Privacy Policy of the Heijo App
This Privacy Policy applies exclusively to the Heijo app (iOS/macOS). The website heijo.app (information pages and waiting list) is covered by its own separate privacy policy.
Version date: 13 August 2026 · Version: 1.1 (the consent given in the app is tied to this version and is logged with a version stamp and a timestamp)
Language note. This English text is a translation of the German original, provided for your convenience. The legally binding version is the German one, available at https://heijo.app/app/datenschutz. In the event of any discrepancy, the German version prevails.
Contents
- What Heijo is, and what Heijo is not
- Controller and contact
- Data protection officer
- The essentials at a glance
- Categories of data processed
- Purposes of processing and legal bases
- Special categories of personal data (health data): Coach chat, Journal & Mirror
- Consent: explicit, granular, freely given, revocable
- Recipients and processors
- Transfers of data to the USA (third-country transfers)
- Artificial intelligence, automated processing and profiling
- Storage location and retention periods
- Data security (technical and organisational measures)
- Protection of minors (minimum age 18)
- Your rights as a data subject
- Withdrawal of consent
- Right to lodge a complaint with a supervisory authority
- Crisis and emergency notice
- Changes to this Privacy Policy
1. What Heijo is, and what Heijo is not
Heijo is a digital assistant for personal development and self-reflection. Heijo helps you structure tasks, plan your day, get to know yourself better, and reflect through a journal and guided sessions.
Heijo is not a medical device. Heijo makes no diagnoses, provides no treatment or therapy, and is no substitute for medical, psychotherapeutic or psychological care. The artificial intelligence (AI) used in Heijo makes no clinical findings.
Heijo is an AI application. The counterpart you talk to in the app is an artificial intelligence, not a human being. You are informed of this at your very first contact inside the app (see Art. 50 of the AI Act).
2. Controller and contact
The controller within the meaning of the General Data Protection Regulation (GDPR) for the data processing in the Heijo app is:
Marco Marius Reczuch
Sole proprietor
Alex-Wedding-Straße 3
10178 Berlin
Germany
Email: hello@heijo.app
Please also send data protection enquiries to hello@heijo.app (there is no separate data protection address; every enquiry reaches the controller directly).
3. Data protection officer
A data protection officer has not been appointed at present. The statutory appointment duties do not apply to the controller at its current size: no 20 people are permanently engaged in data processing (Sec. 38(1) of the German Federal Data Protection Act, BDSG), and large-scale processing of special categories of data within the meaning of Art. 37(1)(c) GDPR does not take place in the current, narrowly limited test operation. We keep reviewing the appointment duty on an ongoing basis, in particular before any broad public release of the app; as soon as it applies, an external data protection officer will be appointed and named here.
Until then, please send data protection enquiries directly to the controller: hello@heijo.app.
4. The essentials at a glance
- What you write to the AI (Coach chat, Journal, Mirror) can contain health data. We process this AI content only with your explicit consent, which you can withdraw at any time (Art. 9(2)(a) GDPR).
- Tasks, planning and your account can be used without this consent. The AI features (Coach chat, Journal, Mirror) require it, because your content is processed in the course of them. The consent is not a precondition for using the app at all (no bundling).
- The "memory" you build up stays with you. The knowledge layer processed and condensed by the AI (facts, patterns, your personal "dossier") is stored locally on your device and backed up to your private iCloud, not on our servers.
- AI processing takes place in the EU by default, with one exception: text vectorisation (USA). The AI responses are generated in the EU by default (Cortecs GmbH, Vienna; model operation by Tensorix Ltd, Ireland). The only content transferred to the USA by default is content sent for text vectorisation (Voyage AI). In the event of major disruptions or outages at the EU service providers, we may temporarily switch response generation over to Anthropic (USA) by hand, in order to keep the app available. Sections 9 and 10 give the details.
- You have comprehensive rights: access, rectification, erasure, withdrawal of consent and complaint. Sections 15 to 17 give the details.
