Haya — Digital Wellbeing & Behavioral Health App
Last Updated: March 15, 2026Welcome to Haya ("we", "our", or "us"). Haya is a digital wellbeing and behavioral health application designed to support individuals in building healthier relationships with technology. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your personal data.
By using Haya, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the application.
🛡️ Our Core Commitment: Haya is built on the principle of privacy-first design. We never sell your personal data to third parties, and all sensitive health-related data is stored securely and used only to improve your personal experience within the app.
We collect the following categories of information:
Account Information
Behavioral & Health Data (User-Provided)
Usage Data (Automatically Collected)
What We Do NOT Collect
Haya utilizes the Android **VpnService** (Infinite Shield) to provide system-wide protection against adult and harmful content. By enabling this feature, your device's DNS requests are securely routed to our filtered DNS servers.
⚠️ Prominent Disclosure: The VpnService is used strictly for content filtering.
Your account data is stored securely using Supabase, a trusted cloud infrastructure provider with enterprise-grade encryption at rest (AES-256) and in transit (TLS 1.3).
Your behavioral health data (mood logs, journal entries, recovery milestones) is stored in your personal account and is only accessible to you. We implement Row-Level Security (RLS) policies to ensure that no user can ever access another user's data.
Content filtering rules (custom block lists) are processed and applied locally on your device whenever possible. We do not store records of what specific content was blocked or attempted to be accessed.
On iOS devices, Haya uses Apple's Family Controls framework (FamilyControls, ManagedSettings, DeviceActivity) to implement the optional "Shield Protocol." This feature allows you to voluntarily restrict access to specific applications and web domains during focus sessions or moments of vulnerability.
Haya integrates with the following trusted third-party services:
Haya may send push notifications for the following purposes:
You can disable all notifications at any time through your device's Settings app under Notifications → Haya.
Your data is retained for as long as your account is active. You may request full deletion of your account and all associated data at any time via our automated Account Deletion Page or by contacting us at the email address below. Upon a deletion request, all personal data associated with your account will be permanently removed from our systems within 30 days.
Haya is intended for users aged 13 and older. We do not knowingly collect personal information from children under the age of 13. If we become aware that a child under 13 has provided us with personal information, we will promptly delete their account and all associated data.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, please contact us directly at the email address below.
We may update this Privacy Policy periodically as our app evolves. When we do, we will update the "Last Updated" date at the top of this page and notify you via an in-app message if the changes are material. Continued use of the app after changes constitutes acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us: