Privacy Policy
TL;DR (plain English)
We built SimpleHaven so that Your home data stays on Your device and in Your own iCloud, where we cannot reach it. Concretely:
- Your scans live in Your iCloud, not with us. We use Your private CloudKit database. We can’t read it.
- Processing happens on Your device. Scanning, color matching, furniture detection and image rendering — all on-device.
- No tracking, no ads, no sale of data. We do not run advertising, do not sell personal information, and do not share it for cross-context behavioral advertising. The app contains no analytics SDK, no advertising SDK and no third-party tracker.
- Your Apple Account is the only identity. We don’t have a password database to lose, because we don’t have accounts at all.
- HomeKit data stays on Your device. We read it through Apple’s frameworks to show accessory state. We never get a copy.
- Depth and LiDAR data is treated with the same restrictions as HomeKit data. Neither is ever used for marketing, advertising or use-based data mining, by us or by anyone else.
- One purchase, no subscription. SimpleHaven Lifetime is a one-time in-app purchase. There is no subscription and no trial, so there is no recurring billing record.
- If we ever offer cloud rendering, it’s opt-in and anonymized. It is not offered in this version and the code path is disabled. Section 11.3 sets out the commitments that would apply if it ever ships.
The rest of this document is the long, legally precise version. In a conflict between the TL;DR and the formal sections below, the formal sections control.
1. Scope
This Privacy Policy describes how SimpleHaven Technologies LLC (“we”, “us”) collects, uses, discloses and protects personal information in connection with:
- the SimpleHaven applications for iPhone and iPad, and any future Apple-platform clients;
- the simplehavenapp.com website (our only website);
- our customer-support and billing-support interactions.
We address several major privacy frameworks here:
- U.S. — California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA), as amended and in effect 1 January 2026.
- EU/UK — General Data Protection Regulation (GDPR) and UK GDPR.
- U.S. — Children’s Online Privacy Protection Act (COPPA) as amended (compliance deadline 22 April 2026).
- Apple — App Store Privacy “nutrition label” requirements and Apple’s HomeKit and depth-mapping developer privacy requirements.
Other jurisdictions (Virginia, Colorado, Connecticut, Texas, Utah, Quebec, Brazil and others) have analogous statutes; we treat all users consistently with the highest-bar framework that applies to them.
We describe the GDPR and UK GDPR positions here because we hold ourselves to that standard as a matter of design, and because You may read this Policy from anywhere. SimpleHaven is not distributed in the European Union — see Section 2 for why — so in practice the EU sections below describe a standard we meet rather than a market we serve.
2. Who we are; how to contact us
Data Controller (GDPR Article 4(7)):
SimpleHaven Technologies LLC
5900 Balcones Dr Ste 100
Austin, TX 78731
United States
Privacy contact:
privacy@simplehavenapp.com
Security contact:
security@simplehavenapp.com
General legal:
legal@simplehavenapp.com
Support:
support@simplehavenapp.com
Distribution: SimpleHaven is distributed through the Apple App Store outside the European Union. Our App Store Connect account is registered as a non-trader under the EU Digital Services Act, and Apple does not distribute apps from non-trader accounts on European Union storefronts. EU distribution is therefore not available to us at present.
EU Representative (GDPR Article 27): we have not designated one, and Article 27 does not require us to, because we do not offer SimpleHaven to data subjects in the European Union. UK Representative (UK GDPR Article 27): we have not designated one either. These statements describe our position as of the effective date at the top of this Policy and are not commitments about any future date. If our distribution position changes, the change will be recorded in the revision history in Section 21 with a new version and effective date.
Wherever You are, You can reach us directly at privacy@simplehavenapp.com about any request under any privacy law, and we will answer within the time limits set out in Section 6.4 and Section 7.
Data Protection Officer (GDPR Article 37): we do not currently meet the threshold requiring one. When we do, we will appoint one and update this Policy.
