Privacy policy
Effective from 10 August 2026
In short — also for children
Hjerterum remembers what the family enters and does in the app so tasks, habits, hearts and rewards work. We do not sell family information, show advertising to children or use information to assess a child without human involvement.
A parent creates the family and the child’s profile. Parents can view and manage information about the family’s children. A child can see the information and history made available by the app’s access rules.
Do not enter information about health, religion, politics or other sensitive and highly private matters in tasks, habits or notes. Hjerterum is not intended to store this type of information.
1. Who is responsible for the information?
The company stated at the top of this page is the data controller for Hjerterum’s processing of personal data. Questions and data protection requests can be sent to the stated privacy email.
Parents decide which names, tasks, habits and rewards they create. Hjerterum supplies the technical service and is responsible for processing information as described here.
2. What information do we process?
Account and family
We process name, optional username, optional child email, hashed password, family connection, parent or child role, optional family title, profile colour and timestamps for creation and changes.
Tasks, hearts and rewards
We process task titles and descriptions, dates, recurrences, assignments, who takes or helps with a task, status and approval. We also store heart history, reasons for manual awards, rewards, redemptions, shared goals and donations.
Positive habits and optional notes
We process created habits, selected weekdays, goals, recorded time, approvals, streaks and bonuses. If a family activates a positive note or journal, we store the text written by the child or parent and whether it was marked as shared.
Brain Break
We process the session date and duration, selected games, scores, level, correct answers and earned hearts. This data displays the child’s own progress and powers the feature — it is not used for psychological assessment or profiling.
Messages and push
We process notifications, read status and selected settings. If a user activates push, we also process a technical push address and encryption keys for the selected device or browser.
Technical information
The server may process IP address, time, browser or device type, session ID, necessary cookies and technical error and security logs for login, operations, troubleshooting and protection against misuse. When a visitor creates a family or uses the public contact form, we send name, email, IP address and limited browser information to CleanTalk to detect spam. Contact form submissions also include the subject and message. Internal family information and content after login are not sent to CleanTalk.
Payment and customer service
When payment is enabled, we process subscription selection, member count, price, payment status, invoice details and necessary accounting history. Vipps MobilePay handles payment, including relevant one-time and recurring payment solutions. Full card details are processed by the payment provider and are not stored in Hjerterum’s database. We also process information a customer sends in connection with support or a rights request.
3. Information about children
Hjerterum is designed for families, but a subscription is entered into by an adult. A parent creates and manages the child’s profile. We do not ask for a child’s Danish civil registration number, date of birth, address, photo, school, precise location or health information.
Hjerterum must process the child’s profile and activity data to show tasks, history, habits and hearts. Parents can create a child with a username and no email, and may use a nickname rather than the child’s full name. Parent profiles still require an email address.
4. Purposes and legal basis
We process account, family and activity data to supply Hjerterum Family and perform the agreement with the paying parent under GDPR Article 6(1)(b).
Necessary technical log and security information is processed for stable operation, misuse prevention and incident documentation based on our legitimate interest in a secure service under Article 6(1)(f).
Information required for accounts and payment documentation is retained to comply with legal obligations under Article 6(1)(c).
Push messages are activated only after the user’s active choice and browser permission. Permission can be withdrawn in the browser and Hjerterum settings.
5. Where does the information come from?
Information comes from the parent who creates the family, from family members’ use of the app and automatically from the device and browser used. We do not purchase personal data about families from others.
6. Who can see the information?
Content is generally only available to the relevant family under the app’s access rules. Parents can manage members and see relevant child history. Children cannot see siblings’ or parents’ private tasks and can only see their own personal history.
Authorised system administrators and technical suppliers may receive limited access where necessary for operations, security, support or troubleshooting. Public counters only show aggregated system-wide numbers and cannot identify a family or person.
7. Processors and transfers
We use suppliers for hosting, databases, backup and technical operations. CleanTalk is a processor for spam checks on public registration and the contact form and is configured for EU data storage and the shortest practical log retention. Payment and email providers may also be used. Push messages are delivered through the service used by the browser or device, for example Apple, Google or Mozilla.
