Last updated: August 4, 2026 · Version: 2026-08-04
Heimvard is operated by KRAKN AS, organisation number 937 892 322, registered address Skjønhaugveien 13, 1940 Bjørkelangen, Norway. The data controller for personal data processed by the Heimvard service (within the meaning of GDPR Article 4(7)) is the operator named above. For privacy and data-protection matters, contact heimvard-privacy@krakn.no. For general correspondence, contact heimvard-legal@krakn.no. This disclosure is provided pursuant to GDPR Article 13, the Norwegian E-commerce Act (ehandelsloven) §8, and Article 5 of EU Directive 2000/31/EC.
Heimvard ("we", "us", "our") operates the Heimvard mobile application. This policy explains how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR).
We collect the following personal data when you use Heimvard:
We use your data for the purposes listed below. Each purpose has its own legal basis under GDPR Article 6.
| Purpose | Data used | Legal basis |
|---|---|---|
| Account and authentication | Email address, display name, session tokens, sign-in provider metadata | Art. 6(1)(b) — contract performance |
| Core service (reminders, task history, photos, contractor contacts) | Home profile, tasks, attachments, contractor contacts | Art. 6(1)(b) — contract performance |
| Subscription receipt validation, account association, and entitlement management | Purchase identifiers, store receipt, Firebase user ID, RevenueCat customer/subscriber identifiers, subscription tier, entitlements, transaction lifecycle metadata, device metadata, IP, locale | Art. 6(1)(b) — contract performance for paid tiers and requested purchase/restore operations |
| Crash and error reporting (toggleable) | Stack traces, device type, OS version, app version, internal user ID, approximate IP-derived geolocation | Art. 6(1)(f) — legitimate interest in a stable service |
| Over-the-air updates | App version, runtime version, device platform, OS version, Expo project identifier | Art. 6(1)(f) — legitimate interest in delivering bug fixes |
| Providing custom recurring tasks | Custom task title, category, cadence/frequency, optional description, property identifier, creator identifier, timestamps, and generated scheduled-task snapshots | Art. 6(1)(b) — performance of the Service you request by creating and managing custom tasks |
| Optional first-party product analytics | App-instance identifier, app/device metadata, automatic Firebase Analytics lifecycle events, and privacy-limited custom product events | Art. 6(1)(a) — your consent. Analytics is off by default and remains off unless you make an affirmative choice in Settings. You may withdraw that choice at any time without losing access to Heimvard. |
| Website operational notices | IP address, browser/user-agent information, request time, and Firebase project/resource | Art. 6(1)(f) — legitimate interest in showing visitors current maintenance, security, and service-status information |
| Optional marketing email | Current verified email address, display name, language, marketing preference, consent history, consent-copy version, unsubscribe/bounce suppression key, and limited server-only unsubscribe binding | Art. 6(1)(a) — your consent. Marketing remains off unless you make an affirmative choice, and you may withdraw it at any time in Settings or by using an unsubscribe link in a marketing email. |
| Essential account, billing, and service email | Current verified email address, display name, language, and limited purpose/export/send metadata | Art. 6(1)(b) when the message is necessary to provide or administer the Service you requested. Where a security or abuse-prevention message is not strictly contractual, Art. 6(1)(f) may apply based on our legitimate interest in protecting accounts and the Service. Essential email is not used for promotion. |
| Legally required or incident-response notices | Current verified email address, display name, language, relevant account context, and limited purpose/export/send metadata | Art. 6(1)(c) when we must notify you to comply with law; otherwise Art. 6(1)(f) where a serious privacy or security incident makes notice necessary to protect users and the Service. |
| AI-assisted technical troubleshooting and support | Email address or internal user ID, plus limited technical, account, or support context relevant to the issue | Art. 6(1)(f) — legitimate interest in investigating faults, keeping the Service reliable, and responding to support requests |
We do not use your account content, uploaded content, contractor data, or user-entered free text for marketing, advertising, or profiling. Firebase Analytics / GA4 is used for first-party product measurement only, as described in §8.1 and §16.
