CHROME EXTENSION · MV3 · IN DEVELOPMENT
Haven
A private wellbeing journal. Thirteen note-taking tools drawn from established therapy practice, kept entirely on your own device — no account, no server, and no network access of any kind.
IN DEVELOPMENT — NOT YET ON THE CHROME WEB STORE
Nothing is submitted and nothing is listed. Version 0.5.0 is packaged and gated; that is a build, not a store listing, and this page does not claim otherwise. When a listing exists, this chip becomes a button and this sentence changes.
What it is
Therapy asks you to keep notes. A diary card, a thought record, an exposure log, a sleep diary — the between-session record that half of an appointment is spent reconstructing from memory. Haven is a place to keep that record where it stays yours.
It opens in a full browser tab from the toolbar icon, or with Alt+Shift+H. Thirteen modules are available; six are on to start with and the rest are one switch away. Turning a module off hides it and never deletes what you wrote in it.
Haven is free. There is no account, no subscription, no paid tier and no advertising. That is not an introductory offer — there is nothing in the product for a tier to sit behind.
The thirteen modules
Every one is modelled on a worksheet or log used in documented practice, and every one names the practice it comes from inside the app rather than inventing a framework of its own.
Mood Log
Mood, energy, anxiety and irritability with the context around them. Routine mood charting, used as an adjunct in both CBT and DBT.
DBT Diary Card
Emotions, urges and the skills you actually used, in the Linehan diary-card shape. Takes your own target rows, because a card used in treatment is set up for the person using it.
CBT Thought Record
The seven-column cognitive restructuring record: situation, thought, belief rating, evidence both ways, a balanced view, and the re-rating afterwards.
Exposure Tracker
An exposure and response prevention practice log. Distress at start, peak and end, what you expected to happen, what you did instead, and whether the ritual was prevented.
Safety Plan
The Stanley-Brown safety-planning structure: warning signs, coping steps, people and places that help, making the environment safer, and reasons for living. Reachable in one click from anywhere in the app.
Grounding Library
Fourteen distress-tolerance and grounding techniques with instructions for each, and a before-and-after log so you can see which ones actually work for you.
Gratitude Journal
The three-good-things exercise, with room for why each one mattered.
Values Worksheet
ACT values clarification across six life domains, each rated for how much it matters and how closely you are living it, plus commitments and the barriers in the way.
Sleep Log
The Consensus Sleep Diary core items, with sleep efficiency worked out for you rather than left as arithmetic homework.
Task Capture
A behavioural-activation task list sized by the energy each thing takes, with pleasure and mastery ratings.
Session Prep
What you meant to say, written down before the appointment instead of remembered halfway home from it.
Habit Tracker
Habit scheduling and adherence, with a cue for each one and streaks that forgive a missed day.
Trigger Log
Antecedent, behaviour, consequence — with the immediate consequence and the later one held apart, because that pairing is what shows why a behaviour repeats.
Rows you add yourself
Every module takes fields you define: a target behaviour, a sensation, a longer note, or an urge — where the urge template produces the clinical shape, a 0 to 5 rating paired with a “did you act on it?” checkbox. Your rows validate, chart, export and print exactly like the built-in ones, and removing a row hides it from the form without deleting anything you wrote in it.
An example week you can browse before writing anything
On first launch Haven offers a made-up week across all thirteen tools, so you can see what a filled-in diary card, a thought record and a real trend chart look like before committing a word of your own. It is worth being exact about how that works, because most software that does this seeds rows into your real store and leaves you to clean up afterwards.
- The example is never written to storage. It is generated in memory when you switch it on and it is gone when you switch it off. There is no sample data to find and delete later.
- It is read-only. Saving, editing, importing and exporting are switched off at the storage layer while it is showing — not hidden in the interface — so fabricated entries cannot reach a backup or a document you print.
- Your own entries sit untouched underneath it and come straight back when you leave.
What Haven does not do
This section is here because the honest limits of a tool like this are load-bearing, not fine print.
- It does not screen, score, diagnose or advise. There are no clinical questionnaires in it — no PHQ-9, no GAD-7, no Y-BOCS. It does arithmetic on your own entries, and arithmetic is not assessment.
- It is not a substitute for care from a professional, and it is not an emergency service. It cannot contact anyone on your behalf. If you are in immediate danger, call your local emergency number.
- It has no streaks that can break. Every count only goes up. There is no current-streak display anywhere in the app, because a zero on a hard day is a loss notification dressed as a statistic.
- It cannot reach the network at all. Not “does not” — cannot. See the privacy section below.
