reflections, sleep logs, Explore answers, goals and schedules, focus sessions, and custom focus tags.
- Your companion and progress: pets (including their names), unlocks and discoveries, owned shop items, food inventory, and eggs.
- Your profile and settings: the name and gender you entered in the App (if any), your onboarding answers (such as intentions and where you heard about Little Haven), notification and night-mode preferences, reflection times and custom emotions, and App preferences such as sound, haptics, font, and clock format.
Your install ID, subscription status, and sign-in session are not part of the synced data.
How this data is protected, and what it means for you
- Data is sent over HTTPS/TLS and stored in a database that is encrypted at rest.
- The database enforces row-level security, so each signed-in account can read and write only its own data.
- On your device, your sign-in session is stored encrypted, using a key held in the iOS Keychain or Android Keystore.
- Cloud Sync is not end-to-end encrypted. Your data is stored in a form that the service can technically read. We do not read your synced content. The only exceptions are when you ask us to (for example, for a support request), when it is strictly necessary to investigate a security incident or fix a technical fault, or when we are legally required to. In those cases, we limit access to the minimum needed.
Your journal and mood data may be sensitive. Content such as mood notes, journal entries, and reflections can reveal information about your health or well-being. Under EU law, that may be a “special category” of personal data. We process it in the cloud only because you choose to turn on Cloud Sync, and only to store and sync it back to you. By creating an account or signing in to Cloud Sync, you give your explicit consent to this processing. You can withdraw your consent at any time by deleting your account (Section 7.1). This does not affect the lawfulness of processing that took place before you withdrew it.
What happens on the device when you sign in, out, or switch accounts
- When you sign in on a phone that already has data, the App asks whether to combine that data with your cloud copy, or — if the phone’s data belongs to a different account — to replace what’s on the phone. Nothing moves until you choose.
- Before combining or replacing, the App tries to save a safety snapshot of your data on the device only. This is a best-effort safety net, not a guaranteed backup. The snapshot is removed when you use Delete all data or Delete Account & Data.
- Signing out disconnects the phone from the cloud but keeps your entries on the device. Anyone who can use your unlocked phone can still see them.
- If your Pro subscription ends, ongoing sync pauses. You can still sign in and restore what is already stored.
3.6 Our website
The pages on littlehaven.app that open from account emails (for example, “confirm your email” and “reset your password”) talk directly to Supabase from your browser, so you can finish those steps on any device. Those pages do not load analytics, and the website does not store your session after you leave the page. If you join our waitlist or contact us on the website, we use the details you provide only to reply to you or send the updates you asked for.
4. Third-party service providers
We use the following providers to run the App. They process data on our behalf under data-processing terms. Each also has its own privacy policy.
| Service | Purpose | Data location | What they receive |
|---|---|---|---|
| Supabase | Cloud Sync database, sign-in, and account emails | EU (Frankfurt); Supabase, Inc. is based in the US | Account email and sign-in identifiers, synced App data, technical logs — only if you use Cloud Sync |
| Apple (Sign in with Apple) | Sign-in option on iOS | Global | The fact that you signed in to Little Haven, under Apple’s terms |
| Google (Google sign-in) | Sign-in option | Global | The fact that you signed in to Little Haven, under Google’s terms |
| PostHog | Product analytics | EU (Frankfurt) | Install ID, event names, safe metadata, app/device info |
| Sentry | Crash and performance diagnostics | EU (Frankfurt) | Install ID, stack traces, technical tags, app/device info |
| RevenueCat | Subscription management | United States | Anonymous app-user ID, subscription receipts |
| Apple In-App Purchase / Google Play Billing | Subscription billing | Global | Your store account and payment details (we do not see these) |
| Vercel | Hosting the littlehaven.app website | Global | Standard web request data (such as IP address) when you visit the site |
We do not use advertising networks, attribution SDKs, data brokers, or AI services to process your content.
5. How we use information, and our legal bases
| What we do | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the App and your Pro subscription | Install ID, subscription receipts | Performance of a contract — Art. 6(1)(b) |
| Provide Cloud Sync: your account, storing, syncing, and restoring your data | Account information, synced App data | Performance of a contract — Art. 6(1)(b); explicit consent for health-related content — Art. 9(2)(a) |
| Keep accounts and the service secure, and prevent abuse | Technical and security logs | Legitimate interests — Art. 6(1)(f) |
| Diagnose crashes and understand how features are used | Install ID, analytics events, crash reports | Legitimate interests — Art. 6(1)(f) |
| Meet legal obligations (for example, tax records, or responding to lawful requests) | As required | Legal obligation — Art. 6(1)(c) |
We do not:
- sell, rent, or lease any data;
- use any data for targeted advertising or marketing profiles;
- use your content to train AI models;
- combine Little Haven data with data from other apps or sources.
We may disclose information if we are legally required to (for example, by a valid court order). We may also disclose it if needed to protect the rights, safety, or property of our users, ourselves, or others. If Little Haven is transferred to another owner (for example, in a sale or reorganization), your data may be transferred as part of that. The new owner must continue to honor this policy, and we will notify you before your data becomes subject to a different policy.
6. International data transfers
We operate from the Netherlands. Cloud Sync data, analytics, and crash reports are stored on servers in the European Union. Some of our providers (including Supabase, Sentry, PostHog, RevenueCat, and Vercel) are companies based in the United States or have US-based support staff, and Apple and Google operate globally. As a result, limited data may be accessed from, or transferred to, countries outside the European Economic Area.