Your personal data — including your profile, properties, tasks, photos, and receipts — is stored on Firebase (Google Cloud Platform) infrastructure located in the European Union. We use the Firebase multi-region location eur3, which replicates data across Google data centres in Belgium (europe-west1) and the Netherlands (europe-west4). All core service data stays within the EU.
On-device data. Limited data is stored locally on your device so the app can function reliably: Firebase sign-in session tokens, app settings such as language, crash-reporting preference, and the current analytics-consent version, cached task-template and home-attribute content/translations, and temporary thumbnail/cache data for selected attachments. Core account records — properties, task history, notes, photos, receipts, contractor contacts, and custom tasks — are stored in Firebase unless explicitly described otherwise.
Firebase Authentication transfers. Firebase Authentication data (your email address and authentication tokens) is stored by Google on servers located in the United States. There is currently no EU data residency option for Firebase Authentication. Google transfers this data under Standard Contractual Clauses (SCC) and, where applicable, the EU-US Data Privacy Framework (DPF). We will migrate authentication data to the EU as soon as Firebase makes EU regional authentication generally available.
Firebase Analytics / Google Analytics for Firebase. Product analytics data is processed by Google Analytics for Firebase / GA4. This is separate from the Firebase eur3 storage location used for core service data. Analytics data may be processed outside the EEA under Google's Data Processing Terms, Standard Contractual Clauses, and, where applicable, the EU-US Data Privacy Framework. We keep analytics events coarse and avoid user-entered content or direct account identifiers.
RevenueCat (subscription processor). When you have an active paid plan or ask to purchase or restore one, subscription state, your Firebase user ID, store receipt information, and device metadata are processed by RevenueCat (RevenueCat, Inc.) on infrastructure located in the United States. RevenueCat is bound by a Data Processing Addendum incorporating Standard Contractual Clauses as the primary transfer mechanism, with the EU-US Data Privacy Framework providing additional coverage where applicable. See §8 for the data fields exchanged.
Expo Updates (over-the-air bundle delivery). When the app starts, it checks Expo's update servers for newer JavaScript bundles. Limited technical metadata (app version, runtime version, device platform, OS version, and an internal Expo project identifier) is transferred to Expo (Expo, Inc.) servers in the United States under Standard Contractual Clauses. No account data is included.
Static website service messages. heimvard.krakn.no uses a direct, storage-free HTTPS request to read enabled operational notices from our public Firestore collection without loading the Firebase Web SDK. The notice records are stored in our eur3 Firestore location. Google processes the technical request data described in §2 to deliver and secure the request under its Data Processing and Security Terms. International transfers of relevant Firebase service data are covered by Google's applicable terms, Standard Contractual Clauses, and, where applicable, the EU-US Data Privacy Framework. The site does not send a Heimvard account ID because visitors do not sign in.
Google Workspace email operations. KRAKN AS uses Google Workspace, including Gmail, Drive, Sheets, and Apps Script, to prepare and send Heimvard email. Google processes this customer data on our behalf under the Google Cloud Data Processing Addendum, which incorporates Standard Contractual Clauses for relevant international transfers. Recipient rows are temporarily processed in a restricted Google Sheet and sent as individual messages from authenticated krakn.no aliases. Google may retain revisions, deleted items, and recoverable data for the periods and purposes described in the Workspace service and processor terms.
OpenAI. When we use OpenAI tools for technical troubleshooting or customer support, the limited data described in §2 may be processed outside the EEA. We provide only the information needed for the specific task. OpenAI handles that data under its applicable privacy and data-transfer terms. See OpenAI's privacy policy.
We do not request structured fields for legal name, physical address, government ID, or financial-instrument data. Properties in the app are identified using user-defined nicknames only (e.g., "My Apartment", "Beach House") — never real addresses. Note that uploaded photos and receipts may contain such information incidentally; see §6. Subscription processing involves device identifiers and IP-derived approximate geolocation handled by RevenueCat; see §8.
Photos and receipts uploaded by users may contain personal information (e.g., names or addresses visible on receipts). Users upload this content at their own risk. We display a warning in the app before receipt uploads.
Please do not upload:
Uploaded photos and receipts are stored in our EU Cloud Storage bucket and are deleted in full when you delete your account (see §12).
