Privacy Policy

Effective Date: August 20, 2026

This Privacy Policy describes how MirrorTab Corp ("MirrorTab," "we," "our," or "us") collects, uses, and protects information when you use the StartHaven service available at https://starthaven.com ("Service"). By using the Service, you agree to the terms of this Privacy Policy.

1. Who We Are

Haven is a family of products from MirrorTab Corp, a Delaware corporation with principal offices in California, United States. MirrorTab Corp is the data controller.

Haven includes more than one product — including the Haven browser extension, the Haven Browser desktop application, and Haven for Gmail. What we collect depends on which product you use, and the differences are significant: the Haven Extension inspects pages on your own device, while Haven for Gmail reads message content on our servers. Below we describe the data common to all Haven products, and then describe each product separately.

2. Data Common to All Haven Products

Regardless of which Haven product you use, we may collect:

  • Account Information: Name, email address, login credentials, and optional profile details.
  • Diagnostic and Security Data: Log files, crash reports, and information related to security events or attempted unauthorized access.
  • Support Communications: Messages or attachments sent to our support alias.

We do not intentionally collect sensitive personal data such as health information, government IDs, or payment card data.

3. The Haven Extension

The Haven browser extension checks the pages and links you view for phishing and impersonation, and shields your sessions on protected sites. This checking happens locally, on your device.

The extension sends us security information only:

  • The hostnames of sites Haven checks or protects (not your full browsing history).
  • Link and threat verdicts (that a link was checked or flagged).
  • Shield activations (when Haven disabled other extensions while you were on a protected site).
  • Phishing and threat flags raised by Haven's detection.
  • An inventory of the extensions installed in your browser (such as name and version), which we use to evaluate extension-related security risk.

The extension does not send us your general browsing history, the contents of the pages you view, your keystrokes, or your passwords.

On-device AI: Haven's on-device phishing model uses Chrome's built-in Gemini Nano, which is downloaded and managed by Google Chrome and can use device storage and bandwidth. This model runs locally on your device without page data being sent to Haven; it produces a structural signature of a suspicious page for further analysis and service improvement.

4. The Haven Browser

When you use the Haven Browser desktop application, we may additionally collect:

  • Usage Data: Browser type, session activity, device identifiers, IP address, and interaction data used to improve performance and security.
  • The domain names of sites you visit and navigation button clicks (e.g., back, forward, refresh, settings).
  • Behavioral analytics: typing speed and mouse-movement speed and patterns (not keystrokes).

5. Flock (Optional Integration)

If you choose to use Haven's Flock integration, we process the contact information (such as phone numbers) you choose to share as part of that integration. You are responsible for obtaining any consents required from the people whose information you provide. If you do not use Flock, we do not collect this information.

6. Haven for Gmail (Optional Connected Service)

Haven for Gmail is a separate, opt-in service. It is off unless you connect your Google account to it. Unlike the Haven Extension, which inspects pages on your own device, Haven for Gmail processes your email on our servers. We describe it separately so that distinction is clear.

What it does: when new mail arrives, Google notifies us, we retrieve the message, extract and check the links it contains, and apply a "Haven - Flagged" label to the message if we consider it unsafe.

Permissions we request from Google:

  • Read and modify your Gmail messages and labels (the Gmail "modify" permission). We use this to read message content in order to extract links, and to apply the Haven label. This permission is broader than what we use it for; we do not delete your mail or send mail as you.
  • Manage Gmail labels, so we can create and maintain the Haven label.
  • Your Google account email address, so we know which mailbox a notification belongs to.

What we store: your Google authorization tokens, encrypted with a managed encryption key; counts of links scanned and flagged; and the email addresses of senders whose messages we flagged.

What we do not store: the contents of your messages. Message bodies and subjects are retrieved, checked, and discarded — they are not written to our databases.

You can disconnect Haven for Gmail at any time, which stops further scanning and deletes the authorization tokens and scan records we hold for you. You may also revoke Haven's access directly from your Google Account permissions page.

7. Google Workspace Directory (Optional Connected Service)

A Haven administrator can optionally connect their organization's Google Workspace directory so that Haven security policy follows the groups they already maintain, instead of rebuilding those lists by hand. It is off unless an administrator connects it.

Permissions we request from Google, both read-only:

  • View groups on your domain, so the administrator can see their groups and choose which to map to a Haven group.
  • View group members on your domain, for the groups the administrator explicitly mapped. We never list members of groups they did not map.

Haven never writes to, modifies, or deletes anything in your directory.

What we store: the Google group IDs and names for the groups the administrator selected, Haven's own group membership records (which reference Haven user IDs), and the Google authorization token, encrypted at rest with a managed encryption key.

What we do not store: the directory member list. Member email addresses returned by Google are used only in memory, to match against people who are already members of that organization's Haven account. We do not retain the email addresses of people who are not already Haven users, and we never create Haven accounts from directory data.

An administrator can disconnect the directory at any time, which deletes the stored authorization token. Access can also be revoked directly from your Google Account permissions page.

8. Google Workspace Data and AI (Limited Use)

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

In plain terms: we do not use Google Workspace data - raw, aggregated, anonymized, or derived - to create, train, or improve any foundational or generalized artificial intelligence or machine learning model, and we do not transfer it to any third party for that purpose.

