Trust & Safety at Haven
Haven was built around one fact most learning platforms avoid: the best person to teach a fifteen-year-old is often not an adult. That means minors are on both sides of Haven — teaching and learning — and a platform where that is true has to be built differently from the first line of code.
The short version
| Minimum age | 13 |
|---|---|
| Under 18 | Guardian consent required, verified by Haven staff, before the account is used |
| Teachers | Identity verified with government ID, and profile approved by staff, before publishing or messaging |
| Messaging | Only between a verified teacher and their own enrolled students |
| Message monitoring | Automatic detection of phone numbers, emails, external links and off-platform services |
| Blocking | Anyone can block anyone. A block is invisible to the person blocked. |
| Reporting | Any message, user or course, from inside the product. Reviewed by a person. |
| Live classes | Live, on Zoom. Safeguards were published in advance at Live class safeguards. |
Identity verification
Every teacher on Haven verifies their identity with a government-issued document before they can publish a course or send a single message. This is handled by Persona, a specialist identity provider. The document is uploaded directly to Persona.
Haven never sees or stores the document or the verification photograph. We receive the result: pass or fail, an age band, whether the person is an adult, and a reference number.
Separately, a member of Haven staff reviews each teacher profile before it can be listed in the catalogue. A passed identity check on its own does not put anyone in front of students.
A passed check lasts two years. After that it has to be run again, and the teaching permissions that depend on it lapse until it is.
- What verification confirms — that a person is who they say they are.
- What it does not confirm — teaching ability, qualifications, credentials, employment history, or anything else a teacher claims about themselves. Haven does not verify those.
- What Haven does not do — criminal background checks. Identity verification is not a background check and we will not describe it as one.
Who can message whom
A teacher can message a student only if that teacher is verified and that student is enrolled in one of their courses. That is the whole rule. Students cannot message each other. Teachers cannot message students who have not enrolled with them. Nobody can message a stranger, and there is no way to search for a person and open a conversation.
This is enforced by the database itself, not by hiding buttons in the app. If someone constructed a request to reach a conversation they should not have, the database refuses it.
Detecting contact exchange
Most harm on learning platforms does not happen on the platform. It happens after a conversation moves to a private channel where nobody is watching.
So Haven automatically scans every message for phone numbers — including numbers spelled out in words — email addresses, including obfuscated ones, links to external sites, and the names of off-platform messaging and payment services. Matches are flagged for our moderation team.
The scanner errs towards flagging. A false positive costs a moderator a few seconds; a false negative is a conversation moving somewhere nobody can see.
Off-platform payment and circumvention
Taking a Haven-introduced student off-platform — to be paid directly, to avoid Haven's fee, or to carry on a conversation somewhere unmonitored — is prohibited for teachers and students alike.
This is a safety rule before it is a commercial one. Every protection on this page — verification, message scanning, guardian oversight, moderation, the record that makes a later report investigable — stops at the platform boundary. A conversation that moves to a private channel takes all of it away at once.
- Do not solicit or accept payment outside Haven for anything arranged through Haven.
- Do not share contact details in order to continue a relationship off-platform.
- Do not ask a student, particularly one under 18, to move to another app.
Photos and course images
Profile photos and course thumbnails are stored privately and served through short-lived signed links. An image is only reachable by someone the database has already decided may see the thing it belongs to — a published course, a listed teacher profile, your own account.
There is no pre-publication moderation queue for images. A teacher who uploads a thumbnail and publishes a course makes that image publicly visible at the moment they publish. Images can be reported, and removed, after the fact.
Guardians
Linking a parent or guardian is optional. A student under 18 uses Haven — including its live classes — on the same terms as an adult, and does not need a linked guardian to do so. Where a guardian relationship is claimed, a person at Haven checks it before it takes effect.
It works in two steps. The student generates a single-use code that expires after a day and gives it to their guardian. The guardian redeems that code on their own Haven account. That records who claimed the relationship — it does not grant anything on its own. Haven staff then verify the relationship, and record how they verified it, before the link takes effect.
We deliberately do not let a redeemed code be its own authorisation. A code that granted access to a child's private messages the moment it was typed in would only be as safe as the person holding it — and the person most likely to ask a child for that code is exactly the person this protection exists to stop. It is slower our way. It is also correct.
A verified guardian can request their student's account information and conversation history by emailing support@havencourses.com. Revoking a guardian link immediately closes everything that depended on it.
Reporting, blocking, and what happens next
Any message, user or course can be reported from inside the product, or by emailing support@havencourses.com. The person you report is never told who filed the report.
You can also block another user, which ends the conversation immediately. A block is invisible to the person blocked — they cannot tell a block from silence, which is the point.
- A report enters the moderation queue, with flagged and unresolved reports prioritised.
- A human moderator reviews the conversation and the context. Severity is assigned by Haven, never by whoever filed the report.
- We act — a warning, content removal, suspension, or permanent removal.
- Where a report concerns the safety of a minor, we act immediately and, where appropriate, contact law enforcement.
Emergencies and law enforcement
Haven is not an emergency service. We do not monitor reports around the clock, we cannot dispatch help, and we cannot respond at emergency speed. Our stated response time is 3 to 5 days.
If you believe someone is in immediate danger, contact your local emergency services first — in the United States, 911. Then tell us, so we can act on the account and preserve the records.
Where we receive a valid legal request from law enforcement, we respond as required by law. Where a report concerns the safety of a minor, we may contact law enforcement ourselves without waiting to be asked.
We preserve safety and moderation records, including messages already deleted by their sender, where they may be needed for an investigation.
Live classes
Live video classes have launched. Sessions are hosted on Zoom, on a Zoom account Haven controls rather than a teacher's personal login, so recordings of lessons involving minors stay somewhere Haven can audit.
We committed to publishing the safeguards before launching the feature, and we did: Live class safeguards describes the enrollment checks, teacher eligibility (including the guardian requirement that applies to teachers under 18), blocking behaviour, waiting rooms, authenticated participants, admin-only recording access, recording retention and reporting path that apply.
Recordings and transcripts are deleted from Haven's active recording store seven days after a class, by a job that runs nightly. That is the one retention period Haven enforces automatically today.
What we do not do yet
We would rather tell you what is missing than let you assume it exists.
- No pre-publication review of profile photos or course thumbnails. Images go public when a course is published.
- No standing scanning notice on the chat screen, though scanning is disclosed here and in the Privacy Policy.
- No guardian dashboard. History is available on request, by email, after we verify the relationship.
- No background checks beyond identity verification.
- No verification of teaching quality or qualifications.
- No round-the-clock moderation. Haven is invite-only while these systems are proven with a small group.
How this is built
The safety rules on this page are enforced in Haven's database, not in its interface. Access controls sit at the data layer, so a rule cannot be bypassed by manipulating the app, changing a URL, or calling an internal endpoint directly.
A large automated test suite runs on every change to Haven, and a substantial part of it exists purely to confirm that things which should be impossible remain impossible — that a teacher cannot reach a conversation they are not part of, that an unverified teacher cannot message anyone, that a revoked guardian link closes what depended on it.
We mention this because “we take safety seriously” is something every platform says. This is what we did about it.