Photo library and camera access. When you attach a photo, the app asks your device for permission to access the camera or your photo library. We only read photos you explicitly select; we never scan your library in the background.
We do not scan, analyse, or moderate uploaded images.
The in-app Custom Tasks feature lets paid-tier property owners create their own recurring maintenance tasks for a property. When you create a custom task, we store: the task title; category; cadence/frequency; optional description; your Heimvard user identifier; the property identifier; creation and update timestamps; and generated scheduled-task snapshots (title/category/frequency) so the task can appear in your normal task list, calendar, reminders, and history. Custom tasks are stored in the same EU multi-region location as your other data (eur3 — Belgium and the Netherlands).
Why we collect it. We process custom task data to provide the recurring task schedule, reminders, task completion history, and household/tenant visibility you ask the Service to provide. Legal basis: GDPR Article 6(1)(b) — performance of the Service.
What you should not include. Please keep custom task titles and descriptions to household or property-maintenance information. Do not include credentials, financial information, special-category personal data, or any of the categories listed in §6 ("Please do not upload").
Visibility. Custom task definitions are managed by the property owner. Generated custom task instances may be visible to household members or tenants who already have access to the relevant property/task under the app's normal sharing rules.
Retention and deletion. Active custom task definitions are deleted when you delete them or when your account/property is deleted. Deleting a custom task removes future upcoming instances, while completed, skipped, or review-pending task history keeps its lightweight snapshot so your maintenance history remains understandable.
Some Heimvard features let you store personal data of third parties. The most important example is Contractor Contacts, where you can save names, phone numbers, and email addresses of tradespeople you engage for property maintenance.
GDPR roles. When you store third-party personal data in Heimvard:
The Article 28 data processing terms governing this relationship are set out in Section 8 of our Terms of Service.
What this means in practice.
eur3 — Belgium and the Netherlands), and deletes it when you delete the entry or your account (see §12).Household exemption. If you use Heimvard purely for personal, household maintenance of your own home, GDPR's household exemption (Article 2(2)(c)) may mean GDPR does not apply to your storage of a tradesperson's contact details — comparable to saving a number in your phone's address book. Once you use Heimvard for a business or professional purpose (for example, the Landlord tier for managing rental properties), GDPR applies in full and the Controller / Processor framework above takes effect.
What you should not store. Please limit Contractor Contacts to professional contact information of tradespeople. Do not store special-category data (GDPR Article 9) — health, political opinions, biometric data — or other categories of third-party data that are not relevant to maintenance management (see §6).
We use the following third-party services to deliver and operate Heimvard. Their role and the data involved are described below. Snapshot as of the version date in the page header.
Firebase (Google LLC). Authentication, database, file storage, static-website operational notices, and Firebase Analytics / GA4. Google's GDPR-compliant Data Processing Terms apply. EU multi-region storage location (eur3 — replicated across Google data centres in Belgium and the Netherlands) for core database/storage data. See §4 for the Authentication, website service-message, and Analytics transfer notes.
Google Workspace (Google LLC). Operator-controlled email preparation and sending through Gmail, Drive, Sheets, and Apps Script. Temporary audience rows may include current verified email address, display name, language, and purpose-specific export fields. Marketing messages are sent only to current opt-ins and include a visible and standards-based unsubscribe path. Essential account messages use a separate sender and must not contain marketing. Heimvard does not use Workspace email for open tracking, click tracking, tracking pixels, behavioural profiles, or tagged engagement links. See §4 for processor and transfer information and §12 for retention.
Firebase Analytics / Google Analytics for Firebase (Google LLC). Optional first-party product analytics for app usage, onboarding, paywall/subscription conversion, and product activation. Native analytics collection and analytics storage are off by default. Collection starts only after you switch on Product analytics in Settings; Heimvard stores that choice on your device and checks the current consent-copy version before enabling the SDK. Firebase Analytics then automatically collects app lifecycle and device/app metadata such as first opens, app opens, app updates, sessions, operating system, device model, approximate geography, and in-app purchase signals. Heimvard also logs a small set of custom events for signup, onboarding, property creation, paywall views, purchase starts, subscription/lifetime conversion, restore success, and task completion. We do not send free-text content, task/property identifiers, uploaded-file metadata, contractor details, email addresses, or display names in analytics events. You can withdraw consent at any time in Settings. Withdrawal stops collection, denies analytics storage, resets the app's analytics identity on that device, and does not affect core app access. Legal basis: GDPR Article 6(1)(a) — consent. Transfer basis: Google Data Processing Terms, Standard Contractual Clauses, and EU-US Data Privacy Framework coverage where applicable. See Firebase privacy and security and Firebase Analytics data collection.
