Haven iOS

Privacy Policy

Last updated October 2, 2026

The short version

The developer runs no servers for this app and collects nothing through it. Your messages live on the Haven server you sign in to, and a few other websites can see your IP address when the app shows pictures they host.

Haven iOS (“the app”, called Haven on your home screen) is an independent client for Haven, a self-hosted chat server. It is published by Donut under The Project Oven (“the developer”). It isn’t a chat service itself: it connects to whichever Haven server you choose, run by you or by someone else.

The developer collects nothing

The app has no analytics, crash reporting, advertising or tracking of any kind, and no servers of its own. Nothing you type, send or view is sent to the developer.

The only exception is mail you choose to send. When you report a message or contact support, the app opens an email addressed to the developer, and the developer receives whatever that email contains. For a report, that’s the server address, channel, the sender’s name and ID, and the reported message’s ID and text. Report emails are used only to deal with the report (see how reports are handled) and support emails only to answer you.

The developer also runs a Haven community server of their own, The Donut Shoppe. It has nothing to do with this app: the app never contacts it unless you type its address, and if you do, that server’s own policies apply like any other server’s.

Your Haven server holds your account and messages

When you sign in, the app talks to the server address you entered. Your account, profile, messages, pictures, files, voice messages, reactions, polls and channel memberships are stored on that server, under the control of whoever runs it. Voice channels connect you to the other people in the channel through that server.

When you sign in or register, the app tells the server that you accepted its terms and confirmed you’re 18 or older, because Haven servers require it. The app only does this after you’ve switched both on.

If you don’t run the server yourself, ask its administrator how they handle your data. The developer has no access to servers they don’t run and can’t read, retrieve or delete anything on them.

Other websites you may contact

Some things in a chat are hosted somewhere other than your Haven server. Showing them means your device fetches them from that website directly, and that website can see your IP address and the time:

  • Pictures linked in messages that are hosted on another website. You can stop these loading automatically in Settings, Content Filter, “Load pictures from other websites”; you then see a link instead, and nothing is fetched unless you tap it. Plain http:// links are never loaded automatically. Pictures from other websites larger than 15 MB aren’t downloaded.
  • GIFs. GIF search goes through your Haven server, which uses whichever provider its administrator configured (such as GIPHY, KLIPY or Tenor). The previews in the GIF picker, and GIFs posted in chat, load from that provider’s servers.
  • Links you tap open in your browser, like any other link.

These websites’ own privacy policies apply to what they receive.

What stays on your device

  • Your sign-in token, in the iOS Keychain, so you don’t have to sign in each time. Signing out or deleting the app removes it.
  • Your two-factor secret, only if you turn on on-device codes in Security. It’s kept in the Keychain on this device, and it’s off unless you choose it.
  • The certificate fingerprint of each server you’ve chosen to trust, so the app can warn you if it changes.
  • Preferences and lists: the servers you’ve used and the last channel you opened, unsent drafts, your Content Filter settings, the people you’ve blocked, the messages you’ve reported or hidden, and a record of when you agreed to the app’s terms and each server’s terms.
  • Cached pictures and files you’ve viewed, which iOS clears as it needs space.

None of this is sent to the developer. Blocking, hiding and the Content Filter all work on your device alone.

Permissions the app asks for

  • Microphone: for voice channels, and for voice messages you choose to record. Only while you’re doing one of those.
  • Camera: only when you take a photo to send.
  • Photos: only to save a picture you choose to your library. Picking a photo to send uses the system picker, which shares only the photos you select.
  • Local network: only if your Haven server is on your home or office network.

Each is used for that purpose alone.

Children

The app isn’t directed at children. You must be 18 or older to use it, and Haven servers require anyone who registers to confirm the same.

Deleting your account

Go to Settings, Delete Account. It asks for your password and then tells your server to erase your account, optionally including your messages. It’s permanent, and the developer can’t undo it. Deleting the app removes everything it stored on your device.

Changes and contact

If this policy changes, the date at the top changes with it. Material changes will also be noted in the app’s release notes.

Questions about privacy: [email protected]

The developer’s legal name, as the account holder named in the App Store listing, is Trent Johnson.