5. Categories of data processed
Depending on how you use the app, we process the following categories of personal data:
| Category | Examples | Relevant to Art. 9? |
|---|---|---|
| Account and authentication data | email address, password (encrypted/hashed at the authentication provider), sign-in status | no |
| Profile data | display name, optionally date of birth, weekly schedule/fixed appointments, areas of life | no (ordinary personal data, not a special category) |
| Task and goal data | tasks, notes, sub-steps, appointments, goals, planning data | as a rule no (may be sensitive depending on the content) |
| Chat content (Coach) | your messages to the Coach and its replies | yes: treated as health data (Art. 9 GDPR), since they can regularly contain information about your mental/emotional state |
| Journal and Mirror content | journal entries, guided reflection sessions, the "Mirror" | yes: health data (Art. 9 GDPR) about your mental/emotional condition |
| AI-derived insights | behavioural patterns formed by the AI, "facts" about you, the condensed "dossier", the coach knowledge map | close to Art. 9: may allow conclusions about your health/mental state and is treated like Art. 9 data |
| Technical usage and log data | timestamps, technical processing metadata (for example token counters of the AI calls), server-side pipeline status logs | no |
| Usage statistics (only with your consent) | event name (from a fixed, defined list, for example "task created"), counts, app version, time rounded to 15 minutes. Structurally free of content: what you write (chat, journal, task texts) cannot technically appear in it | no |
| Crash and stability reports | technical error report when the app crashes or freezes: stack trace, error type, device/OS details. No content, no user identifier (no chat, journal or task text, no screenshots, no interaction traces) | no |
Usage statistics and crash reports never contain content data. Usage statistics are off by default and are only collected with your consent (can be switched off in the settings). Crash reports serve solely to keep the app stable (details in Section 6.7).
6. Purposes of processing and legal bases
6.1 Account, authentication and provision of the app
- Purpose: registration, sign-in, provision and protection of the core features (account, tasks, planning, Coach chat).
- Legal basis: Art. 6(1)(b) GDPR (performance of the user contract) and, in addition, Art. 6(1)(f) GDPR (legitimate interest in secure, functioning operation).
6.2 Tasks, goals, planning and Coach chat
- Purpose: structuring tasks and goals, daily and weekly planning, answering your messages through the AI Coach, ongoing personalisation of the support.
- Legal basis: for structuring tasks/goals and for daily/weekly planning, Art. 6(1)(b) GDPR (performance of the user contract). Answering your messages through the AI Coach, however, processes freely entered content which can regularly contain information about your mental/emotional state; this AI processing therefore takes place, like the Journal and the Mirror, on the basis of your explicit consent under Art. 9(2)(a) GDPR (see Sections 7 and 8). Tasks and planning can be used without this consent.
6.3 Journal, guided sessions and Mirror (health data)
- Purpose: enabling self-reflection, journaling, guided reflection sessions and the summarising "Mirror" feature.
- Legal basis: Art. 9(2)(a) GDPR (your explicit consent) in conjunction with Art. 6(1)(a) GDPR. See Sections 7 and 8.
6.4 Forming AI insights (patterns, facts, dossier)
- Purpose: so that Heijo understands you better over time, the AI forms condensed insights from your input (behavioural patterns, "facts", a personal "dossier", a coach knowledge map) and uses them for personalisation.
- Legal basis: insofar as these insights are derived from health data (Journal/Mirror) or contain such data, Art. 9(2)(a) GDPR (explicit consent); otherwise Art. 6(1)(b) and (f) GDPR. See also Section 11.
6.5 AI service providers: standard EU operation and US service providers
- Purpose: generating the AI responses and converting texts into numerical representations (embeddings) for the memory and similarity features.
- Standard operation (EU): the AI responses are generated by our processor Cortecs GmbH (Vienna, Austria). The language model used (DeepSeek V4 Flash; in the event of disruptions, automatically its sibling model DeepSeek V4 Pro over the same EU route) runs on servers of the sub-processor Tensorix Ltd (Ireland). Your content is processed there exclusively in volatile memory and is not stored after processing (zero retention) and not used for training. "DeepSeek" here refers to the freely available AI model; it is operated in the EU by default, and no data is transferred to the Chinese company of the same name. To guard against outages, Cortecs may temporarily divert the processing to another provider from its published provider network; these providers are established in the EU or the USA (for US providers, the EU-US Data Privacy Framework applies, Section 10). Our account is limited to providers that do not store transferred content after processing (zero data retention).