Sentry (Functional Software, Inc.). Crash and error reporting. Described in detail in §9.
RevenueCat (RevenueCat, Inc.). Subscription entitlement management and App Store / Google Play receipt validation for our paid tiers (Home, Landlord, Lifetime). When you sign in, we identify you to RevenueCat using your Firebase user ID so that an entitlement bought on iOS is recognised on Android (and vice versa) when you use the same Heimvard account. RevenueCat receives:
Account-bound purchase mapping. RevenueCat associates a verified store receipt with the identified Firebase user ID of the Heimvard account that made or first restored the purchase. Heimvard is configured not to move an already-associated receipt automatically to a different identified Heimvard account. When a RevenueCat-confirmed Free account begins a purchase, the app may first ask RevenueCat to synchronise the current store receipt. This lets us restore a purchase belonging to the current Heimvard account or stop before starting a new purchase when the receipt belongs to another account. Heimvard receives the entitlement result or an account-conflict error; it does not receive the other account's email address or reveal its identifier.
RevenueCat → GA4 integration. If you consent to Product analytics, RevenueCat may send subscription lifecycle events to Firebase Analytics / GA4 when the RevenueCat dashboard integration is configured. Heimvard then sets RevenueCat's reserved $firebaseAppInstanceId subscriber attribute so GA4 can attribute those events to the correct Firebase Analytics app instance. If analytics is off or you withdraw consent, Heimvard does not read an analytics app-instance ID and removes that RevenueCat attribute. These events may include subscription starts, renewals, cancellations, refunds, expirations, billing issues, product/package identifiers, entitlement status, platform, country/locale, and pseudonymous RevenueCat/Firebase identifiers. They are used only for first-party subscription analytics and are not used for advertising or cross-app tracking. Exact event names and fields are controlled by RevenueCat/GA4 integration behavior and may change as those providers update the integration.
Retention after account deletion. When you delete your Heimvard account we log the device out of RevenueCat, but that does not delete the RevenueCat customer record. RevenueCat retains the pseudonymous prior App User ID and its aliases, its association with the store receipt, store transaction history, product and entitlement history, and related subscription metadata. Heimvard deletes the account that supplied the Firebase user ID, so we no longer use that identifier as an active Heimvard account or send new account activity under it. A newly created Heimvard account receives a different Firebase user ID and does not automatically inherit that purchase association. RevenueCat documents a separate customer-deletion process for GDPR erasure requests. You can ask us to use that process by contacting heimvard-privacy@krakn.no; deleting a RevenueCat customer does not itself cancel an App Store or Google Play subscription and may affect our ability to recover or verify access later.
Legal basis. GDPR Article 6(1)(b) — processing necessary to perform the paid-tier contract you entered into. Transfer basis. Standard Contractual Clauses primary, EU-US Data Privacy Framework additional coverage where applicable. See RevenueCat's privacy policy.
Expo Updates (Expo, Inc.). Delivers over-the-air JavaScript bundle updates so we can ship bug fixes between full App Store / Play submissions. Each app start sends Expo: app version, runtime version, device platform, OS version, and our Expo project identifier. No account data, email, or content is sent. Legal basis: GDPR Article 6(1)(f) — legitimate interest in delivering bug fixes and security patches. Transfer basis: Standard Contractual Clauses. See Expo's privacy policy.
Sign-in providers (Apple, Google). If you choose "Sign in with Apple" or "Sign in with Google", the respective provider receives the standard sign-in metadata required to authenticate you (provider-issued user identifier, email address, and an authentication token). This data is forwarded to Firebase Authentication; we never see your provider password.