3. Architecture in one paragraph (so you understand the data flows)
SimpleHaven uses Apple’s CloudKit with a private container
(iCloud.com.simplehaven.app). Within that container, Your data goes to the
private database, which is part of Your iCloud storage,
not ours. The technical effect is that we — SimpleHaven Technologies LLC
— cannot read, copy, modify or back up Your scans, room layouts, device assignments or
any other content You create. Apple operates the container under Apple’s own privacy
commitments (see Apple’s
Privacy Policy). We see only StoreKit purchase metadata and crash/diagnostic data that
You opt to share through Apple’s standard “Share with App Developers” toggle. We do
not operate a separate backend that holds Your scans.
4. Categories of information we process
4.1 What stays on Your device and in Your iCloud (we do NOT see)
The list below enumerates every sensor and system permission the app requests, plus the one system picker it uses that requires no permission at all — what each is used for, and where the resulting data goes. None of it is transmitted to us.
| Category | What it is and why | Where it lives |
|---|---|---|
| Camera and LiDAR depth | Camera frames and depth readings captured by Apple’s room-scanning framework while You scan a room, so the app can build a measured 3D model of it | Processed transiently on device. Raw frames and depth readings are not persisted or transmitted. |
| Scan geometry | Room dimensions; wall, floor and ceiling planes; door and window positions | On device + Your iCloud private database |
| Reference photos | Still frames the app retains on device to improve how closely Your 3D model resembles Your home. You can turn retention off at any time in Settings (“Keep scan photos”), and the app keeps working without them. | On device + Your iCloud private database |
| Color samples | The paint and material colors recorded for Your walls, floors and surfaces, so Your model looks like Your home | On device + Your iCloud private database |
| Furniture metadata | The furniture found in Your rooms and where it sits, so it appears in the right place in Your model | On device + Your iCloud private database |
| HomeKit accessory data | Accessory names, rooms, types and real-time state (light on/off, lock locked/unlocked, battery level), read through Apple’s HomeKit framework under the permission You granted | Read transiently from HomeKit on device. Never persisted by us, never transmitted off device by us. |
| Device assignments | Which accessory You placed at which point in which room; Your own notes and names | On device + Your iCloud private database |
| Room names and notes | “Living Room”, “Home Office”, custom notes | On device + Your iCloud private database |
| Approximate home location | Captured once, while You are scanning, so that daylight in Your 3D model matches Your part of the world. There is no background location tracking of any kind. | Stored with the home in Your iCloud private database |
| Calendar events | Read only if You add a widget that displays upcoming events to Your home’s model. Read on device to display those events; never uploaded, never stored by us. | Transient, on device only |
| Floor-plan reference image | While You are planning a scan, You can optionally pick one image from Your photo library to hold on screen as a visual reference. Apple’s system photo picker hands the app only the image You picked, so the app asks for no photo-library permission and never sees the rest of Your library. The app writes nothing to Your photo library. | Transient, on device only |
| Theme selections | Your appearance and theme picks | On device + Your iCloud private database |
| Rendered images | Output of on-device rendering | On-device cache + Your iCloud private database |
4.2 What we DO receive (limited set)
| Category | What we get | Source | Retention | Legal basis (GDPR) |
|---|---|---|---|---|
| StoreKit purchase metadata | Product ID, original transaction ID, purchase date, environment, family-shared flag, signed JWS transaction. SimpleHaven sells a single one-time non-consumable purchase; there is no subscription and therefore no renewal or expiry record. We never receive Your payment-card details — Apple handles payment end to end. | Apple StoreKit | For as long as the purchase entitles You to the app, plus the statute of limitations on revenue and tax claims (typically 7 years) | Contract performance (Art. 6(1)(b)) + legal obligation (Art. 6(1)(c)) |
| Crash and diagnostic reports — only if You opt in via iOS Settings → Privacy & Security → Analytics & Improvements → “Share with App Developers” | Anonymized crash logs, energy and performance metrics, delivered through Apple’s pipeline | Apple (via Your opt-in) | 90 days | Legitimate interest (Art. 6(1)(f)) — the interest being fixing crashes in our own software |
| Support emails | Whatever You voluntarily send us | Direct from You | 2 years from last contact | Contract performance (Art. 6(1)(b)) |
| Beta-test enrolment (if You opt in to TestFlight) | Email and device model — handled by Apple | Apple TestFlight | While You remain in TestFlight + 90 days | Consent (Art. 6(1)(a)) |
| Website analytics | None today. simplehavenapp.com currently runs no analytics, sets no cookies and loads no third-party script. If we ever add analytics it will be aggregate and anonymized (page views, country bucket, referrer category) and this Policy will be updated first. We do not use Google Analytics, Meta Pixel or any comparable tracker. | — | 13 months, if ever enabled | Legitimate interest (Art. 6(1)(f)) where lawful; consent in cookie-consent jurisdictions |
4.3 What we explicitly do NOT collect
- Government-issued IDs, social security numbers, driver’s licenses.