- Fallback operation (USA): in the event of major disruptions or outages at the EU service providers, we may temporarily switch response generation over to Anthropic (USA) by hand, in order to keep the app available. No automatic switch to a third country takes place.
- Text vectorisation (USA): the conversion of text excerpts into embeddings is carried out by Voyage AI (USA).
- Legal basis: the AI processing of your content (Coach chat, Journal, Mirror) takes place on the basis of your explicit consent under Art. 9(2)(a) GDPR. The US transfers (Voyage AI; Anthropic in fallback operation) are safeguarded by the EU-US Data Privacy Framework or by EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) in conjunction with the data processing agreements (see Section 10); we inform you about these transfers and about the residual risk that remains. We do not obtain separate consent to the third-country transfer under Art. 49.
6.6 Security, error analysis and prevention of misuse
- Purpose: stability, troubleshooting, protection against misuse and overload (for example technical usage limits).
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).
6.7 Usage statistics and crash reports
- Purpose: understanding which features are used and where the app crashes or freezes, in order to improve it and keep it stable.
- Usage statistics: only with your consent (Art. 6(1)(a) GDPR), off by default, can be switched off in the settings at any time. Only predefined event names and counts are recorded, never content.
- Crash/stability reports: on the basis of our legitimate interest in a functioning app (Art. 6(1)(f) GDPR). The reports are structurally free of content (no text you have written, no screenshots, no interaction traces, no user identifier) and are processed in the EU region of the service provider Sentry (see Sections 9 and 10).
6.8 Backup to your private iCloud
- Purpose: protecting the memory layer you have built up against device loss or a change of device.
- Legal basis: insofar as the memory layer contains content that is treated as health data, the backup forms part of the AI processing covered by your explicit consent (Art. 9(2)(a) GDPR); otherwise Art. 6(1)(b) or (f) GDPR. The backup is made to your own private iCloud (Apple account); in this respect, as we understand it, Apple does not act as a processor for Heijo, but as the provider of your personal cloud storage (see Section 12).
6.9 Automated safety/crisis detection
- Purpose: for your safety, an automated system checks incoming messages (Coach chat, Journal, guided sessions) for indications of an acute crisis (for example thoughts of harming yourself or others). The process runs in two stages (a keyword detection and a brief AI assessment). If the system detects a possible acute crisis, Heijo shows you pointers to professional sources of help instead of the normal reply (see Section 18).
- Legal basis: this check is part of the AI processing of your content to which you have explicitly consented (Art. 9(2)(a) GDPR), and it serves your protection. For the AI assessment, the content in question is transferred to our standard AI service provider in the EU (in fallback operation to Anthropic, USA, see Sections 6.5 and 10).
- Limits: the detection is technically limited and not reliable; it is not an emergency, crisis or rescue service and is no substitute for professional help. It does not constitute an automated decision with legal effect within the meaning of Art. 22 GDPR; we form no personality profile about you from the result and derive no clinical assessment from it.
7. Special categories of personal data (health data): Coach chat, Journal & Mirror
In the Coach chat, in the Journal, in the guided reflection sessions and in the "Mirror", content about your thoughts, feelings and mental condition can arise. Such content regularly constitutes health data within the meaning of Art. 9(1) GDPR (data concerning mental/emotional health).
The insights derived by the AI (behavioural patterns, "facts", "dossier") can also allow conclusions about your health. We therefore treat them with the same level of protection as health data.
We process this data exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), a consent that covers the entire AI processing (Coach chat, Journal, Mirror). If you do not give it, or if you withdraw it, we process none of this AI content; the app remains usable as a task and planning app (see Sections 8 and 16). The Journal and the Mirror are a place for your own reflection, not an officially maintained health record.
