Draft under review. This page is being prepared for Havory's launch. The operator named in these documents is not final. This page contains temporary TBA placeholders and is not final legal publication text yet.

Privacy Policy

Effective date: TBA
Last updated: TBA

This Privacy Policy explains how Havory processes personal data when you visit the Havory website, create or use a Havory account, use the app, use optional AI features, or contact Havory.

1. Who Is Responsible

Havory is provided by:

Legal operator and legal form: TBA
Business address: TBA
Telephone: TBA
Email: support@havory.app

The operator named above is the controller responsible for personal data processed through Havory within the meaning of the EU General Data Protection Regulation. These operator details must match the Legal Notice, Contact page, App Store trader information, provider records, and data-processing agreements before final publication.

2. Scope

This policy covers people who visit havory.app, people who create or use a Havory app account, and people who contact Havory by email or another published contact channel.

This policy does not cover data processing by Apple as App Store distributor, device operating-system provider, or account provider for Apple services. Apple's own terms and privacy information apply to those activities.

3. Data We Process

Account data

We process the email address, authentication identifiers, account identifiers, timestamps, and related security information needed to create, authenticate, protect, and manage your Havory account.

Purposes include account creation, authentication, service security, and account-related messages such as sign-up confirmation and email-address-change messages. Legal bases are performance of the Havory service contract, Article 6(1)(b) GDPR, and legitimate interests in security and abuse prevention, Article 6(1)(f) GDPR, where applicable.

Inventory data

We process the inventory content you add to Havory, including collections, item names, quantities, prices, dates, notes, links, item settings, collection settings, and other item details. The purpose is to provide the personal inventory features, sync your inventory across devices, and let you organise, search, edit, restore, and delete your content. The legal basis is performance of the Havory service contract, Article 6(1)(b) GDPR.

Shared webpage imports

If you choose Havory in your device's share sheet while viewing a webpage, the app may receive the webpage URL and product metadata available from the shared page, such as a title, brand, price, currency, canonical link, or product-image URL. The purpose is to prepare a new inventory item for your review. Havory does not automatically fill your Category or Notes fields from webpage metadata. The extraction is best effort and may be incomplete or inaccurate.

When shared fields are missing, the app may request the shared public URL directly from your device to read publicly available page metadata. If a webpage provides its product details only after scripts run, the app may load that public page and the page resources needed to render it in a temporary, non-persistent browser session on your device. This can cause requests to the webpage operator and to third-party services embedded by that webpage; those parties process the requests under their own policies. The temporary session does not reuse your Safari login or browsing data. If the page identifies product images, the app may also request and prepare a representative public product image. The Share Extension first stores the shared URL and available metadata in the app's shared on-device container and does not send them to Havory's backend. After you open the signed-in app, the shared URL, bounded extracted fields and evidence, processing status or error, and prepared image may be synchronised to your private Havory account so an unfinished Shared Items queue can be restored after local data loss or reinstall. Completed results may be reused when you reopen the app so that Havory does not request the same webpage again merely because you revisit Shared Items. A new share of the same link, an explicit retry or reprocess action, or a required importer update may request the webpage again. Pending-import data is not sent to an AI provider for this feature. It is removed when you save or discard the pending item, subject to temporary backup/log retention and a delayed retry if an offline deletion request cannot complete. After you review and save the item, the selected fields and image become ordinary inventory content and are processed under this Privacy Policy, including the image-storage processing described below. Restoring pending imports after reinstall requires signing in and completing an online synchronisation.

The webpage operator remains responsible for its own website, cookies, analytics, personal-data processing, prices, availability, content, and terms. Havory does not guarantee that an imported price or other webpage detail is current or correct.

Images

We process images you add to Havory, including item photos, avatar or profile images, and nutrition-label images if you choose to save them. The purpose is to display, store, sync, and process the images for the features you choose to use. The legal basis is performance of the Havory service contract, Article 6(1)(b) GDPR.

Optional AI features

When you use AI Assistant, we process your question, relevant inventory context, and recent conversation context where needed to answer you. When you use Nutrition Scan, the app may process a label image and recognised label text to extract nutrition facts. These features are optional requested features.

The legal basis for generating the AI Assistant answer or Nutrition Scan result you request is performance of the Havory service contract, Article 6(1)(b) GDPR. The legal basis for limited security, abuse-prevention, reliability, and operational logging connected with those features is legitimate interests, Article 6(1)(f) GDPR, where applicable.

Website visitor data

When you visit havory.app, technical data is processed to deliver the website. This can include IP address, timestamp, requested URL, user agent, device or browser information, TLS and security metadata, status codes, and similar request metadata. Purposes include delivering the website, securing it, preventing abuse, and diagnosing availability problems. Legal bases are legitimate interests, Article 6(1)(f) GDPR, and performance of a requested digital service, Article 6(1)(b) GDPR, where strictly necessary to deliver a requested page.

Support and contact data

When you contact Havory, we process your email address, message content, attachments, headers, and correspondence metadata. Purposes include responding to requests, providing support, handling privacy rights requests, legal notices, complaints, and establishing or defending legal claims. Legal bases are Article 6(1)(b), Article 6(1)(c), and Article 6(1)(f) GDPR depending on the request.

Deletion and audit data

We process account-deletion request data and limited operational records needed to run and verify deletion. Purposes include operating the 14-day restore window, completing scheduled deletion, preventing accidental deletion, and maintaining accountability evidence. The legal basis is legitimate interests in reliable deletion and accountability, Article 6(1)(f) GDPR.

4. AI Features And OpenAI

Havory has two optional AI features: AI Assistant and Nutrition Scan. Core inventory features can be used without enabling either feature.