OpenAI. An authorised KRAKN AS operator may use OpenAI tools to help investigate technical problems and respond to support requests. OpenAI may receive your email address or internal user ID when it is needed to locate the affected account, along with limited technical, account, or support context relevant to the issue. We minimise the data shared and exclude unrelated account content.
We use Sentry (Functional Software, Inc.) to collect crash and error reports so we can identify and fix bugs.
Crash reporting is off until you enable it. You can make or change that optional choice in Settings → Crash and error reporting. The Sentry SDK is not initialized before an explicit opt-in, and disabling the choice stops later crash payloads from leaving your device.
What is collected when enabled. When the app encounters an error or crash, the following is sent to Sentry: the error stack trace, your device type, OS version, app version, and an internal user identifier (your Firebase user ID).
Linkability to your identity. Although Sentry does not receive your email address directly, the internal user identifier in crash reports can in principle be linked back to your account (and therefore to your email address) by Heimvard when investigating an issue. Crash reports are therefore pseudonymised, not anonymous.
Approximate geolocation. Sentry derives approximate geolocation (country, region, and sometimes city) from the IP address of the device sending the crash report. This happens during ingestion. We have enabled IP-address scrubbing and Advanced Data Scrubbing rules to limit what is retained, but some coarse geolocation data may be stored.
Legal basis. GDPR Article 6(1)(f) — legitimate interest in maintaining a stable, reliable service. Transfer basis. Standard Contractual Clauses; the EU-US Data Privacy Framework provides additional coverage where applicable.
For more information, see Sentry's privacy policy.
We do not sell or rent your personal data, and we do not share your personal data with third parties for their marketing or advertising. Google Workspace processes temporary audience data and outgoing messages on our behalf solely to operate Heimvard email. Limited account identifiers and relevant technical or support context may be shared with OpenAI for AI-assisted debugging and support as described in §8.2. Pseudonymised crash and error reports are shared with Sentry solely for identifying and fixing bugs, and only if you have not disabled crash reporting in Settings. Subscription and purchase data is shared with Apple App Store, Google Play, and RevenueCat solely to validate receipts and grant access to the paid tier you purchased. First-party product analytics data is processed by Firebase Analytics / GA4 as described in §8.1. Over-the-air update metadata is shared with Expo solely to deliver newer JavaScript bundles to your device. Website technical request data is processed by Google/Firebase solely to fetch and secure current operational notices, as described in §§2, 4, and 16.
As a user in the European Economic Area, you have the right to:
Your account data is kept for as long as your account is active. Account deletion removes your user-scoped Firebase records, including your profile, properties, tasks, photos, receipts, contractor contacts, custom task definitions, invitations, and the marketing preference/history described below. Processor-held and limited operational records follow the separate retention rules in this section.
Product analytics. Your analytics choice is stored on your device. A missing, unreadable, or older consent version means analytics is off. Firebase Analytics event-level data collected while consent was active is retained for no longer than 14 months. Withdrawing consent stops future collection, resets the app's analytics identity on that device, and removes the Firebase app-instance link supplied to RevenueCat; data already processed by Google ages out under the same retention limit.
Marketing preference and audit. Your current marketing preference and its change history are stored inside your user record and are deleted with that record when your Heimvard account is deleted. Choices can come from onboarding, Settings, or a marketing-email unsubscribe link. Withdrawing marketing consent changes the current state immediately but keeps the earlier consent event while the account remains active so we can show and prove the sequence of choices.
Temporary audiences. Recipient rows in the restricted Workspace sheet are cleared through the protected sender workflow after a verified completed send. Operators are required to delete downloaded CSV copies promptly after import and no later than 24 hours after export; this local-file step is procedural rather than automatic. If a send outcome is ambiguous, the affected temporary row is kept only until it can be reconciled safely; it is not retried blindly. Google Workspace revisions, trash, backup, and administrator-recovery handling follow Google's service and processor terms.
