Privacy policy
ShowHaven is a parental-control app. You hold the account, you decide what your child can watch, and this explains what we hold on your behalf. Every list below was taken from the actual database, not from a template.
Last updated 10 August 2026.
The short version. We collect what is needed to show your child the shows you approved, and nothing else. No ads, no analytics SDKs, no trackers, no data sold or shared for marketing — not now and not later. You can delete all of it yourself, immediately, from inside the app.
Who we are
ShowHaven is made by DTX Studios LLC. For anything in this policy, email support@showhaven.tv.
What we collect
From you, the parent
- Your email address and display name
- Your password, stored only as a scrypt hash — we cannot read it
- Your parent PIN, also stored only as a hash
- A household name and region
- A push token for your phone, if you allow notifications, so we can tell you when your child asks to come out
About your child
All of this is created by you, in your app. Your child is never asked for anything.
- A display name that you choose. It does not have to be their real name — “Child 1” works exactly as well
- An age range (3–5, 6–8 or 9–12). Never a date of birth
- An avatar picked from a fixed set of drawings
- The shows you approved, and the order you put them in
- The collections you build — their names and which shows are in them — and, if you share one, a record of the share code you created
- Which shows were opened and when, and whether the link worked
- What happened after: whether the show actually started playing, and whether your child left it and was brought back — the events behind the Activity page and its notifications
- Roughly how much of an episode was watched, so the app can offer the next one
- When your child asked to come out, and how you answered
About the devices
- A device name, platform and app version
- What the device is actually able to enforce
- When it last checked in
- A hash of its long-lived access token
What we never collect
This is not aspirational. The app does not request these permissions and the database has nowhere to put them.
- Location, of any kind
- Contacts, SMS or call logs
- Camera, microphone, photos or files
- Any advertising identifier
- Device serial numbers, IMEI, IMSI, MAC or wifi network names
- Biometrics
- Any browsing or app activity outside ShowHaven itself
- The contents of notifications
About notification access. ShowHaven asks for it, and it sounds worse than it is. Android puts “is something playing right now” behind that same permission, and that single fact is all we read — it is how the app knows your child is watching their show rather than browsing the catalogue. We never read the text of any notification, and nothing from your notifications is stored or sent anywhere.
Why we collect it
- To run the product — the approved shows have to be stored somewhere and synced to your child's device
- To keep your account secure — password hashes, PIN hashes and device tokens
- To answer your child — a request to come out is useless if we cannot notify you
- To fix broken links — when a streaming service changes how its links work, the record of failed launches is how we find out. This is the only thing viewing history is used for today
We do not profile anyone, build advertising audiences, or make automated decisions about your family.
Children's privacy
ShowHaven is sold to and used by parents, not marketed to children. An adult creates the account, chooses the shows, configures the restrictions and pays for it. What a child sees is the result of those decisions — a read-only screen of the artwork you approved.
Every child profile is created by that adult, and there is deliberately no text entry anywhere on the child's screen — no search, no messaging, no profile editing, no way for a child to type anything into ShowHaven at all.
A child's use of the app does still generate records: which show they opened, how much they watched, and when they asked to come out. We treat all of it as children's data and protect it accordingly, whether or not a regulator would classify it as personal information.
We do not knowingly let children create accounts, and there is no way for a child to share anything with anyone through ShowHaven. If you believe a child has provided us information some other way, email support@showhaven.tv and we will delete it.
Your consent, before anything is collected
Before you can add a child, children's privacy law — COPPA in the US, PIPEDA in Canada — requires your verifiable consent, and we ask for it by email. The same flow runs for every family, wherever they are. The email spells out exactly what ShowHaven collects from your child and what we do with it; clicking the link inside it is the consent. Because a child could type a parent's email address, we then send a confirmation to the same address describing what just happened, with a link to undo it. One consent covers every child you add on your account. If our data practices ever materially change, we will stop and ask you again first.
Revoking consent, and what it actually does
You can revoke consent at any time — from either email or from the app — and the link never expires. Revoking does two things immediately: no new child profiles can be created, and we stop recording your child's activity — no new watch history, no activity events, no resume points. Your child's device keeps working: the grid, the parental controls and your own settings are unaffected, because revoking consent should never punish the child. Revoking deletes nothing by itself — deleting a child or your whole account is a separate choice that is always yours, described below.
We keep a record of when consent was requested, given and revoked, for as long as your account exists — it is how we can show your consent existed for the data we hold. It is deleted with everything else when you delete your account.