When OpenAI processing is needed, Havory sends the request through Havory's backend. Havory does not deliberately add your email address, display name, or internal account identifier to the OpenAI request. However, the content you provide, such as item names, notes, photos, labels, or assistant messages, may itself identify you or another person.

Havory sends OpenAI requests with store: false, and organisation-level API-call logging is disabled. The active OpenAI project currently uses Global residency and does not have Zero Data Retention or Modified Abuse Monitoring enabled. These controls do not exclude all provider abuse-monitoring, safety-screening, prompt-caching, or temporary processing. Under OpenAI's documented default controls, abuse-monitoring logs may contain customer content and may be retained for up to 30 days unless approved alternative controls apply. Havory's pre-launch audit removed historical stored Responses created under the earlier logging posture and verified that they were no longer retrievable. Final contracting-entity and legal transfer wording remains TBA before publication.

5. Nutrition, Health, And Sensitive Data

Havory is a personal inventory app. It is not a medical device, healthcare service, nutrition adviser, emergency service, or health-record system.

Nutrition Scan is intended to extract nutrition facts printed on product packaging. AI Assistant is intended to answer questions about your inventory. Neither feature provides medical, dietary, allergy, safety, legal, financial, or other professional advice.

Havory includes free-text notes, item names, custom fields, images, and assistant messages. You could choose to enter information that reveals health, dietary, religious, political, or other sensitive information. Please do not use Havory to store medical records, diagnoses, prescriptions, health history, allergy emergency instructions, or other special-category personal data.

6. Cookies, Local Storage, And Device Access

The Havory app stores information on your device where needed to provide the service, such as authentication or session state, settings, cached display data, and local app state.

The Havory website does not use non-essential cookies, advertising tools, or visitor-level analytics. Cloudflare Real User Measurements are disabled, so Cloudflare does not inject its Web Analytics script. Cloudflare still processes ordinary request information, such as IP address, requested URL, device or browser information, timestamps, and security signals, where needed to deliver, protect, and operate the website. Analytics may be added later only after updating this policy and implementing any required consent or preference mechanism.

7. Recipients And Service Providers

Havory uses service providers to operate the app and website.

Supabase, Cloudflare, Brevo, Spaceship, and OpenAI publish data-processing terms and subprocessor information for their services. Havory must keep a current internal provider register, monitor material subprocessor changes, and ensure the final contracting entity shown in each provider account matches the operator named in this policy. Provider-specific retention and product configuration are described in the relevant sections above where they have been verified.

8. International Transfers

Some service providers or their subprocessors may process personal data outside the European Economic Area. This includes OpenAI for optional AI processing. Other providers involved in website delivery, cloud infrastructure, platform operations, support, security, or email delivery may also involve non-EEA processing depending on the final provider configuration.

Where personal data is transferred to a country without an adequacy decision, Havory relies on applicable provider data-processing terms and transfer safeguards, including the European Commission's standard contractual clauses where required. The providers may use subprocessors in the United States and other countries. Havory must complete and retain its controller-side transfer assessment before launch and revisit it when a provider, subprocessor, processing purpose, or relevant legal framework changes.

9. Security

Havory uses technical and organisational measures intended to protect personal data in a manner appropriate to the risk. Measures may include encrypted transport, account authentication, access controls limiting each account to its own data, restricted administrative access, secret management, deletion-process monitoring, provider security controls, and limited operational logging.

No internet service can guarantee absolute security. Final production security, backup, log-retention, and provider configuration details remain TBA before final publication.

10. Automated Decisions

Havory does not currently make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. AI Assistant and Nutrition Scan provide generated or extracted output for your review; they do not automatically decide your rights, eligibility, account status, pricing, or deletion outcome.

If Havory later adds automated decisions with legal or similarly significant effects, this policy and the product design must be updated first.

11. Account Deletion, Trash, And Retention

You can request account deletion in the Havory app. After a deletion request, a 14-day restore window begins. During that window, you can restore the account by signing in and choosing to stop deletion. If you do not restore it, the account becomes eligible for scheduled permanent deletion after the restore window ends.

Items and collections that you move to Trash may remain available for restore for a limited period. The current launch wording treats 30 days as an eligibility threshold for permanent deletion, not as a guaranteed exact deletion deadline. Havory uses a scheduled server-side process to check eligible Trash items and collections and permanently delete them; cleanup does not depend on opening Trash in the app, and processing may take longer than the eligibility threshold. Deleted data may also remain temporarily in backups or logs until those systems expire.

Pending shared-webpage imports are retained until you save or discard the pending item, or delete your account. If a removal is requested while offline, Havory retries it when the app can synchronise; deleted copies may remain temporarily in restricted backups until normal expiry.

Final retention periods will be stated here before publication.

12. Your Rights

Subject to legal conditions, you may have rights of access, correction, deletion, restriction, objection, portability, and complaint to a supervisory authority. The competent supervisory authority remains TBA until the final operator facts are set. You can contact Havory at support@havory.app.

At launch, data export and portability requests are handled manually through support@havory.app. After verifying the request against the account's confirmed contact details, Havory can prepare a ZIP containing machine-readable JSON account and inventory data together with linked private photos. Export generation checks that every included database row and file belongs to the requested account and excludes password hashes, authentication tokens, and service credentials. The package is delivered through an access-controlled, expiring channel rather than as an ordinary email attachment, and temporary delivery and local copies are removed after confirmed receipt or expiry under the operational export procedure.

13. Language

The final public Privacy Policy should be available in German for the German-market launch. English may be provided as an informational translation. If both versions are published and differ, the German version should control unless a later final publication decision says otherwise.