Processor agreements are entered into when a supplier processes personal data on our behalf. Transfers outside the EU/EEA must use a valid basis, for example the European Commission’s standard contractual clauses and necessary supplementary safeguards. Selected suppliers and locations are shown at the top of this page when confirmed.
8. Retention and deletion
Account and activity data is retained while the family subscription is active and afterwards only as long as required for closure, security, documentation or law. A parent can download a combined account export and permanently delete the whole family in the app. The family can also clear selected categories such as tasks, habit activity, Brain Break, hearts, rewards, goals and notifications.
Following a valid full-deletion request, information that is no longer required is deleted or anonymised. Payment and accounting information may be retained for the period required by accounting law. Technical logs and backups are deleted after the periods stated at the top of this page.
9. Security
We use encrypted connections, access controls between families, password hashing, role-based permissions, backups and limited administrative access. No internet service can guarantee complete security, but we continually work to prevent unauthorised access, loss and misuse.
10. Cookies and local storage
Hjerterum uses necessary cookies and local storage for login, security, selected features and PWA installation. When logged in, the app may store a limited read-only offline copy with the user’s name and balance and visible tasks and habit plans for the current and following week. The normal read copy does not contain notes or passwords. If a habit is completed offline, recorded time and an optional note may temporarily remain in a local outbox until synchronised, after which it is removed. The copy is used only on the device, deleted on normal logout and can also be removed from the offline page. Optional statistics and marketing technologies are only enabled after consent.
11. Automated decisions
Hjerterum does not make decisions with legal or similarly significant effects based solely on automated processing. Points, streaks, budgets and leaderboards are calculated from rules chosen by the family and are only app features.
12. Your rights
Depending on the circumstances, a data subject has rights of access, rectification, erasure, restriction, portability and objection. Consent can be withdrawn without affecting previous lawful processing. Parents can generally exercise their child’s rights where this is in the child’s interests; the child’s age and maturity must also be respected.
Send requests to the privacy email above. We may ask for information needed to ensure data is not disclosed to the wrong person. We respond without undue delay and normally within one month.
13. Complaints
Please contact us first so we can try to resolve the matter. You also have the right to complain to the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, through datatilsynet.dk.
14. Changes
This policy is updated when the service, suppliers or rules change. Material changes are communicated clearly to active customers before taking effect where required.
Visitor statistics with Google Analytics
When a visitor actively accepts statistics cookies, we use Google Analytics 4 on Hjerterum’s public pages. We process visited public pages, traffic source, time, browser and device type, approximate geographic area and random cookie identifiers to understand traffic and improve the website. The legal basis is consent under GDPR Article 6(1)(a).
Google Ireland Limited provides Analytics. Google may use affiliated subprocessors and process data outside the EU/EEA using the transfer mechanisms it states for the service. Retention follows Hjerterum’s account settings and is limited to what is needed for statistics.
We do not send Hjerterum user IDs, names, emails, family information, tasks, notes or other logged-in content to Analytics. Google Signals and personalised advertising are disabled in the tag configuration. Consent can be withdrawn through Cookie settings.
Anonymous usage statistics in the PWA and browser
After an active statistics choice, Hjerterum may process limited usage information from the logged-in PWA on our own server. Measuring child profiles requires separate activation by a parent. The purpose is product improvement and capacity planning: we measure active time, foreground time, installed PWA or browser and broad feature areas.
We do not store the user’s name, email, family ID, task text, reward names, notes, messages or other content in usage statistics. A random session number is converted server-side to a technical key. Families and associations are counted with a one-way key used briefly to avoid double counting. Statistics are not used for marketing, profiling, leaderboards, automated decisions or assessment of an individual child or member.
Short session measurements are deleted after no more than 30 days and technical account keys after no more than 95 days. Aggregated daily, monthly and annual totals may be retained long-term so Hjerterum’s development can be followed over time. These totals cannot identify a user or family.
Google Analytics remains limited to public pages after consent. Information from the logged-in PWA is not sent to Google Analytics.
For product improvement, we may also count broad technical event types such as offline use, synchronisation errors, restored synchronisation and slow or failed actions. Error text and action content are not stored. Short-lived one-way keys may be used for aggregated measurements of feature adoption and retention after 7, 30 and 90 days; only an aggregated count is retained afterwards.