8. Consent: explicit, granular, freely given, revocable
For the AI processing of your content (Coach chat, Journal, Mirror) and the associated transfer to service providers in the USA, we obtain your separate, explicit consent. This consent is designed to meet the requirements of the GDPR:
- Explicit and active: you give the consent through a clear affirmative action (for example an active tap). There is no pre-ticked box.
- Granular: the consent for the processing of health data is requested separately from any other permissions and is separate from the terms of use.
- Freely given and not bundled: the core app (tasks, planning, account) can be used without this consent. The AI features (Coach chat, Journal, Mirror) require it, but the consent is not a condition for using the app at all (Art. 7(4) GDPR). Its voluntary nature does not depend on the price, but on the fact that the core app remains fully usable without consent.
- Informed: before you give it, you are informed in clear language about the purpose, the categories of data, the recipients and the US transfer.
- Revocable at any time: you can withdraw the consent at any time with effect for the future, without affecting the lawfulness of the processing carried out up to that point (see Section 16).
- Documented: your consent is logged with a version stamp and a timestamp, so that it can be demonstrated (Art. 7(1) GDPR).
9. Recipients and processors
To provide the app's features, we use carefully selected service providers, with each of whom a data processing agreement under Art. 28 GDPR is in place (where they act as processors). Your data is not sold or disclosed for these service providers' own purposes.
| Recipient | Role | Location / region | Which data | Function |
|---|---|---|---|---|
| Supabase Pte. Ltd | processor | database/server region EU (Frankfurt, eu-central-1), verified 2026-07-02; company seat Singapore | raw chat messages, session snapshots, account/authentication data, usage statistics | database, authentication, server-side functions (edge functions) |
| Cortecs GmbH (Althanstraße 4, 1090 Vienna, Austria) | processor | EU: gateway in Austria; model operation by default at the sub-processor Tensorix Ltd (Ireland); fallback providers in the Cortecs network in the EU/USA (US providers: EU-US Data Privacy Framework) | conversation/content data transferred to the AI for response generation | AI language models (DeepSeek V4 Flash/Pro), standard operation; processing in volatile memory only, no storage after processing (zero data retention) |
| Anthropic (contracting party for EEA customers: Anthropic Ireland, Limited; processing: Anthropic, PBC) | processor (fallback operation) | USA | conversation/content data transferred to the AI for response generation | AI language model (Claude), only upon a manual switch when the EU route is disrupted |
| Voyage AI Innovations, Inc. (part of MongoDB, Inc.) | processor | USA | text excerpts for conversion into numerical representations (embeddings) | text vectorisation for the memory and similarity features |
| Functional Software, Inc. (Sentry) | processor | processing in the EU region (ingest `de.sentry.io`); company seat USA | content-free crash/stability reports (stack trace, error type, device/OS details) | crash reporting to keep the app stable |
| Apple | independent controller / "deemed supplier" for subscription sales | EU/worldwide (Apple group) | purchase/payment and Apple account data (collected by Apple, not by us) | app distribution and subscription payment; also the provider of your private iCloud (see Section 12) |
Note on Apple: for distribution via the App Store and for the handling of in-app subscriptions, Apple is an independent controller under data protection law (in particular for payment/purchase data). Apple's privacy policy applies in that respect. We have only limited or no direct access to the payment and account data collected in the App Store.
Note on the website: the hosting service provider Cloudflare is used exclusively for the website heijo.app and is separate from the app. The separate website privacy policy provides information on this.
10. Transfers of data to the USA (third-country transfers)
The generation of the AI responses takes place in the EU by default (Cortecs GmbH/Tensorix Ltd, Section 6.5) and is therefore not a third-country transfer. Processed in the USA are: text vectorisation (Voyage AI), in fallback operation the AI responses (Anthropic), and, in the event of disruptions, individual requests via US providers in the Cortecs network that are certified under the EU-US Data Privacy Framework (Section 6.5); the crash reporting service provider Sentry is a US company but processes the (content-free) reports in its EU region. Under data protection law, the USA is regarded as a third country without a general level of protection fully equivalent to that of the EU.
