Documentation

How to use Haven.

Haven finds the sensitive things you forgot you had — passwords sitting in old emails, tax documents in your cloud drive, files shared with the whole internet — and helps you clean them up. Everything below is what you'll actually see in the app. The scanning happens on your device; your content isn't sent anywhere to be read.

On this page
Getting started

An overview of Haven

Haven scans the accounts and devices you connect, surfaces anything that looks sensitive, and gives you one-click ways to deal with it. The whole loop is: connect your accounts → Haven scans → you review findings → you remediate.

1. Connect your accounts

Open the Connectors page from the sidebar and add the sources you want Haven to watch. You can connect as many as you like:

  • Email — Gmail, Outlook & Hotmail (outlook.com, hotmail.com, live.com, and Microsoft 365), and Proton Mail.
  • Cloud storage — Google Drive and OneDrive.
  • This device — pick a folder and Haven scans the files on your own computer.
  • iMessage — on Mac, Haven can scan your local Messages history.

Google and Microsoft each use a single sign-in that covers both their email and their cloud storage, so you only grant access once per account. You can connect more than one account of the same kind — several Gmail or Outlook mailboxes, say — and Haven keeps each one's findings labeled and filterable separately. Haven asks for the permissions it needs to read and (when you choose to act) tidy up — nothing more.

2. Haven scans

Scanning starts as soon as a source is connected. A first deep scan of a large mailbox can take a while, so Haven looks at the highest-signal items first — you'll usually have real findings to look at within the first minute or two, while the rest fills in.

Detection runs in three layers: fast pattern-matching and a local machine-learning classifier both run entirely on your device. For the small number of items that need a closer look, a short, bounded excerpt may be checked against Haven's own zero-retention service — it's never kept, and your content never goes to a third-party AI provider. You can see exactly what left the device on the Logging page.

Running scans on your terms

You don't have to wait for the background scanner. On the Connectors page, every connector — and each connected account — has its own controls:

  • Scan now — check a source for anything new since the last pass. This is a quick, incremental scan.
  • Rescan all — start over from a clean slate. Haven clears that account's existing findings, then re-scans the whole mailbox or drive from scratch with the current detection logic. This is the one to use after a Haven update improves detection, so older items get re-checked too. Because it clears findings first, Haven asks you to confirm.
  • Stop scanning — halt a scan that's in progress; anything already found is kept.

On a Mac, the iMessage connector has its own Re-scan from the beginning, which walks your full message history again. The Overview, Findings, and Sharing audit pages also carry a Scan now / Re-scan shortcut that drops you straight onto your connectors.

You can turn background scanning on or off per connector from the Connectors page. With it on, Haven keeps each source up to date and notifies you when something new turns up.

Experimental detectors (iMessage)

On Mac, the iMessage connector offers two detectors for the kind of private content that's most damaging if a device is lost, stolen, or used for extortion. Both are on by default, marked Beta, and live under Experimental detectors on the connector — turn either off per connector if you don't want Haven to look for it:

  • Detect intimate content — flags sexually explicit messages (text only) so you can decide what to keep. Intimate conversations sitting in cloud-backed threads are a common target in device theft and extortion.
  • Detect explicit photos — checks image attachments for sexually explicit photos. Because this needs more compute than a laptop has, each image is scored by an image-safety classifier on Haven's own GPU — sent over TLS, held in memory, never written to disk or logged — then you review and clean up the matches.

In both cases, content involving minors is never flagged. These detectors only ever look at the iMessage history you've already connected, and you can switch them back off at any time.

3. Review and remediate

The Overview page is your home base: your posture score and how it's moving, a summary of findings by severity, and the status of each connected source. From there you'll spend most of your time on three pages — Findings, Sharing audit, and Remediations — each covered below.

Posture score

Your posture score

The number at the top of the Overview is a single 0–100 summary of how exposed your connected accounts are right now — and, more usefully, which direction it's heading.

How it's calculated

Every finding Haven still considers open counts against the score, weighted by severity: a critical finding costs far more than a low one. That total is then measured against the size of everything Haven scanned, not taken as a raw count.

That last part matters. A fifteen-year-old mailbox with 140,000 messages will always contain more findings in absolute terms than an account opened last month. Scoring on raw counts would tell the person with the most history that they're the most careless, which isn't true and isn't useful. The score asks a fairer question: of everything you have, how much is exposed?