On-device analysis. Haven's browser extension can use Chrome's built-in on-device model (Gemini Nano) to assess whether a link looks like phishing. It is disabled by default, runs entirely on your own device, and is never given data obtained from Google Workspace APIs. Nothing about it is transmitted to the model's provider for training or any other purpose.

Optional AI assistant access. Haven publishes a Model Context Protocol (MCP) server that an administrator may choose to connect to an AI assistant, such as Claude. If they connect one, information they ask for through it - which can include the names of directory groups - is sent to that assistant's provider under the administrator's own agreement with that provider, in order to answer their request. This is off unless an administrator sets it up, and it is used to answer their questions, not to train models. Haven does not send Google Workspace data to any AI provider for training, and does not enable this on anyone's behalf.

9. How We Use Your Data

We use personal data for the following purposes:

  • To operate, maintain, and improve the Service.
  • To communicate with you about updates, support, or security notifications.
  • To prevent, detect, and respond to fraud, abuse, or security incidents.
  • To comply with legal obligations.
  • To analyze usage trends and enhance user experience.

10. Legal Basis for Processing

Where applicable under data protection laws (e.g., GDPR), we process your personal data based on one or more of the following:

  • Your consent.
  • Performance of a contract (to provide you the Service).
  • Legitimate interests (to improve security and reliability).
  • Compliance with legal obligations.

11. Data Sharing

We share limited data with the following service providers, who process it only on our instructions and only to help us operate the Service:

  • Google Cloud Platform — hosting, databases, analytics, encryption key management, and message notification for Haven for Gmail.
  • Google Firebase — account authentication.
  • alphaMountain — domain and link reputation lookups. When Haven checks a link, the hostname is sent to this provider so it can be assessed.
  • Stripe — subscription billing. Payment card details are handled by Stripe and are not stored on our systems.
  • Mailgun — transactional and announcement email.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. See Section 17 for what those terms mean under California law.

We may share anonymized or aggregated data that cannot identify individuals.

12. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy or as required by law. Specifically:

  • Security telemetry (the events described in Section 3): retained for approximately 400 days, then automatically deleted.
  • Account and billing records: retained for the life of your account, and afterwards only as long as tax and accounting law requires.
  • Haven for Gmail authorization tokens and scan records: retained while the service is connected, and deleted when you disconnect.
  • Support communications: retained for as long as needed to resolve your issue and maintain a support history.

When data is no longer needed, it is securely deleted or anonymized.

13. Data Security

We use administrative, technical, and physical safeguards to protect data against loss, theft, and unauthorized access. However, no online service is completely secure, and we cannot guarantee absolute protection.

14. International Data Transfers

Your data may be stored and processed in the United States or other countries where MirrorTab or its service providers operate. We take steps to ensure appropriate safeguards are in place for such transfers.

15. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access, correct, or delete your personal data.
  • Withdraw consent at any time.
  • Object to or restrict processing.
  • File a complaint with a relevant data protection authority.

To exercise your rights, contact us at business@starthaven.com. California residents should also see Section 17.

16. Cookies and Tracking

We may use cookies or similar technologies for functionality, analytics, and security. You can adjust your browser settings to block or delete cookies.

17. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the rights below. We honor these rights for all users where we can.

  • Right to know: you may request the categories and specific pieces of personal information we have collected about you, the sources we collected it from, the purposes we collected it for, and the categories of third parties we disclosed it to.
  • Right to delete: you may request that we delete personal information we collected from you. We may keep information we need to complete a transaction, to detect and prevent security incidents, or to comply with a legal obligation.
  • Right to correct: you may request that we correct inaccurate personal information about you.
  • Right to opt out of sale or sharing: we do not sell personal information, and we do not share it for cross-context behavioral advertising. Because we do neither, there is nothing for you to opt out of, and we do not offer a "Do Not Sell or Share My Personal Information" link. If that ever changes, we will update this policy and provide the link before doing so.
  • Right to limit the use of sensitive personal information: we use sensitive personal information — such as your account credentials and, if you connect it, your email content — only to provide the service you asked for and to keep it secure. We do not use it to infer characteristics about you.
  • Right to non-discrimination: we will not deny you service, charge you a different price, or give you a lower quality of service because you exercised any of these rights.

Categories of personal information we collect: identifiers (such as name, email address, and account identifiers); commercial information (subscription and billing records); internet or network activity (the security telemetry described in Section 3); and, if you connect Haven for Gmail, the contents of email messages, which are checked and discarded rather than stored.

Where it comes from: directly from you, automatically from the Haven products you use, from your connected Google account if you connect Haven for Gmail, and from your employer or IT provider if your Haven is managed for you.

How to make a request: email us at business@starthaven.com. We will confirm we received your request within 10 business days and respond substantively within 45 calendar days. If we need more time, we may extend once by a further 45 days and will tell you why.

How we verify you: we match your request against the account it concerns. We will not ask you for identity documents in order to service a privacy request.

Authorized agents: you may use an authorized agent to make a request on your behalf. We will ask the agent for proof that you authorized them, and we may still contact you directly to confirm.

If your Haven is provided by your employer or IT provider, that organization directs how your data is used and we act as its service provider. Please direct your request to them; we will assist them in responding.

18. Changes to This Policy

We may update this Privacy Policy from time to time. If we make significant changes, we will notify you by email or within the Service.

19. Contact Us

If you have questions or concerns about this Privacy Policy, contact us at:

MirrorTab Corp

Attn: Privacy Team

Email: support@starthaven.com