We safeguard these transfers as follows:
- Anthropic, PBC (USA, fallback operation only): a transfer to Anthropic takes place only if we temporarily switch response generation there by hand when the EU route is disrupted. It is based on the EU Standard Contractual Clauses (SCCs) contained in the data processing agreement with Anthropic, supplemented by a Transfer Impact Assessment (TIA) as well as appropriate technical and organisational safeguards. A certification of Anthropic under the EU-US Data Privacy Framework (DPF) is not confirmed (publicly documented are, among others, SOC 2 and ISO 27001). Anthropic deletes the transferred content automatically within 30 days and does not use it to train AI models; longer storage takes place only where legally required or where it serves the enforcement of Anthropic's usage policies. The SCCs apply in Module 2 (controller to processor); our Transfer Impact Assessment is dated 2 July 2026 (documented internally, reviewed annually).
- Voyage AI / Voyage AI Innovations, Inc. (USA, part of MongoDB): transfer on the basis of a self-certification under the EU-US Data Privacy Framework (DPF); in addition, the MongoDB data processing agreement with Standard Contractual Clauses serves as a safeguard (fallback).
- Functional Software, Inc. (Sentry, USA): the crash reports are stored and processed in Sentry's EU region; they are structurally free of content. Insofar as a third-country element nevertheless exists (US parent company), it is safeguarded by Sentry's DPF self-certification as well as by the Standard Contractual Clauses contained in the Sentry data processing agreement (fallback).
- Supabase Pte. Ltd (Singapore): the data itself is held in the EU region (Frankfurt); a group-related third-country element in relation to the company seat in Singapore is safeguarded by the Standard Contractual Clauses contained in the data processing agreement.
Notes on the risks (Schrems case law): despite the safeguards named above, there is a risk that US authorities may access data transferred to the USA under US law (for example FISA 702) without data subjects always having legal protection equivalent to that in the EU. An enforceable level of protection like the one inside the EU cannot therefore be guaranteed in every case.
The transfer of the health data (Coach chat, Journal, Mirror) to the USA is based on the appropriate safeguards named above under Art. 46 GDPR, namely the EU-US Data Privacy Framework (Voyage AI) or the EU Standard Contractual Clauses (Anthropic, fallback operation), in conjunction with the data processing agreements. We inform you about the risks associated with the US transfer before you give your consent to the AI processing; we do not obtain separate consent to the transfer itself (Art. 49). You can withdraw your consent to the AI processing at any time (Section 16).
11. Artificial intelligence, automated processing and profiling
Heijo processes your input with the help of artificial intelligence, in order to generate responses and to understand you better over time. In doing so, patterns are formed from your behaviour and your input and summarised in a condensed knowledge layer (facts, patterns, "dossier", coach knowledge map). This constitutes a form of profiling within the meaning of Art. 4(4) GDPR, since aspects of your person (for example habits, energy patterns, recurring obstacles) are evaluated in order to personalise the support.
No automated decision-making within the meaning of Art. 22 GDPR takes place that produces legal effects concerning you or similarly significantly affects you. In particular, Heijo makes no automated decisions about contracts, creditworthiness, employment, healthcare or the like. The AI makes suggestions and offers for reflection; the decisions are always yours.
Labelling of the AI: in the app you are informed from the outset that you are interacting with an artificial intelligence (Art. 50 of the AI Act).
No clinical assessment: the AI does not use clinical or diagnostic labels about you and makes no diagnoses.
Automated safety check: incoming messages are checked automatically for indications of an acute crisis, so that sources of help can be shown to you if needed (see Section 6.9). This is a protective function and not an automated decision within the meaning of Art. 22 GDPR.
12. Storage location and retention periods
12.1 Storage location
- On your device (locally): the memory layer processed and condensed by the AI (facts, patterns, "dossier", coach knowledge map) is stored primarily locally on your device.
- In your private iCloud: to protect it against device loss, this memory layer is backed up to your own private iCloud (account-bound, tied to your user identifier). This backup is held in your personal Apple storage, not on Heijo's servers. Access by other users is ruled out by the account-bound separation.