- It has no AI features, and will not get any. Every one of them needs a network request, and the absence of that request is the product.
Built on evidence, where evidence exists
Two design decisions here came from the literature rather than from taste, and both of them removed features rather than adding them.
The first is streaks. Silverman and Barasch, writing in the Journal of Consumer Research in 2023, measured that a broken streak reduces later engagement, and that the effect is strongest when the person attributes the break to themselves. A 2026 systematic review of gamification in digital mental-health tools lists failed achievement streaks, leaderboards and loss-framed points among its documented harms in exactly this population. So milestones in Haven are off by default, count only upward, and a test in the build fails if praise or scolding appears in their wording.
The second is the example week. Every mature product that seeds demonstration data into a real store eventually publishes a support article explaining how to delete it. In a local-only tool there is no support article, no undo and no server copy — so the example does not go into the store at all.
Colour, contrast and reading
Five accents, each in light and dark. The colours were not chosen by eye: each foreground was solved numerically against its own surface, and all 130 resulting pairs are re-checked against the WCAG AA threshold on every test run, so a hex that looks nicer and reads worse fails the build.
- Sage
- Blue
- Butter
- Purple
- Red
- Light
- Dark
Alongside them: four text sizes that scale the whole interface rather than just body copy, a higher-contrast mode, an always-underline-links switch, reduced motion, and a switch that turns single-key shortcuts off for anyone using speech input or whose keystrokes are less deliberate than the design assumes.
Your data is a file you own
JSON round-trips back into Haven exactly, including your own custom rows and every entry’s original date. CSV opens in any spreadsheet, with the entry id and a second-precision timestamp as real columns rather than a day-only approximation. The printable views are what you take to an appointment, through your browser’s own print dialog.
There is also a switch for what leaves Haven. Shared documents can carry your ratings, dates, dropdown answers and ticked skills while leaving out everything you typed in your own words — the paragraphs stay home and the structure goes to the appointment. It is deliberately not offered on the JSON backup, because a backup missing half your entries is a data-loss trap wearing a safety label.
Backups to a folder you pick, and the Google Drive question
A local-only tool has one real weakness, and it is worth naming precisely rather than dramatically. Clearing your browsing history and site data does not delete your entries — extension storage is a separate thing, and that was measured rather than repeated from the way local-only apps are usually described. What does delete them is uninstalling Haven, resetting or deleting this browser profile, using “Clear data” on Haven’s own entry in your extensions page, and losing the computer.
So Haven backs itself up. You pick a directory in your operating system’s own dialog; Haven writes a full JSON backup into it, at most once a day after you save something, keeping as many as you choose and deleting the oldest only after a new one has landed. It never touches a file it did not name. Restoring reads the newest backup back through the ordinary import path.
This costs no permission and no network access. It uses the File System Access API, which is not a fetch: the browser hands the extension one directory handle and nothing else, and Haven never learns where on your disk that folder is. The manifest still requests storage alone, and the content security policy still sets connect-src to none.
And that is the answer to Google Drive. If the folder you point Haven at is one that Google Drive, OneDrive, Dropbox or iCloud already syncs, your backups are in that cloud — through software you chose and installed, on your account, under your control. Haven itself does not speak to Google, cannot speak to Google, and cannot tell whether the folder is synced. A real Drive integration would need an identity permission, host permissions for Google’s API domains, and a content security policy that no longer says none. That is the one claim this whole project is built on, and a convenience feature is not worth spending it. If a synced folder is what you use, switch on the passphrase option: those backups are then AES-256-GCM encrypted before they are written, so what reaches the cloud is unreadable to it.
One honest cost, stated here as it is stated in the app: the backup passphrase is held in the open tab and is never saved anywhere, because a passphrase stored beside the file it protects is not a passphrase. After a browser restart, automatic backups wait until you type it in again rather than quietly writing a plaintext file in the meantime.
Questions
Is Haven on the Chrome Web Store?
Not yet. It is in development. Version 0.5.0 is packaged and has passed its build gate, but nothing has been submitted and there is no listing to install from. This page will say so plainly on the day that changes.
Does anything I write leave my computer?
No, and it is enforced rather than promised. The extension declares no host permissions and its own content security policy sets connect-src to none, so the browser itself blocks any network request an extension page could attempt — including one added by mistake in a future version. The build gate greps the source for fetch, XMLHttpRequest, WebSocket, sendBeacon and remote assets, and fails on a single hit.
What permissions does it ask for?