- Precise or background GPS location. The app captures approximate home location once, during a scan, and stores it on Your device and in Your iCloud — it is never sent to us.
- Biometric data for identification purposes (see Section 6.2).
- Health, medical or wellness data.
- Financial or payment-card information — Apple handles payments end to end.
- Browsing history outside SimpleHaven.
- Contact lists or messages. (Calendar events are read on device only if You add a widget that displays upcoming events — see Section 4.1. They are never transmitted to us.)
- Audio or voice recordings of any kind. SimpleHaven does not use the microphone and does not perform speech recognition.
- Children’s personal information — the Service is not directed to children under 13; see Section 9.
4.4 Alignment with the App Store privacy label
Apple defines “collect” as transmitting data off the device in a way that lets the
developer or its partners access it beyond what is needed to service a request in real time, and
states that data processed only on device is not collected. Your scans, geometry, colors, furniture,
device assignments, room names, HomeKit state and location sit in Your own private CloudKit database
or on Your device, where we have no access — so they are correctly declared as not collected.
What is declared on our App Store privacy label is the short list in Section 4.2: purchase
history, and crash data if You turn on Apple’s sharing toggle. The app also ships a
PrivacyInfo.xcprivacy manifest that declares no tracking and lists no tracking
domains.
5. Purposes of processing
We process information for the following purposes only.
5.1 Service delivery
- Provide the core scanning, rendering, visualization and sync functionality.
- Sync Your home data across Your own Apple devices via Your iCloud.
- Unlock the paid tier when Apple tells us You have made the one-time SimpleHaven Lifetime purchase, and restore that unlock on Your other devices. There is no subscription to police and no recurring entitlement check.
5.2 Purchase and entitlement management
- Receive purchase metadata from Apple to grant the paid unlock.
- Honor a refund: Apple administers refunds and notifies us; we revoke the entitlement.
5.3 Customer support
- Respond to email You send to support@simplehavenapp.com.
- Diagnose issues You report, using only information You voluntarily share.
5.4 Security and abuse prevention
- Detect and prevent reverse engineering, license fraud and abuse of the Service.
- Maintain audit logs for security incidents.
5.5 Service improvement (only where lawful)
- Aggregate crash and diagnostic data, only if You opted in via iOS, to fix bugs.
5.6 Legal compliance
- Comply with subpoenas, court orders and law-enforcement requests where legally required.
- Preserve records as required by tax or other law.
We do not process information for targeted advertising; profiling for credit, employment, insurance, housing or eligibility decisions; sale or rental to data brokers; or training third-party models on Your data.
6. GDPR-specific disclosures
6.1 Lawful bases (Article 6)
See the “Legal basis” column in Section 4.2. In summary: contract performance for service delivery and purchases, legal obligation for tax and record-keeping, legitimate interests for crash diagnostics and security (subject to Your objection right under Article 21), and consent for opt-in features such as TestFlight enrolment. Providing personal data to us is not a statutory requirement; the only data that is contractually necessary is the purchase metadata Apple sends us when You buy, and You can use the free tier without any of it.
6.2 Special categories of personal data (Article 9)
We are conservative about Article 9 risk. Article 9 covers biometric data processed for the purpose of uniquely identifying a natural person, plus health, racial origin, religious belief, political opinion, sexual orientation and similar categories. SimpleHaven’s operation does not process Article 9 data:
- No biometric identification. The models the app runs on a scan are object and color classifiers, not face-recognition or person-identification models. The room-scanning framework operates on geometry, not on people; a person present during a scan appears, if at all, as a transient depth blob and is not identified.