- On servers in the EU (Supabase): our processor's server (EU region) holds the account/authentication data for as long as your account exists. Raw chat messages and session snapshots are held there only temporarily, as a rolling processing window, and are deleted automatically after 35 days at the latest. Your complete conversation history lives on your device and in your private iCloud, not on our servers. Both are additionally stored there with content encryption at the application level (Section 13). The condensed memory layer is not stored there as a holding; the session snapshots may temporarily contain excerpts from it and are subject to the same deletion (Section 12.2).
- Temporarily at the AI service provider: in standard EU operation (Cortecs/Tensorix), your content is processed for each request exclusively in volatile memory and is not stored afterwards; Cortecs only stores technical processing metadata without content (for example billing data) for up to 12 months. Voyage AI (USA) processes the transferred text excerpts exclusively on our instructions in order to provide the embedding function (Art. 28 GDPR, MongoDB data processing agreement); no use for its own purposes takes place. In fallback operation, Anthropic (USA) deletes the transferred content automatically within 30 days and does not use it for AI training.
12.2 Retention periods
We store personal data only for as long as it is necessary for the respective purposes:
| Data category | Retention period |
|---|---|
| Account/authentication data | for as long as your user account exists; upon account deletion, immediate erasure, definitively including from the database service provider's technical backup copies once the backup window (7 days) has elapsed |
| Task/goal/profile data | until you delete the respective content, or until the account is deleted |
| Chat content (raw messages and session snapshots, Supabase EU) | rolling, no more than 35 days (processing window, automatic deletion); your complete history is held permanently only locally on your device and in your private iCloud |
| Journal/Mirror content and derived health insights | until the account is deleted, or until you delete it; after a withdrawal of consent, no further AI processing takes place and the storage is blocked (details in Section 16) |
| Local/iCloud memory layer | until you uninstall the app or delete the iCloud backup; this is under your own control and is removed together with the in-app account deletion |
| Consent logs (text version, timestamp, granted/withdrawn, without content) | logged server-side; retained for as long as your account exists and for 3 years thereafter as the legally required record (Art. 7(1) GDPR), that is, also beyond an account deletion |
| Usage statistics (opt-in) | until the account is deleted (covered by the deletion cascade) |
| Crash reports (Sentry, EU region, content-free) | up to 90 days (the service provider's standard retention) |
| Technical/security logs | short-term: server/function logs a few days; internal development audit logs 3 days (these concern exclusively the controller's developer/test accounts, no user accounts); pipeline status logs 30 days; AI usage metadata (token counters, without content) until the account is deleted |
Account deletion: you can delete your account directly in the app (Settings → Account). The deletion is carried out server-side as a cascade across all account-related data holdings (messages, session snapshots, usage statistics, technical logs, AI usage metadata and the account itself) and additionally removes the local memory layer on the device as well as the backup in your iCloud. The only exception is the content-free consent log (text version and timestamp of your consents and withdrawals), which we retain for a further 3 years after the account deletion as the legally required record. The completeness of the deletion cascade across all account-related tables was last reviewed on 2 July 2026. Content that was previously transferred temporarily to our service providers for AI processing is not held there as a permanent, account-related holding, but only processed transiently per request: in standard EU operation (Cortecs/Tensorix) it is deleted immediately after processing; at Voyage AI there is no storage for its own purposes; in fallback operation Anthropic deletes it automatically within 30 days. It therefore expires there automatically rather than being deleted separately. Likewise, short-term technical backup copies of our EU server may still contain deleted data until the short backup window has elapsed, before it ceases to exist definitively. Deletion on our own live systems, by contrast, takes place immediately.
13. Data security (technical and organisational measures)
We take appropriate technical and organisational measures to protect your data (Art. 32 GDPR), in particular:
- Transport encryption (TLS/HTTPS) for all connections between the app, the server and the service providers.
- Access separation per user account at server and iCloud level (account-bound isolation), so that data of different users is not mixed.
- Authentication through a specialised authentication service; passwords are not stored in plain text.
- Data minimisation: the particularly sensitive memory layer is held primarily locally and in your own iCloud storage and is not stored centrally on our servers.
- No content data in telemetry/logs: usage statistics and crash reports are structurally built so that content (chat, journal, task texts) cannot appear in them.