The score is calculated on your device, stored on your device, and never sent anywhere. Haven doesn't compare your score to other users' — there's no leaderboard and no percentile. A number that told you you're doing better than most people would be cold comfort while a password sat exposed in your inbox.

Three things the score always does

  • Connecting a new account never drops it. New sources set a new starting point rather than punishing you for looking. When it happens, the chart marks the moment as baseline moved and your score holds steady — then climbs as you clear things. Software that scored you lower every time you used more of it would be teaching you not to use it.
  • Remediating moves it up straight away — the moment you act, not at the next scan.
  • Telling Haven something is normal for you moves it up too. If you've said a finding isn't a concern, the score agrees with you instead of arguing.

If a new account turns out to be tidier than what you already had, the score is allowed to rise on its own merit — the protection above stops it falling, not from reflecting genuine good news.

Reading the trend

  • The trend chip under the score sums up the last week in plain English — "Up 4 points this week."
  • The sparkline plots the last 90 days, with a dashed marker anywhere your baseline moved.
  • Since last month breaks the change into what actually happened: findings resolved, new findings, the net movement, and which source improved most.

Small wins won't always shift the numeral — clearing one low-severity finding out of a hundred thousand items is a real improvement but a tiny fraction of a point. That's why the panel reports what you did alongside what the number did. A score that jumped on every click would be a progress bar, not a measurement.

Your score appears after Haven's first scan finishes; there's nothing to measure before that. Undoing a remediation lowers it again — the exposure is genuinely back, and a line that only ever went up would be tracking your clicking rather than your posture.
Findings

Reviewing your findings

A finding is a single item Haven thinks may contain sensitive information — one email, one file, or one message. The Findings page lists them all so you can work through them.

Severity

Every finding is rated so you can triage at a glance:

  • Critical and High — the things most worth handling first, like a plaintext password or an exposed account number.
  • Medium and Low — worth knowing about, lower urgency.

Finding your way around the list

  • Search the list, or use Add filter to narrow by severity, source, or account.
  • Switch between a flat list (sorted by severity) and a by-folder view that groups findings by their folder path — handy for cloud-drive results.
  • Select multiple findings with the checkboxes to act on them together.

Opening a finding

Click any row to open the detail panel. It tells you what you need to decide without ever quoting your content back at you:

  • Why this matters — a plain-language explanation of the risk.
  • What we found — a redacted preview, so you can confirm it's real without exposing the value to anyone looking over your shoulder.
  • Details — context like sender, recipients, date, file path, or who a file is shared with, depending on the source.
  • View in… — a button that opens the original item in Gmail, Outlook, Drive, OneDrive, Messages, or your file explorer.

From the same panel you can take an action (see Remediations) or tell Haven it got something wrong.

Teaching Haven what's normal for you

Two verdict buttons let you correct a finding and quiet similar ones in the future:

  • This is a false positive — the item isn't actually sensitive. Haven stops flagging that pattern.
  • This is fine — it's normal for me — the item is sensitive but expected (it's part of your normal workflow). Haven learns the context and stops nagging you about look-alikes.

Anything you've quieted this way can be reviewed and undone later under Settings → Your context.

Ask Haven

Ask Haven Beta

Ask Haven lets you ask about your exposure in plain language — "where are my tax documents?", "what's exposed externally?", "any old passwords in my inbox?" — and get back the findings that match.

Search, not a chatbot

Ask Haven is search over your findings, not a generative assistant. Your question is interpreted on your device and run against the same index Haven built while scanning. Nothing is sent anywhere to answer it, and — like the rest of Haven — it reads your findings, never the contents of your messages.

Asking a question

  • Open Ask Haven from the sidebar and type your question the way you'd say it out loud.
  • Or tap one of the suggested questions to start — your most sensitive findings, what's shared externally, where particular kinds of documents live, and so on.
  • Results come back as the same finding rows you see on the Findings page. Open any one for the full detail panel, or act on it with a remediation (see Remediations).

What it can answer

Ask Haven is good at narrowing your findings down by the things Haven already knows about them:

  • By kind — passwords and credentials, tax documents, IDs, financial info, and the other categories Haven detects.
  • By source — a particular place or account, like Gmail, Drive, or your local files.
  • By exposure — what's shared publicly or with people outside your accounts.
  • By rank — your most sensitive findings, or the top few worth handling first.