Who else sees it
We do not sell data, share it for advertising, or hand it to data brokers. One exception you control entirely: if you share a collection, anyone you give the code to can see that collection's name, your household name, and its list of shows — that is the point of sharing. They never see your children, your email, or anything else, and revoking the code ends it. There are no advertising or analytics SDKs in either app. The only third parties involved are the infrastructure needed to run the service:
| Who | What they get | Why |
|---|---|---|
| Our hosting provider (IONOS, United States) | Everything above, stored on our own server in the United States | The service has to run somewhere |
| Cloudflare | Network traffic to our servers | Security and delivery of this website and the API |
| TMDB | The title you searched for. Nothing about you or your child | Show artwork, descriptions and which service carries a title |
| Expo push service | A push token and the notification text — which can include your child's display name and the show involved (“Ben left Bluey”). Expo relays through Google's and Apple's push systems to reach your phone | Delivering “asking to come out”, “stopped watching” and “brought back” notifications to your phone |
| IONOS (our email provider) | Your email address and the message being sent | Delivering account emails: verifying your address, and password-reset links you request |
| Google Play | Payment details, which we never see | Subscription billing, when billing is switched on |
Streaming services receive nothing about your family from us. When your child taps a show, ShowHaven simply opens that service's app on that title, exactly as tapping a link would.
Where your data is stored
On servers in the United States, in Missouri, run by our hosting provider IONOS. That is true wherever you live. If you are outside the United States, using ShowHaven means your information — and your child's — is sent there and kept there.
We say this plainly because it has a consequence worth understanding: information stored in the United States is subject to United States law, and can in principle be reached by American courts, law enforcement and government agencies through their legal processes, regardless of where you live. That is true of any service hosted there. We have never received such a request; if our position on that ever changes, this page changes with it.
We hold our hosting provider to terms requiring it to protect your information, and they process it only to run the service — they do not get to use it for anything of their own.
How long we keep it
Deletion runs automatically, every hour, against these periods:
| What | Kept for |
|---|---|
| What your child watched | 90 days |
| Device activity (started, stopped, brought back) | 90 days |
| Requests to come out | 30 days |
| Error reports, when something on our side breaks | 30 days |
| Pairing codes | 7 days |
| Password reset links | 7 days past expiry |
| Email verification links | 7 days past expiry |
| Sign-in tokens | 7 days past expiry |
| Your consent record (requested, given, revoked) | Life of the account |
| Devices that paired but never checked in | 365 days |
| Our log of staff access to your account | 365 days |
Your account, your children's profiles and your approved shows are kept for as long as you have an account, because they are the product. A device that has checked in is never aged out — a tablet left in a holiday cabin still belongs to its family.
On error reports: when something breaks on our side we record what was being asked for and what went wrong — the address the app called, the error, and the time. We do not put your name, your email or your children's names in them on purpose, but an address can contain the identifier of the profile or device involved, so we list them here rather than treat them as invisible.
Deleting your data
In the app: Settings → Delete account. It is immediate and irreversible, and it takes everything — every parent, child, approved show, watch record, device and token.
One thing survives, and we would rather name it than claim a clean sweep: our internal log of support access to your account — which member of staff looked at or changed something, and when. A record of who accessed a family's data is not much of a safeguard if the account holder can erase it. It holds staff actions and internal identifiers only, never your children's names or what they watched, and it is deleted after 365 days.
The full detail, including deleting a single child.
Your rights
Depending on where you live you may have the right to see the data we hold, correct it, delete it, or take a copy elsewhere. You can do most of this yourself in the app; for anything else, email support@showhaven.tv and we will respond within 30 days.
We will never make you jump through hoops or charge you for a request, and we will never refuse to delete an account to keep a subscription alive.
How it is protected
- Everything travels over HTTPS
- Passwords and PINs are stored as scrypt hashes, never as text
- Device tokens are stored as hashes, so a database copy is not a set of working keys
- Staff access to family data is logged, and that log cannot be edited by the person doing the accessing
Being honest about the limit: your parent PIN is a short number, shipped to the device so it still works with the wifi down. It is a genuine barrier against a child and it is not a defence against an adult with your unlocked tablet.
Changes
If this policy changes in a way that affects what we collect or who sees it, we will email every account holder before it takes effect rather than quietly changing the date at the top.
Who is accountable, and how to reach them
ShowHaven is operated by DTX Studios LLC, in Connecticut, USA. Patrick Shorey is the person accountable for privacy here — for how this policy is applied, for answering your questions about it, and for handling access, correction and deletion requests. Small company, so that is a real person rather than a department.
support@showhaven.tv — privacy questions and requests, and everything else. We answer within 30 days, usually much sooner.