Start tiny. Keep the proof. Currently in development for iOS and Android.

Havdone

Privacy

Privacy policy

This policy covers the Havdone mobile app and this website. Last updated 17 September 2026.

The short version

  • Your entries are private to you. We do not sell them or show them to other users.
  • You can use Havdone as a guest without giving us an email address.
  • Product analytics are on by default and can be turned off at any time. They never include anything you have written.
  • Crash reporting is separate from product analytics. It runs whenever Sentry is configured and is not controlled by the analytics switch.
  • You can permanently delete your account and its app data from inside Havdone.

Who we are

Havdone is operated by Misppelled Ltd, whose registered office is 106 Hither Farm Rd, London, England, SE3 9QU. We are the controller of the personal data described in this policy.

If anything is unclear, email [email protected] and we will explain it.

What the app collects

Things you give us

Your entries. This includes what you log, its tag or category, impact, and its date and time. We store this so it can appear in your Done list and Proof history and synchronise across your devices.

Your account details. If you save your progress with email and password, Supabase handles the password securely; we do not see it in plain text. If you choose Apple or Google sign-in, we receive the account identifier and available email or name that provider supplies. Apple may give us a private relay address when you use Hide My Email. Facebook sign-in may be offered in a future build; if enabled, the same limited principle applies. Your sign-in provider learns that you used it to access Havdone, but not what you log.

Your profile and preferences. These may include an optional display name, timezone, appearance, haptics, reduced-motion choice and reminder settings. Reminders are scheduled locally on your device; we do not keep a push-notification token.

Your purchase status. If you buy Havdone Pro, RevenueCat and the relevant app store tell us whether the one-time purchase is valid. We never receive your card or bank details.

Things collected automatically

An account identifier. A random identifier is created when Havdone first creates a guest account. It is not derived from your device, email address or entry text.

Crash and error reports through Sentry. When a Sentry DSN is configured, crash reporting is always on. It is separate from the product-analytics switch. Reports can include the error, affected code, app version, device model, operating-system version and an opaque account identifier. Havdone does not send default personal information. Before a report leaves the app, it removes request bodies, cookies, headers and query strings, and removes fields whose keys match email, title, text, password, token, content or body. Screenshots, view hierarchies and failed-request capture are disabled.

Performance data through Sentry. In production, approximately 10% of sessions may send timing information so we can find slow or unreliable parts of the app.

Product analytics through PostHog. Product analytics are on by default when PostHog is configured. Havdone shows this choice during onboarding, and you can turn it off at any time in Account → Privacy & diagnostics → Share product analytics. Turning it off stops new events immediately. Events describe screens and interactions, with aggregate properties such as whether a feature was used. They never include entry text, email addresses or other free text. Session replay, touch autocapture and automatic error capture are disabled.

Abuse-prevention checks. When account protection requires it, Havdone uses Cloudflare Turnstile or hCaptcha to distinguish a person from automated traffic. The provider receives the technical information needed to perform that check under its own privacy terms.

What we do not collect

Havdone does not request your location, contacts, photos, camera, microphone, health data or calendar. It does not use advertising identifiers, track you across other apps or websites, or show advertising.

Why we use this information

Information, purpose and legal basis
InformationWhy we use itUK/EU legal basis
Entries, profile and preferencesProvide and synchronise HavdonePerformance of our contract
Email and sign-in detailsCreate, secure and recover an accountPerformance of our contract
Purchase statusUnlock Havdone ProPerformance of our contract
Crash and performance reportsKeep the app reliable and secureLegitimate interests
Product analyticsUnderstand which parts of Havdone need improvementLegitimate interests; you can object by turning it off
Verification dataPrevent automated abuseLegitimate interests

Where we rely on legitimate interests, our interests are operating a reliable product, preventing abuse and learning which parts need improvement without collecting the content you write. You may object to this use by contacting us; product analytics also have an immediate in-app off switch.

Who processes information for us

We do not sell your data, share it for advertising or share it with other Havdone users.

Service providers and the information they process
ProviderWhat it processesWhere
SupabaseAccounts, entries, profiles and preferencesThe project hosting region and limited supporting infrastructure
SentryScrubbed crash and performance reportsEuropean ingestion endpoint
PostHogProduct analytics when enabledEuropean endpoint
RevenueCatPurchase entitlement and validationUnited States and other locations covered by its transfer terms
Apple and GoogleSign-in and store payments you choose to useUnder each provider’s own policy
Cloudflare Turnstile or hCaptchaA verification challenge when abuse protection is requiredGlobal infrastructure

Some providers operate outside the UK or European Economic Area. Where personal data is transferred internationally, we rely on the provider’s applicable safeguards, such as adequacy regulations, approved contractual clauses or a recognised data-transfer framework. We may also disclose information when the law requires it.

How long we keep it

  • Accounts, entries, profiles and preferences: kept until you remove individual content or delete the account. This also applies to guest accounts.
  • Crash, performance and analytics events: kept only for the active retention period in the relevant service and deleted or aggregated as those service settings roll over. Turning analytics off stops new PostHog events but does not rewrite events already received.
  • Purchase records: kept by RevenueCat and the stores for as long as needed to validate, restore and account for the purchase and meet legal obligations.
  • After account deletion: live app records and the authentication account are removed immediately. Residual encrypted copies may remain temporarily in provider-managed disaster-recovery backups until those backups rotate. They are not available in normal use and are not restored as an individual account.

Retention settings can change as providers and operational needs change. You can ask us for the current period applying to a particular record at [email protected].

Deleting your account and your rights

Use Account → Delete your account to remove the account and its live app records immediately. This also clears Havdone’s local cache on that device. Store purchase records and diagnostic or analytics events already held by separate providers are not automatically erased by that action. Read the full account deletion guide, or contact us if you want us to handle an identifiable provider record as part of a rights request.

Depending on where you live, you may have rights to access, correct, delete, restrict or object to our use of your data, receive a portable copy, and withdraw consent where consent applies. Email us to exercise a right; we will respond within one month unless the law permits longer.

You may complain to your local data-protection authority. In the UK, this is the Information Commissioner’s Office at ico.org.uk.

Children

Havdone is not directed at anyone under 16, and you must be at least 16 to use it. If you believe someone under 16 has provided personal data, contact us and we will investigate and delete it where appropriate.

Security

Data is encrypted in transit. The database uses row-level security so an account can access only its own rows, and passwords are handled and hashed by the authentication provider. No system is perfectly secure. Please report a suspected vulnerability privately to [email protected].

This website

The Havdone website has no account, form or newsletter. Google Analytics and PostHog are opt-in on the website: they do not load and set no non-essential cookie until you accept the cookie banner. If accepted, they record broad visit information such as page, referrer, approximate location derived from IP address and device type. This is separate from the mobile app’s analytics setting. You can change the website choice at any time: .

The hosting provider also keeps standard server logs, including IP addresses, for the limited period needed to operate and secure the site.

Changes and contact

We will update the date above when this policy changes and will give notice in the app when a change is significant.

Misppelled Ltd
106 Hither Farm Rd, London, England, SE3 9QU
[email protected]