- No facial recognition or face matching. We do not create face templates and we do not match faces.
- No inference of Article-9-protected attributes from interior images. We do not infer religion from religious objects, political views from posters, sexual orientation from interior context, or health status from medical equipment visible in a scan. We recommend You avoid scanning sensitive items You would not want to appear in Your iCloud private database.
If a future feature would process Article 9 data, we will re-disclose it, seek explicit consent under Article 9(2)(a), and update this Policy with a clear “what changed” notice.
6.3 International transfers (Chapter V)
Because User Content lives in Your private CloudKit database, the geographic location of Your data is determined by Apple’s iCloud regional architecture; see Apple’s privacy pages. For the limited data we receive (StoreKit metadata and support emails), processing occurs in the United States. We rely on the European Commission’s adequacy decision for the EU–U.S. Data Privacy Framework where applicable, and on Standard Contractual Clauses as a backup. If You are in the EU or UK, contact privacy@simplehavenapp.com for a copy of our SCCs.
6.4 Data subject rights (Articles 12–22)
EU and UK residents have the following rights, subject to lawful exceptions:
- Access (Art. 15) — request a copy of the personal data we hold about You.
- Rectification (Art. 16) — request correction of inaccurate data.
- Erasure (Art. 17) — request deletion. Most of Your content is in Your iCloud, which You control directly; for the limited metadata we hold (support tickets, purchase records) we will erase except where retention is required by law.
- Restriction (Art. 18) — request we stop processing in defined circumstances.
- Portability (Art. 20) — request Your data in a machine-readable format. For scans, You already have export from inside the app.
- Objection (Art. 21) — object to processing based on legitimate interests.
- Automated decision-making (Art. 22) — we make no decisions with legal or similarly significant effects based solely on automated processing.
- Withdraw consent (Art. 7(3)) — at any time, without affecting prior lawful processing. See Section 12 for how.
- Complain to a supervisory authority (Art. 77) — typically Your country’s data-protection authority.
To exercise any right, contact privacy@simplehavenapp.com. We will respond within 30 days of a verified request, with a possible 60-day extension where the request is complex. We verify identity via the email address associated with Your Apple Account and an in-app confirmation where feasible.
6.5 Retention (Article 5(1)(e))
We retain personal data only as long as necessary for the stated purpose. Specific retention windows are in Section 4.2.
6.6 No significant automated decision-making
We do not use automated profiling to make decisions that produce legal or similarly significant effects.
7. CCPA / CPRA disclosures (California residents)
SimpleHaven Technologies LLC does not currently meet the CCPA’s thresholds for a “business”. We make these disclosures voluntarily, and we will honor the rights below regardless.
7.1 Categories collected in the 12 months prior to the effective date
| Statutory category | What we collect | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| A. Identifiers | The email address You write to us from; an IP address transiently in web server logs | You; Apple StoreKit; web server | Support; security | Apple, as a processor |
| D. Commercial information | The fact of a single one-time purchase and its transaction identifier | Apple StoreKit | Grant and restore the paid unlock; tax records | None |
| F. Internet activity | Aggregate web server logs for simplehavenapp.com | Web server | Site availability and security | None |
| L. Sensitive personal information | None | — | — | — |
We do not collect, and have not collected in the past 12 months: customer records under a separate account system (we have no accounts); characteristics of protected classifications; biometric information; sensory data (audio, visual, thermal, olfactory) transmitted to us; professional or employment information; education information; or inferences drawn to create a profile.
7.2 Sale and sharing
We do not sell personal information and we do not share personal information for cross-context behavioral advertising, as those terms are defined in Cal. Civ. Code § 1798.140(ad) and (ah). Because we neither sell nor share, the “Do Not Sell or Share My Personal Information” link required by § 1798.135 is not required of us, and adding one would imply a sale that does not happen. We will nevertheless honor any opt-out signal a California resident sends, including the Global Privacy Control signal on our web property.
