What Naven collects, where it goes, who else touches it, how long it stays, and how to make it go away. Including the parts that are not flattering — a privacy policy that only lists the reassuring facts is an advert.
Last updated 6 September 2026Naven is new and it makes mistakes. This page describes what Naven does with your data, honestly and in detail. It is not a promise that your data is safe. Naven is written and run by one person, it is not end-to-end encrypted, and it offers no security guarantee of any kind — see what Naven does not promise. Do not put anything through Naven that would harm you if it were read by someone else, published, or lost.
| What | When | Given by |
|---|---|---|
| Account identifier | On sign-up | Generated |
| Display name | On sign-up | You |
| Email address | If you sign in with one | You or Google |
| Profile photo | If you add one | You or Google |
| Age band (under 13 / teen / adult) | On sign-up | Derived from the year you gave |
| Messages, pictures, voice notes | As you send them | You |
| Who you talk to | As conversations are created | Implied |
| Last-active time | Each visit | Automatic |
| How you first found Naven (one word) | On sign-up | Your browser |
| Channels you joined and posted in | As you use them | You |
| A count of blocked messages | Only when one is blocked | Automatic |
| Push subscription | If you turn notifications on | Your browser |
| Guardian's email address | Only for an under-13 account | You |
| Whether you agreed to marketing email, when, and the exact wording you agreed to | Only if you switch it on | You |
A hashed copy of your email address is stored so another member can start a conversation by typing an address they already know, without Naven publishing a directory anybody can browse. The stored value is a SHA-256 hash, and a lookup can reveal only your display name — never your address, and only if you switched that on.
Not collected: your birth date (only the band), your phone number, your contacts, your location, your browsing outside Naven, and any identity document.
There are three kinds, and they follow different rules on purpose.
Naven does not buy, rent, scrape or otherwise acquire email addresses. Every address it holds was typed in by the person who owns it, or supplied by Google when that person chose to sign in that way. Addresses are never sold or shared for anybody else's marketing.
Naven screens every message, picture and voice note before it sends. Screening a message and being unable to read it cannot both be true, so:
Naven is a small product standing on other companies' infrastructure. Each of these processes some of your data to do a specific job:
| Company | What it does | What it sees |
|---|---|---|
| Cloudflare | Serves the site, runs the API, stores channels and uploads | Requests, uploaded files, channel content, member records |
| Google (Firebase) | Sign-in and the message database | Account records, conversations, messages |
| Cloudflare Workers AI | Screens text, images and voice notes at the edge | Message content, at the moment it is screened |
| Groq, OpenAI | Fallback screening, and the assistant | Message content only when the edge model is unavailable; assistant prompts |
| Agora | Carries voice and video calls | Call media in transit |
| Resend | Sends email | Your address and the content of Naven's emails to you |
| NewsAPI | Supplies the newsroom's source material | Nothing about you |
These are processors, not partners: none of them is given your data to use for their own purposes, and none of them pays for it. Naven has never sold data and has no plan to.
Where your data physically sits. Cloudflare runs at the network edge and Firebase in Google's data centres, which means your data may be processed outside the country you are in. That is inherent to using a global platform, and it is the honest answer rather than a claim of a single location.
| What | Kept for |
|---|---|
| Messages | Until you or the other person deletes them, or the account is deleted |
| Uploaded files | Two years, then automatically expired |
| Voice-note transcripts | Not kept, unless the speaker turned on “Let people read my voice messages” — then kept with that message, and deleted with it |
| Account record | Until deletion is requested |
| Marketing consent record | Kept while the account exists, including after consent is withdrawn — the record of a withdrawal is what proves it was honoured |
| Blocked-message count | Rolling fortnight, and cleared on age confirmation |
| Push subscription | Until you turn notifications off or the browser drops it |
| Guardian approval | For the life of the account |
| Guest sessions | Only in your browser; gone when you clear its data |
| How you first found Naven | With the account, until deletion is requested |
| Page counts (no one is named in them) | One year, then deleted |
Naven is used by children and is designed for that rather than pretending otherwise.
Naven deliberately holds no identity documents. Age confirmation proves control of an email address — a guardian's, for a child. Verifying age with a passport scan would mean holding scans of children's passports, which is a category of data worth not having.
Depending on where you live you may have rights under the UK GDPR, the EU GDPR, the CCPA or similar law. Naven applies them to everyone rather than checking your postcode first:
One request handles any of these: shervin@shapoury.com. Expect a reply within 30 days, usually much sooner.
One limit worth being clear about. Deleting your account cannot unsend messages you already sent to other people. Those sit in the other person's conversation, which is theirs. Naven will not reach into somebody else's inbox and rewrite a conversation they took part in.
Naven sets no advertising or tracking cookies, and loads no analytics script, tag manager or pixel from anyone. There is no consent banner because there is nothing being shared with a third party to consent to.
What is stored in your browser, and why:
All of it is removed by clearing site data for navenapp.com.
Naven counts visits to its public pages on the server, as each page is sent. This is how one developer finds out whether anything he writes is read — without it, the honest answer to “is the safety page useful to anyone” is that nobody knows.
What that count contains:
What it deliberately does not contain:
If your browser sends Sec-GPC, nothing is counted for your visit at all.
That signal is about selling personal data, which Naven does not do — but it is a clear
statement that you would rather not be included, and honouring it costs nothing.
Crawlers — Google's, and the ones belonging to AI assistants — are counted separately under their own names, and are never mixed into the number of people.
Everything is served over HTTPS. Message access is enforced by database rules rather than by the app being polite about it, so a member can only read conversations they belong to. Uploads are keyed to the uploader. Secrets live in the server's secret store and never in the code. Push payloads are encrypted for one device.
What that does not mean. Naven is a free product built by one person. It has not had an external security audit. No system is unbreachable, and anyone who tells you otherwise is selling something. If something is genuinely private and high-stakes, use an end-to-end encrypted tool — and if you find a vulnerability here, please report it to the address below and it will be taken seriously.
Naven is operated by its developer, Shervin Shapoury. For a data request, a privacy question, a guardian withdrawing consent, or a security report: shervin@shapoury.com.
If this policy changes materially, members with an email address are told before it takes effect. The date at the top is always the current version.