Security
Where your scan goes, and how to tell us about a flaw.
A scan of your home is a floor plan of where you sleep. We treat it that way. The short version: it never comes to us, because we built the app so that it cannot.
Reporting a vulnerability
[email protected] — monitored by SimpleHaven Technologies LLC. We acknowledge reports within three business days and aim to give you an assessment within ten business days. Details below.
Architecture
How scans are handled
Capture happens on your device
Room capture uses Apple’s RoomPlan framework and your device’s camera and LiDAR Scanner. Camera frames and depth readings are processed as the scan runs and are not persisted as raw frames. What is kept is the finished result: room geometry, surface colors, furniture, and the reference photos the app retains on device so that the model resembles your home.
Storage is your iCloud, not our server
The finished model is written to the private database of the CloudKit container
iCloud.com.simplehaven.app. A CloudKit private database is part of the
user’s own iCloud storage. The developer of an app has no administrative read access to it.
In practical terms: SimpleHaven Technologies LLC cannot open, copy, export or back up your scans,
your room names, your device assignments or your notes. There is no separate SimpleHaven backend
that holds them, because there is no separate SimpleHaven backend.
Encryption at rest and in transit is handled by Apple as part of iCloud, including end-to-end encryption for the categories Apple covers under Advanced Data Protection when you have turned that on.
There is no account to compromise
SimpleHaven has no sign-up, no username, no password and no password database. Identity is your Apple Account, managed entirely by Apple. There is no credential of yours for an attacker to steal from us, because we hold none.
Apple Home access is local and permission-gated
Accessory state is read on the device through Apple’s HomeKit framework, under the permission you granted in iOS. It is never persisted by us and never transmitted off your device by us. SimpleHaven sends control commands — on, off, brightness, fan speed — through that same grant. It does not add, remove, rename or re-room accessories, and it does not create or edit scenes, automations or groups. Those stay yours to manage in Apple’s Home app. You can revoke the app’s access at any time under Settings → Privacy & Security → HomeKit.
No trackers, no analytics SDKs, no ad networks
The app’s privacy manifest declares no tracking and lists no tracking domains. It bundles no analytics SDK, no advertising SDK and no third-party crash reporter. The only crash data we can ever receive is what Apple forwards if you have turned on Share with App Developers in iOS Settings, and that arrives through Apple’s own pipeline.
Machine learning runs on device
Object detection, color analysis and image rendering all run locally using models shipped inside the app. Those models are frozen at the version we ship. Running them on your scan does not train them, and your data is never used to train anything of ours or anyone else’s.
What actually reaches us
Purchase metadata from Apple’s StoreKit (a product identifier, a transaction identifier and dates — never your payment card), any email you choose to send us, and opt-in crash reports routed by Apple. That is the list. It is spelled out with retention periods and legal bases in the privacy policy.
Coordinated disclosure
If you find something
We are a small company and we would much rather hear from you than read about it later. Email [email protected] with enough detail to reproduce the issue: what you did, what you observed, the app build number, and the device and iOS version. Proof-of-concept code, logs and screenshots all help.
What we commit to
- Acknowledge your report within three business days.
- Give you our assessment — confirmed, not reproducible, or working as intended — within ten business days.
- Keep you updated while we work on a fix, and tell you when it ships.
- Credit you by name or handle when we announce the fix, if you want that. We will not name you if you would rather stay anonymous.
- Not pursue legal action against you for research conducted in good faith under the rules below, and not ask a third party to do so on our behalf.
What we ask of you
- Give us a reasonable window to fix the issue before disclosing it publicly. Ninety days is our default; tell us if you need a different timeline and we will agree one with you.
- Test only against your own devices, your own Apple Account and your own data. Do not access, modify or destroy anyone else’s data, and stop as soon as you realize you can.
- Do not run denial-of-service tests, spam, social engineering, or physical attacks against us, our vendors or our users.
- Do not use automated scanners against Apple’s infrastructure. It is not ours to test.
Scope
In scope: the SimpleHaven iOS and iPadOS app and its bundled resources, and the simplehavenapp.com website.
Out of scope: anything belonging to Apple — iCloud, CloudKit, StoreKit, HomeKit and the App Store. Report those through Apple’s security channel. Also out of scope: issues in third-party accessories or hubs you have paired with Apple Home, and findings that amount to a missing best-practice header with no demonstrated impact.
We do not run a paid bug bounty
We are not going to pretend otherwise. There is no reward program and no payout. What we offer is a fast, honest response, a real fix, and public credit if you want it.
If something goes wrong
Breach notification
No system is completely secure. If a breach occurs that affects personal information we hold, we will notify affected people and the relevant regulators as required by applicable law — including notification to a supervisory authority within 72 hours where GDPR Article 33 applies, and under US state breach-notification law where it applies. Because your scans live in your own iCloud and not on our infrastructure, the data we could lose is limited to what is listed under “What actually reaches us” above.