One: storage, to save what you write. If you switch on the optional daily reminder, Haven asks for the alarm and notification permissions at that moment and you can take them back at any time — a default install never has them. An earlier version also asked for the side-panel permission; removing the side panel removed the permission with it, and permissions on this project only ever shrink.
Is the passcode encryption?
No, and the app says so in those words. The passcode is a screen: it stops someone who picks up your computer from reading your journal, and it does not encrypt what is stored. There is no reset. For a file that actually leaves the device, the export offers real encryption — AES-256-GCM with a key derived from your passphrase at 310,000 PBKDF2 rounds.
Can it sync to Google Drive?
Effectively yes, without Haven ever touching Google. Point Haven’s backup folder at a directory your Drive client already syncs and the backups go to Drive through that client, on your account. Haven has no Drive integration, no identity permission and no network access, and a synced folder gets you the outcome without any of them. Use the passphrase option if you do this — the backups are then encrypted before they are written.
If I clear my browser data, do I lose everything?
No — and that was worth testing rather than assuming. Clearing browsing history, cookies and site data does not touch extension storage. What does lose your entries is uninstalling Haven, resetting or deleting this browser profile, “Clear data” on Haven’s entry in your extensions page, and losing the computer. An earlier version of this page said otherwise, and it was wrong in the alarming direction.
Who is it for?
Anyone keeping the notes that therapy asks for, and — squarely — neurodivergent people who find the standard version of these tools hostile. That means adjustable text and contrast, no timed pressure, no guilt mechanics, keyboard access to everything, and a form you can leave half-finished without losing it.
Privacy
This section is the privacy policy for Haven, and when a Chrome Web Store listing exists this anchor is the URL that will be given in its privacy field. Last updated 29 August 2026, for version 0.5.0.
| Question | Answer |
|---|---|
| What is collected? | Nothing. There is no collection step, because there is nowhere for anything to go. |
| Where do entries live? | In this browser profile, on this device, in extension local storage. Nowhere else. |
| Is there an account? | No. No email address, no sign-in, no identifier of any kind. |
| Analytics or telemetry? | None. No usage statistics, no crash reporting, no advertising identifiers, no cookies. |
| Is data sold or shared? | No — not sold, not shared, not transferred, for any purpose, because none of it ever leaves your device. |
| Does it read the pages I visit? | No. It declares no host permissions and injects no content script into any page. |
| Can it make a network request? | No. The content security policy blocks it at the browser level. |
| Is anything synced to my Google account? | No. Chrome’s sync storage is not used. |
| What about the example week? | It is generated in memory, never written to storage, and cannot be exported. Leaving it discards it. |
| Who can read my entries? | Anyone with access to this browser profile, unless you set a passcode. That is the honest answer for any local-only tool. |
| Can they be recovered if lost? | Not by anyone else — there is no server copy and no support address that can undo a loss. Clearing your browsing history and site data does NOT delete them: extension storage is separate, and that was measured rather than assumed. Uninstalling Haven, resetting this browser profile, or losing the device does. Set up the backup folder, or export a copy now and then. |
| Does the backup folder send anything anywhere? | No. The browser hands Haven one directory you picked and nothing else. If that directory is one your own cloud client syncs, your backups reach that cloud through software you installed, on your account — Haven cannot see it happen and still cannot make a network request. |
| Who do I contact? | dhseadev@gmail.com |
The permissions, one at a time
| Permission | Why |
|---|---|
storage | Writes your entries and settings to local extension storage on this device. This is the only place any of it is kept, and it is the only permission a default install requests. |
alarms | Optional, requested only if you switch on the daily reminder, revocable at any time. The alarm is scheduled and fired by your own browser. |
notifications | Optional, same as above. The reminder text deliberately says nothing about how you are, because it is read on a lock screen. |
| Host permissions | None are requested. Haven has no access to any site you visit. |
| Content scripts | None. Nothing is injected into any page. |
Standard disclosures. Haven does not collect personally identifiable information, health information, financial information, authentication information, personal communications, location, web history or user activity — because it collects nothing at all. It is not used for creditworthiness or lending. Its permissions are not used for any purpose unrelated to its single stated function.
Haven is a personal project by DHSeaDev. It is note-taking software, not treatment, and it is not affiliated with any clinical body or any of the practices its modules are modelled on.
Read more
Why Haven exists, and who it is built for — the design decisions, and what “built for neurodivergent people” means in a form field.
What thirteen mental-health apps taught me before I wrote a line — the competitor scan, the gamification evidence, and the four features that were declined on purpose.