What it won't do

Because Haven keeps a record that a finding exists — not a copy of what it says — Ask Haven is honest about its limits instead of guessing:

  • It can't tell you what a message says. Haven doesn't store your message text, so it points you to the original to read it yourself.
  • It can't filter by who sent or received something — there's no contact graph behind your findings. Filter by kind or source instead.
  • Posture questions — how you're doing overall, or how your exposure is trending — are answered by your posture score on the Overview, not here.
Ask Haven is in Beta. Every answer is produced from the local index on your machine — no message bodies are read to respond, and nothing about your question leaves the device.
Sharing audit

The sharing audit

The Sharing audit page focuses on one specific risk: files in Google Drive and OneDrive that are shared more widely than you probably remember.

What it flags

  • Files set to anyone with the link or otherwise reachable on the public web.
  • Files shared domain-wide across an organization.
  • Files shared directly with people outside your own accounts or organization.
  • Stale external collaborators — outside people who still have access long after they needed it.

Haven knows the difference between sharing inside your own organization and sharing with outsiders, so routine collaboration with colleagues on the same work domain doesn't clutter the audit — the focus stays on files reaching people beyond your accounts. Personal mailboxes like Gmail or iCloud are always treated as external, since two people on the same provider aren't the same organization.

Two ways to look at it

The audit has a toggle in the top corner, because there are really two different questions here.

  • By file — the default. Each entry shows the file, the folder it lives in, and exactly who can reach it: a named list of people, or "Public via link." It uses the same list, search, and filter controls as the Findings page, so you can sort by exposure and work through the riskiest files first.
  • By recipient — the same sharing, organised by who. One row per person or link, with how many of your files they can reach and the worst severity among them. Open a row to see the files.

A file list is the right shape for handling one thing at a time. It's the wrong shape for "wait — how much does this one person still have?", which is the question that actually comes up when a contract ends, a job changes, or a relationship does. That's what the recipient view is for.

Links and domain-wide grants get their own rows at the top, ahead of individual people — an open link is usually the widest exposure you have, so it shouldn't be buried alphabetically among your collaborators. Above the list, a simple map connects recipients on the left to the files they can reach on the right. If you have a lot of recipients, Haven shows the most-exposed and tells you plainly how many more there are.

Fixing it

Open any entry to inspect it, jump to the file's sharing settings with View in Drive / OneDrive, or fix it on the spot with Revoke link — which removes the over-broad sharing permission. You can also select several files and revoke them in one go.

From the recipient view there's one more: Revoke everything shared with this person, which removes that one person's access across every file they can reach. It removes only them — other collaborators on the same files keep their access. Like every other action in Haven, it's reversible for 30 days, and if a revoke fails on one file the others still go through and Haven tells you which didn't.

Remediations

Taking action — and undoing it

A remediation is any action you take on a finding. Haven's promise is simple: every action is reversible for 30 days, so you never have to be afraid to click.

What you can do

The available action depends on where the finding lives:

  • Archive — for Gmail and Outlook, moves the message out of your active inbox while keeping a copy in your archive.
  • Move to trash — for Gmail and Outlook, sends the message to Trash. It's never hard-deleted, and it stays recoverable for 30 days — both from Haven and from your mail provider's own Trash.
  • Add a sensitive label — for Gmail and Outlook, tags the message so it's easy to find later, without moving or hiding it.
  • Revoke link — for Drive and OneDrive, removes the public or external sharing permission.
  • Mark as resolved (also shown as Mark as handled) — records that you've dealt with a finding yourself and hides it from your dashboard, without Haven changing anything on the account. Use this for things that get fixed elsewhere too — an exposed API key or password you need to rotate — once you've made the change.

When a finding is a login or password sitting in an email, Haven also offers to save it to a password manager — 1Password, Bitwarden, or LastPass — and then archive the original, so the credential ends up somewhere safe instead of in your inbox.

When you've selected several findings, the same actions are available in bulk from the toolbar.

The Remediations page

Every action you take is logged on the Remediations page (in the sidebar), with a timestamp, the connector, and whether it succeeded. Right after you act, a banner with an Undo button appears; for the next 30 days you can reverse any remediation from this log and Haven will restore the finding.