7.3 Rights of California residents
- Right to know (§§ 1798.110, .115)
- Right to delete (§ 1798.105)
- Right to correct (§ 1798.106)
- Right to opt out of sale or sharing (§ 1798.120) — not applicable, as we do neither, but we will honor opt-outs we receive
- Right to limit use of sensitive personal information (§ 1798.121) — not applicable, as we collect none
- Right to non-discrimination (§ 1798.125) — we do not discriminate against You for exercising privacy rights
- Right to portability, as a subset of the right to know
To exercise, contact privacy@simplehavenapp.com. We verify identity via the email associated with Your Apple Account and an in-app confirmation where feasible, and respond within 45 days, with a 45-day extension where the request is complex. Authorized agents acting on a California resident’s behalf must provide signed permission and proof of identity.
7.4 Retention (CPRA § 1798.100(a)(3))
See Section 4.2. We do not retain personal information for longer than reasonably necessary for the disclosed purposes.
7.5 No financial incentives
We do not offer financial incentives in exchange for personal information.
8. Other U.S. state laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Tennessee, Montana, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Maryland, Minnesota, Nebraska, Rhode Island and other states with comprehensive consumer-privacy laws have rights analogous to CCPA/CPRA — access, deletion, correction, portability, opt-out of targeted advertising or sale, and opt-out of profiling for legally significant decisions. We honor these rights through the same channel: privacy@simplehavenapp.com.
Texas (TDPSA, Tex. Bus. & Com. Code ch. 541). As a small business as defined by the U.S. Small Business Administration, we are exempt from the notice-content requirements of § 541.102. One obligation applies regardless of size: § 541.107(a) prohibits the sale of sensitive personal data without prior consent. We sell no personal data of any kind, so that prohibition is satisfied and the statutory all-caps sale notices are not triggered.
9. Children’s privacy (COPPA)
SimpleHaven is not directed to children under 13. We do not knowingly collect personal information from children under 13. The App Store rating is 4+, but the app’s use case — scanning and customizing a home — presumes an adult user. A home scan will often include a child’s bedroom; that scan stays on the scanning adult’s device and in their iCloud, and never reaches us.
If we learn we have collected personal information from a child under 13 without verifiable parental consent in compliance with COPPA (16 C.F.R. Part 312, as amended with the 22 April 2026 compliance deadline), we will delete that information promptly. If You are a parent or guardian and believe Your child under 13 has provided personal information through SimpleHaven, contact privacy@simplehavenapp.com.
COPPA 2.0 and teen protection: should the pending Children and Teens’ Online Privacy and Protection Act be enacted, we will extend equivalent protections to users under 17 as required.
10. Apple frameworks — specific disclosures
10.1 HomeKit, and depth and LiDAR data
Apple’s App Review Guideline 5.1.2(vi) places data gathered from the HomeKit API and data gathered from depth or facial-mapping tools under the same restriction. We commit to both, in the same terms:
- No use for marketing or advertising. We do not use HomeKit data, depth data or LiDAR-derived scan data for marketing or advertising.
- No use-based data mining. We do not mine HomeKit data or scan data, and we do not build a dataset out of users’ homes.
- No off-device transmission by SimpleHaven. We read HomeKit accessory state on device through Apple’s framework and display it spatially. We do not transmit it anywhere.
- No third-party sharing. Not with anyone, including any affiliate.
- No service-improvement use of HomeKit or scan data without separate, explicit consent.
- We control accessories; we never change Your Home configuration. SimpleHaven sends control commands — turning a light on or off, setting brightness, setting a fan speed — through Apple’s HomeKit framework using Your existing grant. It does not add, remove, rename or re-room accessories, and does not create or edit scenes, automations or groups. Those remain Yours to manage in Apple’s Home app.
10.2 Matter
The same restrictions apply. Matter accessories are reached through Apple’s Home framework, on device only.