Where that happens, the transfers are covered by appropriate safeguards under the GDPR — typically the European Commission’s Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
7. Your rights and choices
7.1 Controls inside the App
You can exercise most of your rights directly in the App:
- Delete your account and all synced data: Settings → Cloud Sync → Delete Account & Data. This permanently deletes your account and all Cloud Sync data from our servers, and erases the App’s data on the device you use. This cannot be undone.
- Delete data on this device only: Settings → Data → Delete all data. This erases everything stored on the device and resets your analytics identity. It does not delete your Cloud Sync account or cloud data. To delete those, use Delete Account & Data (above) or contact us.
- Stop syncing without deleting: sign out of Cloud Sync. Your entries stay on the device, and your cloud copy stays in your account until you delete it.
- Get a copy of your data: everything you have written is visible in the App, and Pro members can export it as a file from Settings → Data. Anyone can also ask us for a free copy of their data (Section 7.2).
7.2 Residents of the European Economic Area, Switzerland, and the United Kingdom
Under the GDPR and UK GDPR, you have the right to access, rectify, erase, restrict, and port your personal data. You also have the right to object to processing based on legitimate interests, and to withdraw consent at any time.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). In the UK, it is the Information Commissioner’s Office (ico.org.uk). Users in other EEA countries can contact their national data-protection authority.
To make a request, email support@littlehaven.app. Requests are free of charge.
- For Cloud Sync data, tell us the email address linked to your account. Before we share or delete anything, we will send a confirmation message to that address, and act only once it has been answered. If you use Apple’s “Hide My Email”, this still works: the message is forwarded to your inbox.
- For analytics or crash data, include your install ID, shown in Settings → Data. We cannot link analytics data to your account or email, so the install ID is the only way for us to find it.
We will not act on a request until we are reasonably satisfied that it comes from the person the data belongs to. We will respond within one month of receiving a request we can verify. For complex or numerous requests, the law lets us extend that by up to two further months, and we will tell you if we do.
If a request is manifestly unfounded or excessive — for example, because it is repeated — we may refuse it or charge a reasonable fee, as the law allows, and we will explain why. We may also keep some information where the law requires or allows it, such as records we must keep for tax purposes, and we will tell you if that applies.
7.3 Residents of California (CCPA / CPRA)
California residents have the right to know what personal information we collect, and to request its deletion or correction. You also have the right to opt out of its “sale” or “sharing,” and to limit the use of sensitive personal information. We do not sell or share personal information, and we use sensitive information only to provide the service you asked for. We will not discriminate against you for exercising these rights. To make a request, contact us as described in Section 7.2.
7.4 Other regions
If your country has a similar data-protection law (for example, Brazil’s LGPD, Canada’s PIPEDA, or Australia’s Privacy Act), you have equivalent rights under that law and can contact us the same way.
8. Data retention
- On-device data is kept until you delete it in the App or uninstall the App.
- Cloud Sync account and data are kept for as long as your account exists. When you delete an entry, its content is removed from the cloud at the next sync. A small deletion marker — the entry’s ID and when it was deleted, with no content — may remain so your other devices know to remove it too. When you delete your account, your account and all synced data are deleted from our live database right away.
- Inactive accounts: if a Cloud Sync account has not been signed in to for 24 months and has no active Pro subscription, we may delete it and its data. Before we do, we will send at least 30 days’ notice to the account’s email address.
- Backups and logs: Supabase keeps short-term database backups and technical logs for disaster recovery and security. Deleted data may remain in those backups until they expire in the normal backup cycle (typically within a few weeks). It is not restored or used in the meantime.
- Analytics events in PostHog are kept for up to 24 months.
- Crash reports in Sentry are kept for up to 90 days and then deleted automatically.
- Subscription records in RevenueCat are kept while your subscription is active, plus any period required by tax and accounting law.
9. Children’s privacy
Little Haven is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13.
Cloud Sync accounts are only for people aged 16 or over, or older where the age of digital consent in your country is higher. If we learn that a Cloud Sync account belongs to someone below that age, we will delete the account and its data.
If you are a parent or guardian and believe your child has created an account or shared information with us, contact us at support@littlehaven.app and we will help.
10. Security
We use reasonable technical and organizational measures to protect your data. They include:
- Your content stays on your device unless you choose to use Cloud Sync.
- All network traffic from the App uses HTTPS/TLS.
- Cloud Sync data is encrypted at rest and protected by row-level security, so each account can access only its own data.
- Your sign-in session is stored encrypted on your device.
- Analytics and crash reports are kept separate from your Cloud Sync account and scrubbed of known content-bearing fields.
- Access to our production systems is limited to the developer.
You are responsible for keeping your password confidential and your device secure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a personal-data breach that is likely to put your rights at risk, we will notify the relevant supervisory authority and, where required, you, as the law requires.
If you believe you have found a security issue, please report it to support@littlehaven.app.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example when we add features. The “Last updated” date at the top shows the most recent revision.
We will announce material changes in the App or in the App Store / Google Play release notes. If you have a Cloud Sync account, we may also announce them by email. Where the law requires your consent to a change, we will ask for it.
12. Contact
The data controller for Little Haven is Thomas Tjaja – UX Design & Consultancy. For questions, requests, or complaints about this Privacy Policy, contact:
- Email: support@littlehaven.app
- Address: Thomas Tjaja – UX Design & Consultancy, Lilahof 19, 5044 RH Tilburg, Netherlands
- Chamber of Commerce (KvK): 98789988
- Web: https://littlehaven.app
We aim to respond to all privacy requests within one month.