- Access restriction at database level: every account-related table is protected by row-level security policies (access only to your own rows); data at rest is stored encrypted at the database service provider.
- Content encryption at the application level: conversation content and session snapshots are additionally stored on our EU server encrypted with AES-256-GCM; the key is managed separately from the database. Administrative database tools and backup copies therefore contain only encrypted content. For the AI processing, content is briefly decrypted server-side for each request; the app is therefore not end-to-end encrypted.
- Reporting process for data breaches: personal data breaches are assessed in accordance with Art. 33/34 GDPR and, where necessary, reported to the competent supervisory authority within 72 hours.
14. Protection of minors (minimum age 18)
Heijo is aimed at adults (aged 18 and over). Persons under 18 may not use the app and may not transmit any personal data. The reason for the age limit of majority (instead of the Art. 8 GDPR threshold of 16 years) is the processing of health data (Art. 9 GDPR) in combination with the full legal capacity required for the user contract (Secs. 104 et seq. of the German Civil Code, BGB).
The minimum age is stated in the terms of use and on the consent screen; no further technical age verification currently takes place. Should we become aware that a person under 18 is using the app, we will delete the data concerned.
15. Your rights as a data subject
You have the following rights against the controller with regard to your personal data:
- Access to the data processed about you (Art. 15 GDPR),
- Rectification of inaccurate data (Art. 16 GDPR),
- Erasure of your data ("right to be forgotten", Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability, that is, receiving your data in a structured, commonly used, machine-readable format (Art. 20 GDPR),
- Objection to processing based on a legitimate interest, on grounds relating to your particular situation (Art. 21 GDPR),
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR, see Section 16),
- Complaint to a supervisory authority (Art. 77 GDPR, see Section 17).
Exercising your rights: an informal message to hello@heijo.app is sufficient. We answer enquiries without undue delay, and at the latest within one month of receipt (Art. 12(3) GDPR). For particularly extensive or complex enquiries, this period may be extended by up to two further months; we will inform you if that happens. Directly in the app you can: withdraw your consent (Settings → Privacy, see Section 16) and delete your account completely (Settings → Account, see Section 12.2). We provide a machine-readable data export on request to hello@heijo.app; an in-app export function is in preparation.
16. Withdrawal of consent
Insofar as processing is based on your consent, in particular the AI processing of your content (Coach chat, Journal, Mirror) and its transfer to the USA, you can withdraw this consent at any time with effect for the future.
- You can declare the withdrawal directly in the app: Settings → Privacy → switch off the "AI processing" toggle. Alternatively, an informal email to hello@heijo.app is sufficient. Withdrawing is just as easy as giving consent (Art. 7(3) GDPR).
- The withdrawal does not affect the lawfulness of the processing carried out up to the withdrawal.
- After a withdrawal we process no further AI content (Coach chat, Journal, Mirror); no new messages are transferred to the AI service providers. Content already created is blocked from further AI processing: the messages held on our server are not processed further by the AI and expire automatically via the normal 35-day processing window; your history and your local memory layer remain on your device, under your control. You can delete everything completely at any time via account deletion (Section 12.2) or an erasure request.
- The core app (tasks, planning, account) remains usable after a withdrawal, and you can give the consent again at any time.
17. Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Competent is the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement. The supervisory authority competent for the controller is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Alt-Moabit 59–61
10555 Berlin
Germany
Web: www.datenschutz-berlin.de
18. Crisis and emergency notice
Heijo is not an emergency service and is no substitute for professional help. If you are in an acute crisis or are thinking about harming yourself or others, please turn to professional help immediately:
- Emergency number: 112
- Telefonseelsorge: 0800 111 0 111 · 0800 111 0 222 · 116 123 (free of charge, around the clock)
19. Changes to this Privacy Policy
We adapt this Privacy Policy as soon as the data processing changes (for example with new features, new service providers or changed legal bases). The version published in the app or at https://heijo.app/app/datenschutz applies; the English translation of that version is published at https://heijo.app/app/privacy. Where changes are material and require consent, we obtain it again.
← Back to home