Built like it matters.

    Haevn holds your family's calendar, budget, documents and messages. That is a responsibility, and this page explains plainly how we protect it.

    Your household is a wall, not a folder

    Every piece of Haevn data belongs to exactly one household, and that boundary is enforced inside the database itself, on every table, with no exceptions. One household can never read another's data, and we prove it with automated tests that try to cross the boundary and must fail.

    Records that cannot be quietly changed

    Haevn's audit records, consent records and co-parenting messages are append-only. Once written, they cannot be edited or deleted, by anyone, including us. That is enforced at the database level, not by policy.

    Sign-in without passwords

    There is no Haevn password to steal, guess or reuse. You sign in with a secure link sent to your email, or with Google. Every new sign-in triggers a quiet email alert, and Settings includes a single control to sign out of every device at once.

    Your data stays close to home

    Haevn runs in London (AWS eu-west-2). Data is encrypted in transit and at rest. We are built to UK GDPR standards, including the ICO Children's Code for anything touching a child's data: children's location sharing is off by default, clearly indicated when on, and switches itself off automatically.

    Honest deletion

    When you delete your account, we delete it: personal data anonymised, files removed, sign-in erased, and a tamper-evident record kept of the deletion itself. Where the law requires some shared records to survive (for example co-parenting records both parents rely on), we keep only those, only for as long as the law sets, and we tell you exactly that at the point of deletion.

    If you find something

    Security reports reach us at support@haevn.co.uk and are read by the founder. We would rather hear it from you than anyone else.

    Last reviewed: 22 July 2026.