Privacy Policy
How Heivol handles your data across Heivol Messenger and Heivol Calendar. We collect as little as the service needs, we don't sell your data, and you can delete your account at any time.
Last updated: 3 June 2026
Who we are What we collect How we use it Legal basis Sharing Security Retention Your rights Deleting your account Contact
1. Who we are
Heivol ("we", "us") is the data controller for the Heivol Messenger and Heivol Calendar apps and the associated Heivol Identity sign-in service. Heivol is established in Denmark (CVR 43973932). You can reach us at [email protected].
This policy covers both apps. Where a practice applies to only one app, we
say so. Both apps sign you in through Heivol Identity
(id.heivol.com) — there is no separate per-app account.
2. What we collect
Account & identity
- A Heivol Identity account identifier and your display name and email address, provided when you sign in. We do not require a phone number.
- Authentication tokens needed to keep you signed in on your device.
Heivol Messenger
- The conversations you take part in, the messages you send and receive, and any media or files you attach.
- Group membership, contacts you add, and users you block.
- A device push token so we can notify you of new messages.
Heivol Calendar
- The calendars, events, and reminders you create, including their times, titles, and any notes or participants you add.
- A device push token so we can deliver event reminders.
- If you connect an external calendar, the event data needed to sync it.
Technical data
- Minimal server logs (e.g. timestamps and error diagnostics) needed to operate and secure the service. We minimise metadata by design.
We do not use advertising trackers, and we do not sell your personal data.
3. How we use your data
- To provide the service: deliver your messages, sync your calendar, and keep you signed in.
- To send the notifications you've enabled (new messages, event reminders).
- To keep accounts and content secure and to prevent abuse.
- To meet legal obligations where they apply.
4. Legal basis (GDPR)
For users in the EU/EEA, we process your data under the GDPR, principally on the basis of performance of our contract with you (providing the app you asked for) and our legitimate interest in keeping the service secure and reliable. Where we rely on consent (for example, push notifications), you can withdraw it at any time in your device settings.
5. Sharing & sub-processors
We share data only with the providers needed to run the service:
- Apple Push Notification service and Google Firebase Cloud Messaging — to deliver notifications to your device. Notification payloads are kept minimal.
- Heivol-operated infrastructure — your content is stored on servers operated by Heivol. We do not hand your content to third-party advertisers or data brokers.
We may disclose data where required by law, but we will resist over-broad requests.
6. Security & encryption
- All traffic between your device and Heivol is encrypted in transit (TLS).
- Content stored on our servers is protected by access controls and is isolated per account.
- Heivol Messenger is rolling out per-conversation end-to-end encryption; when a conversation is end-to-end encrypted, message contents are encrypted on your device and Heivol cannot read them. Where end-to-end encryption is not enabled, messages are encrypted in transit and at rest but are technically readable by the service to deliver them.
- Heivol Calendar lets you mark events as private, in which case the event body is encrypted on your device before it reaches our servers.
7. Data retention
We keep your data for as long as your account is active and you continue to use the apps. When you delete your account (see below), we erase your personal data and content, retaining only what we are legally required to keep or what has been irreversibly anonymised.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- erase your data ("right to be forgotten");
- receive a portable copy of your data;
- object to or restrict certain processing.
To exercise any of these, email [email protected]. You also have the right to lodge a complaint with your local supervisory authority (in Denmark, Datatilsynet).
9. Deleting your account
You can permanently delete your Heivol account from within the app (Settings → Delete account) or at id.heivol.com. Deleting your account removes your identity profile and your content across Heivol services — including your messages and conversations in Heivol Messenger and your events and reminders in Heivol Calendar. This action is permanent and cannot be undone.
10. Children
The Heivol apps are not directed to children under the age required to consent to online services in their country, and we do not knowingly collect their data.
11. Changes to this policy
We may update this policy as the service evolves. We will revise the "last updated" date above and, for material changes, notify you in-app or by email.
12. Contact
Questions about your privacy? Email [email protected]. For help using the apps, see our support page.