10.3 Room scanning
Scans are produced on device by Apple’s room-scanning framework using the LiDAR depth sensor and camera input. The resulting scan record is written exclusively to Your private CloudKit database; raw camera frames and depth readings are processed transiently and discarded. We do not transmit raw frames, depth data or geometry to any server.
10.4 CloudKit private container
Apple operates iCloud under Apple’s own privacy commitments. SimpleHaven’s CloudKit
container iCloud.com.simplehaven.app is structured as follows:
- Private database — Your data, in Your iCloud. We have no administrative read access. Inaccessible to other users.
- Shared database — used only if You explicitly create a share. We have no read access there either.
- Public database — not used by SimpleHaven. If we ever add a use for it, only data You explicitly publish would go there, under a separate consent flow.
10.5 Privacy manifest
The app ships a PrivacyInfo.xcprivacy manifest declaring the Required Reason APIs it
uses and stating that it does not track. We update it as the codebase evolves.
10.6 Third parties and equal protection
Apple requires that any third party with whom an app shares user data must provide the same or equal protection of user data as stated in the app’s privacy policy. Our commitment: any third party that receives user data from SimpleHaven will provide the same or equal protection of user data as stated in this Policy. In practice the list of such parties is very short:
- Apple Inc. — as our processor for CloudKit (Your storage), StoreKit (purchases) and TestFlight (beta enrolment), under Apple’s own published privacy commitments.
- Nobody else. We use no analytics vendor, no advertising network, no attribution SDK, no data broker and no customer-data platform. We have no parent, subsidiary or affiliate that receives user data.
11. Automated and generative features
11.1 On device
All automated inference runs on device. That includes object and furniture detection, color analysis, image rendering, and room-name suggestions. None of these models train on Your data. They are frozen at the version we ship; running inference on Your scan does not improve them and does not send anything anywhere.
11.2 Third-party model license terms
The shipping app does not perform generative image synthesis. The on-device
inference described in Section 11.1 analyses what You scanned; it does not invent imagery, and no
diffusion model is distributed with the app. Accordingly We do not ask You to accept any use-based
restriction as a condition of rendering, and any earlier version of this Policy that did is
superseded by this one. To reconcile that with our
open-source attributions, which list it: the app links Apple’s
ml-stable-diffusion Swift package, but it ships none of that package’s model
weights, in the bundle or as a downloadable asset pack. Without them no code path in the
shipping app can synthesize an image.
If We ever ship a component whose license imposes conditions on You, We will name that component and state those conditions here and in the open-source attributions before it reaches You — not afterwards. This is a commitment about how We would introduce such a component, not a statement that We intend to, and it is not a commitment about any date.
11.3 Cloud rendering — not offered in this version
SimpleHaven does not offer cloud rendering. The feature is disabled in the shipping app, and no image, frame or scan leaves Your device for rendering. The commitments below are conditional and describe what We would require of ourselves if We ever offered it; they are not a statement that We intend to, and they are not a commitment about any future date. If We ever enable it, it will:
- be opt-in, with a clear consent flow describing exactly what is sent and what comes back;
- send only the minimum data necessary, and not Your full scan;
- strip identifiers before upload (no Apple Account, no identity derived from an IP address);
- retain the frame only transiently — no more than 60 seconds on our side — and require any processor We used to delete input and output promptly;
- run in a U.S. data center, or an EU data center for EU users, matching the regional posture Apple uses;
- never be used to train any model.
We will update this Policy with full specifics, including naming the vendor, before launching any such feature.
12. How to delete Your data, and how to withdraw consent
This section is the practical one. It tells You exactly which control does what.
12.1 Delete a home, or everything
Deleting a home inside the app removes that home — its geometry, colors, furniture, room names, accessory placements and rendered images — from Your device and from Your iCloud private database, along with every setting stored for it. That deletion propagates to Your other devices through iCloud. There is nothing held on our side to delete, because Your scans never reach us.
If Your device cannot reach iCloud at that moment, the app tells You so rather than reporting a deletion it could not complete. Retry when You are back online. Deleting the app itself removes its local data; content already in Your iCloud is removed by deleting the homes first, or by turning off iCloud for SimpleHaven and using Apple’s own iCloud storage management.
