Heimrunde

Privacy policy

This is a translation for convenience. The German Datenschutzerklärung is authoritative.

This privacy policy applies to the Heimrunde app in the browser, as an installed web app and as an Android app, and to this website. It explains which personal data we process, for what purpose, on which legal basis, and which rights you have.

In short: Heimrunde processes your data only to provide the app for your household. We show no advertising, use no tracking or analytics tools and sell no data.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Bochmann Software GmbH
Am Sennehügel 49
32052 Herford
Deutschland
E-mail: [email protected]
Phone: +49 5221 9930216

You can contact us at these details at any time with questions about data protection and to exercise your rights.

2. Hosting, Cloudflare and server logs

Heimrunde runs on our own server in Germany. The data of your account and your household is stored there.

The connection between your device and our server runs through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare encrypts the connection, protects against attacks and forwards requests to our server. In doing so, Cloudflare processes technical connection data such as your IP address, the requested address, the time and the browser identifier as our processor. Cloudflare may also process data in the USA, based on Cloudflare's certification under the EU-US Data Privacy Framework and the European Commission's standard contractual clauses. The legal basis is our legitimate interest in secure and fast delivery (Art. 6(1)(f) GDPR).

When you open the app or this website, our server logs technically necessary data: IP address, date and time, requested address, status code, amount of data transferred and browser identifier. We use these logs only to keep the service running, find errors and fend off abuse. The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). The logs are deleted after 30 days at the latest unless they are needed longer to investigate a specific security incident.

3. Your account

You need an account to use Heimrunde. For it we process your e-mail address, your display name, your password (only as a secure, irreversible hash), the connected sign-in methods, your sign-in sessions, a second sign-in factor if you set one up, and your settings such as language, appearance and notification preferences.

The purpose is providing the app, secure sign-in and assigning you to your household. The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR). To protect against password guessing we count and limit failed sign-in attempts (Art. 6(1)(f) GDPR).

4. Sign in with Google

Instead of a password you can sign in with your Google account. We then redirect you to Google; the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. After you consent at Google, we receive through the scopes “openid”, “email” and “profile” only:

We use this data only to create or find your Heimrunde account, sign you in and show your account by name in your household. We receive no Google password and no access to any other data of your Google account such as e-mails, contacts, files or calendars. The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR). You can disconnect Google in Heimrunde under Settings › Account while you have another sign-in method, or revoke access in your Google account at myaccount.google.com/permissions. Google's processing is governed by Google's privacy policy.

Heimrunde's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google APIs is not used for advertising, not sold, not used to train AI models and only shared where necessary for the visible feature or required by law. Humans read it only with your explicit consent, to fend off abuse or where the law requires it.

5. Your household's content

In Heimrunde you and the other members of your household enter content, for example shopping lists and purchases, staples, dishes, recipes and meal plans, appointments, activities and routines, household chores with rooms and floor plans, visits of a domestic help with feedback, and the people of the household with birthdays. We also store who created or changed something and when, so the household can follow changes.

Only the members of your household see this content, within their role. We process it to provide the app: store it, sync it across your devices, plan, remind and make suggestions, such as for purchases that come up regularly. Such suggestions are derived from your own household's entries and are not shared with other households. The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR).

If you enter data about other people, such as children, relatives or a domestic help, please make sure you are entitled to do so.

6. Photos and pictures

You can upload photos, for example of dishes, floor plans or as feedback on a visit, and share photos or links to Heimrunde. On upload we remove embedded metadata such as location and camera data. Pictures are stored assigned to the household and delivered to signed-in members only through time-limited signed links. The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR).

7. Voice input and AI features (OpenAI)

Some features use AI models from OpenAI (OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland, and OpenAI, L.L.C., San Francisco, USA). OpenAI processes this data as our processor. The features are optional; data is transferred only when you trigger the feature:

You can switch AI processing off. Whoever manages the household switches the AI features off in the settings for the whole household, for single features or for single members, for example children. Every person can choose “Do not send my input to AI” in the settings; this applies in all of their households. While AI is switched off, Heimrunde sends no data to OpenAI: Heimrunde reads entries itself, voice input is not available, and recipes can only be taken from links to pages that declare their recipe data themselves. The plan is not affected.

OpenAI also processes this data in the USA. Transfers are based on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) in the data processing agreement with OpenAI and, where certified, the EU-US Data Privacy Framework. Under OpenAI's terms, data sent through the API is not used to train models and is deleted after 30 days at the latest unless there is a legal obligation to retain it longer. The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR), because you use the feature explicitly. Please do not enter particularly sensitive data, such as health data, into these features if you do not want it transferred.

8. Import and calendar connections

For the one-time move from Microsoft To Do you sign in with Microsoft (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). Heimrunde then reads your task lists so you can take over the entries you want. Alternatively you can paste lists as text. The legal basis is Art. 6(1)(b) GDPR.

Heimrunde will offer an optional connection to Google Calendar in the future. Only if you set it up explicitly does Heimrunde read and write the events of the calendars you choose, to sync them with the Heimrunde calendar. The Limited Use commitment described above applies to this data as well. You can disconnect at any time; synced calendar data that is then no longer needed is deleted.

9. Notifications

Heimrunde shows notifications in the app. If you allow push notifications, we store the push address your browser creates, with its keys. Notifications are delivered encrypted through the push service of your browser or operating system (for example Google Firebase Cloud Messaging, Mozilla or Apple). Where e-mail notifications are set up and chosen by you, we send them to your e-mail address. You decide in the settings which notifications you receive through which channel; you can revoke the push permission in your browser or device at any time. The legal basis is Art. 6(1)(b) GDPR.

10. Cookies and storage on your device

Heimrunde uses only technically necessary cookies:

The app also stores in your browser's storage your language and appearance, the program files for a fast start and use without a connection (service worker), recently loaded content, and changes made without a connection until they are sent. This storage is strictly necessary for the service you requested (§ 25(2) no. 2 TDDDG); the subsequent processing is based on Art. 6(1)(b) GDPR. We use no cookies or similar techniques for advertising, tracking or audience measurement. You can clear this storage in your browser at any time.

11. Fonts

We serve the fonts Heimrunde uses for display from our own server. