Privacy notice
Written in plain language, because I should be able to understand what happens to my information without needing a legal background.
What I collect, and why
I collect only what the service needs: my email address for secure sign-in, an optional preferred name, and the wellbeing entries I choose to create (check-ins, body awareness notes, reflections and completed practices).
Sign-up asks for as little as possible: my first name, my email address, a password, confirmation that I am 18 or over, and my agreement to the terms and privacy notice (the version and the date are recorded). My country is optional, and only used to show the right support services. No surname, no date of birth, no phone number and no home address are asked for. If I take a paid plan, the payment provider collects whatever billing details it needs — card details never reach SelfCare Haven, which only knows that my plan is active.
I do not collect diagnoses, clinical records, location, contacts or device identifiers. There are no advertising trackers, no analytics profiling and no third-party marketing tools in this app.
Consent
Wellbeing information is only stored after I give explicit consent. Sharing anything with my therapist is a separate, opt-in choice, and engagement summaries and written reflections are consented to separately.
I can review or withdraw any consent at any time in Privacy & security. Withdrawing consent stops future sharing immediately and does not affect my access to the app.
Nothing I enter is shared with anyone — not even my therapist — unless I explicitly choose to send it. Every kind of sharing is opt-in, and I can withdraw my consent at any time. Data is encrypted, EU-hosted, and handled in line with GDPR.
Who can see my information
By default, only me. My therapist sees my name and engagement summary only while I have consented, and can read written reflections only if I have given that separate consent.
Every time a therapist views client information, an audit entry is recorded. I can see the audit history relating to me in Privacy & security.
Security
Data is encrypted in transit (TLS) and at rest. Access is enforced at database level with row-level security, so one account cannot read another account's records.
Accounts require a strong password (minimum 12 characters with mixed character types), and two-factor authentication with an authenticator app is available to every account.
Where my data is stored
The database and backups are hosted within the European Union. There is no data brokerage: my personal data is never shared with third parties for their own purposes.
My rights
Under GDPR I can request access to my data, correction of inaccurate data, deletion, restriction of processing, and portability. I may also object to processing.
I can raise any of these requests from Privacy & security inside the app. Requests are responded to within one month. I also have the right to complain to my national data protection authority.
Retention
Wellbeing entries are kept while my account is active. If I delete my account, my personal data and wellbeing entries are deleted; limited, anonymised audit records may be retained where required for accountability, without my journal content.
What this service is not
SelfCare Haven is a wellbeing tool used alongside psychotherapy. It does not diagnose, does not provide treatment, does not offer AI therapy, and is not a crisis service.
If I need urgent help, I can contact the appropriate emergency service in my area.