12.2 Withdraw a permission
Every permission the app uses can be revoked at any time in iOS Settings, without uninstalling:
- Apple Home accessories — Settings → Privacy & Security → HomeKit → SimpleHaven.
- Camera, location, calendars — Settings → Privacy & Security, then the matching category.
- Crash and diagnostic sharing — Settings → Privacy & Security → Analytics & Improvements → Share with App Developers. Turning this off stops the only diagnostic flow that can ever reach us.
- Reference photo retention — in SimpleHaven’s own settings, turn off “Keep scan photos”. The app continues to work; Your 3D model may resemble Your home less closely.
- iCloud sync — Settings → [Your name] → iCloud, and turn SimpleHaven off. The app then works on that device only.
12.3 Ask us to delete what we hold
For the limited data listed in Section 4.2 — support emails, purchase records, TestFlight enrolment — email privacy@simplehavenapp.com. We will delete what we can and tell You plainly what we must keep and why (purchase records are retained for tax and revenue-claim purposes; TestFlight enrolment is held by Apple, not by us). Withdrawing consent does not affect the lawfulness of processing carried out before You withdrew it.
13. Cookies and the website
simplehavenapp.com is a set of static pages. Today it sets no cookies, runs no analytics, loads no third-party script, and embeds no tracking pixel. If that ever changes we will use strictly necessary cookies plus a privacy-respecting, aggregate analytics tool at most; we will present a cookie banner conformant with the EU ePrivacy Directive to EU and UK visitors before doing so; and we will update this Policy first. We will honor the Global Privacy Control signal as an opt-out request. We do not use Google Analytics, Meta Pixel or any comparable cross-site tracker.
14. Affiliate links
SimpleHaven contains no affiliate links. We share no click data with any affiliate network.
15. Security
We follow industry-standard practices to protect personal information:
- Apple-managed encryption at rest and in transit for CloudKit data, including end-to-end encryption for the categories Apple covers under Advanced Data Protection where You have opted in.
- TLS for all transmissions between Your device and any service we use (currently limited to Apple’s billing receipts and inbound support email).
- Least privilege for our limited internal access to support tickets and revenue records.
- No long-lived secrets in client code.
- No account system — we hold no passwords, so there is no credential store to breach.
- Responsible disclosure — report security issues to security@simplehavenapp.com. Our policy, scope and response times are published at simplehavenapp.com/security.
No system is completely secure. If a breach occurs that affects Your personal information, we will notify You and the relevant regulators in accordance with applicable law — including GDPR Article 33’s 72-hour notification where it applies, and US state breach-notification law.
16. Family Sharing
Apple’s Family Sharing can let a family organizer share an eligible in-app purchase with other family members. Whether the SimpleHaven Lifetime purchase is shareable is a setting Apple administers, and Apple — not us — controls who is in a family group and what is shared. If a family member is under 13, they use the family organizer’s payment method per Apple’s rules, their experience of SimpleHaven is identical to an adult’s, and we recommend parents supervise that use given that the app is not directed to children under 13.
17. Government and law-enforcement requests
We respond to legally valid requests from government and law-enforcement authorities. Because Your content lives in Your own iCloud private database, in most cases such a request would have to go to Apple, not to us — we cannot produce what we cannot read. When we do receive a request:
- We require valid legal process appropriate to the data sought.
- We narrow the response to the specific data legally compelled.
- We notify You where legally permitted; some orders prohibit notice.
- We log the request and, where lawful, will publish aggregate statistics in a future transparency report.
18. Changes to this Policy
We may update this Policy from time to time. Material changes — a new category of data we collect, or a new processing purpose — will be announced by in-app notice and on simplehavenapp.com with at least 14 days’ notice, logged in the revision history below, and, where consent is the lawful basis, accompanied by a fresh consent flow. The effective date at the top of this document indicates when the current version took effect.
The version published on this page is the authoritative one. A copy of this Policy is also bundled inside the app; if the two ever differ, the version and effective date shown at the top of this page govern.