If an action can't complete — for example, your cloud provider's policy blocks a sharing change — Haven shows the reason rather than failing silently, so you know what to do next.
Trace

Trace Beta

A Trace gathers everything tied to one chapter of your life — a person, a project, a period, a topic — across the accounts you've connected, so you can review it as one cluster and secure it in one pass.

Describe the chapter

The description field is the search. Write it the way you'd say it — "the John Allison tax work in 2021–2022" — and Haven extracts the searchable parts on your device: names, organizations, email addresses, quoted phrases, and any years you mention (which set the time window unless you've picked dates yourself). Those become native searches on each provider — your sentence itself never leaves your machine in Fast search. The optional terms field narrows things further with exact names, addresses, or phrases.

If a description is too vague to search — no names, addresses, or specific phrases — Haven says so and asks for one, rather than running a search that matches everything or nothing.

Fast and Deep

Fast is exact matching: your planned search runs against each provider's own search engine (Gmail, Outlook, Google Drive, OneDrive, and iMessage on a Mac), returning up to 200 items per account with a line explaining what matched.

Deep starts with the same exact pass, then goes where string matching can't: Haven looks at who appears in your results, gathers other mail exchanged with those people in the same window, and has its private model judge — message by message — whether each one belongs to the chapter you described, even when it never uses your words. Items it adds are marked Related, with the model's one-sentence reason shown right on the item. Deep checks up to 100 candidates per run, using redacted excerpts on GPU infrastructure Haven operates end to end, and typically takes a few minutes longer. Gmail and Outlook today.

Ask about the results

Once a Trace finishes, you can ask questions of what it found — "what was my tax bill for 2022?" — right on the results. Haven picks the most relevant items (at most 12), re-reads them transiently, and has its private model check each one for the answer, then writes a short reply cited to the specific messages it came from. Nothing is stored: your mailbox stays the only copy, and if the answer isn't in the items checked, Haven says exactly that — including when it looks like the answer lives in an attachment it can't read yet.

Acting on a Trace

Select any set of results and Archive or Move to Trash in one pass (Gmail today). Every action lands on the Remediations page with the same 30-day undo as any other remediation. Past Traces are saved (the found items' details, never message bodies) so you can reopen, re-ask, re-run, or delete them.

What leaves your device

Fast search sends only the planned search queries to your own providers — each one visible verbatim in Logging. Deep search and Ask additionally send short, redacted excerpts of candidate messages to Haven's own inference infrastructure for judgment — the same bounded, logged, never-retained path the scanner's second-opinion tier uses. Every provider call and every model check appears in Logging, so what a Trace did is exactly what you can audit.

Settings

Settings

The Settings page is where you tune how Haven looks, when it notifies you, and what it has learned about you.

Appearance

Switch between light and dark themes. (The same toggle lives in the top corner of every screen.)

Tray & notifications

  • Keep Haven running in the background when you close the window, so scanning continues.
  • Start Haven when you sign in to your computer.
  • Quiet hours — set a window where Haven won't notify you, and when to resume.
  • Notifications — turn desktop notifications for new findings on or off, and choose the severity that's worth interrupting you (for example, Critical only, or Critical and High).

Privacy & inference

Shows how Haven handles the small number of items that need the deeper check — which model is in use and the zero-retention posture (excerpts are checked and discarded, never stored, and never sent to a third-party AI provider). Pairs with the Logging page, where you can audit every call that left your device.

Detection model

Shows the on-device classifier Haven is currently using — its version and when it activated. Haven improves this model over time; after an update, running Rescan all on a connector (see Getting started) re-checks older items with the newer detection.

Auto-updates

See your installed version, whether an update is available, and update on your schedule with Check for updates and Restart to update. New versions roll out gradually, so the page also tells you whether this install is eligible yet.

About you & Your context

These two panels are Haven's transparency window — everything in them is computed on your device and stays there.

  • About you — a read-only look at what Haven has inferred to make its findings smarter: a likely role, broad life-stage signals, your locale, and which kinds of sensitive content it has seen most. Nothing here leaves your computer.
  • Your context — the things you've told Haven. The content types you've marked as "normal for me," and the patterns you've quieted, each with a button to restore it if you change your mind.

Send feedback

A quick way to tell us what's working and what isn't, right from the app.