Email operational records. Recipient-key delivery records used to prevent duplicate sends and enforce the two-marketing-messages-per-Europe/Oslo-month limit are kept for the current and previous calendar month. Aggregate export and send logs, without recipient addresses, are kept for three years. Completed-export identifiers, without recipient addresses, are kept as durable reuse-prevention markers. A server-only exact-generation unsubscribe binding is kept only so an unsubscribe link can update the correct account preference; it stores no raw email address and is deleted with the account. A keyed unsubscribe suppression is kept until a newer explicit opt-in included in a fresh export supersedes it or the email system is retired. A keyed repeated-bounce suppression is kept until the address is verified corrected, changes, or the email system is retired.
AI-assisted debugging and support. Data provided to OpenAI may be retained under OpenAI's applicable terms and the data-control settings of the account used by KRAKN AS. Operators must limit each request to the account identifiers and context needed for the specific debugging or support task.
One narrow exception: deleting your Heimvard account logs the device out of RevenueCat but does not automatically delete RevenueCat's pseudonymous customer record (see §8). That record may include the prior App User ID and aliases, its association with the store receipt, store transaction history, products, entitlements, and subscription lifecycle metadata. It contains no Heimvard content such as photos, tasks, notes, or contractor contacts. A recreated Heimvard account uses a new Firebase user ID and does not automatically receive purchases associated with the deleted account. You may ask us to delete the RevenueCat customer record by emailing heimvard-privacy@krakn.no; legal exceptions may apply, deleting that record does not cancel a subscription with Apple or Google, and it may affect later purchase recovery.
Heimvard is not intended for use by children under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child under 16 has provided us with personal data, we will delete it promptly.
We take reasonable technical and organisational measures to protect your personal data, in line with GDPR Article 32:
No method of electronic storage or transmission is 100% secure. While we strive to protect your data using industry-standard practices, we cannot guarantee absolute security.
If we become aware of a personal data breach that affects you, we will:
The notification will describe the nature of the breach, the likely consequences, and the measures we have taken or propose to take in response.
The heimvard.krakn.no website is a static information site with one functional network integration: it makes a direct HTTPS request to our public Firestore collection for enabled operational notices when the page loads, every five minutes while visible, and when it becomes visible again. These requests disclose the technical request data listed in §2 to Google/Firebase. They are not used for analytics, advertising, profiling, or cross-site behavioural tracking.
The website sets no cookies and the service-message integration writes no browser storage. It does not load the Firebase Web SDK, Firebase Authentication, Analytics, Performance Monitoring, App Check, an advertising SDK, or gtag. Dismissing a website notice is remembered only in page memory and resets on refresh or navigation.
The Heimvard mobile app offers optional Firebase Analytics / Google Analytics for Firebase for first-party product analytics. Native collection and analytics storage are off by default. Nothing is collected unless you switch on Product analytics in Settings, and you can switch it off again without losing access to Heimvard. When enabled, it helps us understand whether users complete onboarding, create properties, view the paywall, start purchases, restore purchases, change paid tier, and complete maintenance tasks. Analytics events use coarse product metadata only; we do not log task titles, notes, property names, contractor details, uploaded-file names, receipt/photo metadata, email addresses, display names, or property/task identifiers.
Marketing preferences, opt-in/opt-out events, audience membership, email opens, and link clicks are not sent to Firebase Analytics / GA4. Email messages contain no tracking pixels or per-recipient engagement links.
Heimvard does not include ad networks, does not use IDFA-based tracking, does not show an App Tracking Transparency prompt, and does not use analytics data for cross-app tracking or personalised advertising. With analytics consent, RevenueCat lifecycle analytics may be connected to Firebase/GA4 through the RevenueCat dashboard integration for subscription events such as renewals, cancellations, refunds, expirations, or billing issues. Heimvard supplies RevenueCat's reserved $firebaseAppInstanceId subscriber attribute only while analytics consent is active and removes it after withdrawal.
Crash and error reports collected through Sentry can be disabled at any time in Settings → Crash and error reports (see §9).
The version date in the page header is the source of truth. The Privacy Policy is a notice, not an agreement. We may announce material privacy changes through a dismissible in-app or website notice, but a Privacy-only update does not block access. If the Terms change materially, the app may require acceptance of the updated Terms under Terms §12.
For any data-related requests — including account deletion, data export, or general questions about your privacy — contact us at heimvard-privacy@krakn.no.