19. Rights summary by jurisdiction
| Jurisdiction | Access | Delete | Correct | Opt out of sale/share | Limit sensitive PI | Portability | Appeal |
|---|---|---|---|---|---|---|---|
| EU / UK (GDPR) | Yes (Art. 15) | Yes (Art. 17) | Yes (Art. 16) | N/A — we don’t sell | N/A — no Art. 9 data | Yes (Art. 20) | Yes — supervisory authority |
| California (CCPA/CPRA) | Yes (§ 1798.110) | Yes (§ 1798.105) | Yes (§ 1798.106) | Yes (§ 1798.120) | Yes (§ 1798.121) — none collected | Yes | Yes |
| Virginia, Colorado, Connecticut, Texas and other comprehensive-privacy states | Yes | Yes | Yes | Yes | N/A | Yes | Yes |
| Utah | Yes | Yes | No | Yes | N/A | Yes | Yes |
20. Contact
SimpleHaven Technologies LLC
Attn: Privacy Team
5900 Balcones Dr Ste 100
Austin, TX 78731
United States
Privacy: privacy@simplehavenapp.com
Security: security@simplehavenapp.com
General legal: legal@simplehavenapp.com
Support: support@simplehavenapp.com
Related documents: Terms of Service · End-User License Agreement · Open-source attributions · Security and disclosure policy.
21. Revision history
| Version | Effective | Changes |
|---|---|---|
| 1.0 | 2026-05-26 | Initial version. |
| 1.0.1 | 2026-05-27 | Product rename pass; effective-date refresh. No substantive policy changes. |
| 1.0.2 | 2026-08-07 | Provider identity and contact details clarified. No privacy commitment was weakened in this revision. |
| 1.0.3 | 2026-08-12 | Full business address added to the controller and contact blocks. Data categories and permissions restated more completely, and the purchase-retention row corrected to the one-time purchase. New sections added on App Store privacy-label alignment, third-party equal protection, and a step-by-step deletion and consent-withdrawal procedure. No privacy commitment was weakened in this revision. |
| 1.0.4 | 2026-08-12 | Territory statement revised and several data categories restated to match the shipping app more exactly. No privacy commitment was weakened in this revision. |
| 1.0.5 | 2026-08-12 | Territory statement corrected, superseding 1.0.4: Section 2 now states that the app is not offered on European Union storefronts, that no representative is designated under either Article 27, and that none is required. Section 1 notes that the GDPR material describes a standard we hold ourselves to. Section 11.3 labelled explicitly conditional. Direct contact at privacy@simplehavenapp.com remains available to everyone, everywhere. No privacy commitment was weakened in this revision. |
| 1.0.6 | 2026-08-12 | Editorial only. Several descriptions in Sections 4.1, 6.2 and 11.1 were reworded to state purposes in plain terms. Nothing changed about what is collected, why it is collected, where it is stored, how long it is kept, or Your rights. |
| 1.0.7 | 2026-08-12 | Section 11.2 corrected: it previously described generative-model license terms and asked You to accept use-based restrictions for a model the shipping app does not contain. It now states plainly that the app performs no generative image synthesis and imposes no such restriction on You. The cloud-rendering commitments in Section 11.3 no longer describe a specific third-party retention window, because no such processor is engaged; the 60-second limit on our own side is unchanged. Two purpose descriptions in Section 4.1 were reworded. Nothing changed about what is collected, why it is collected, where it is stored, how long it is kept, or Your rights, and no privacy commitment was weakened in this revision. |
| 1.0.8 | 2026-08-13 | Section 4.1 corrected against the shipping binary. A “Motion and altitude” row was removed: the app contains no motion or altimeter code and declares no motion permission, so the row described a capability that does not exist and pointed You at a Settings control You do not have. A “Photo library (add only)” row was replaced by a “Floor-plan reference image” row: the app has no way to write to Your photo library, and the only photo access it has is Apple’s system picker handing it the single image You choose, which requires no photo-library permission. Section 12.2 was updated to match. These are corrections to descriptions of what the app can do. Nothing changed about what is collected, why, where it is stored, how long it is kept, or Your rights. |
End of Privacy Policy.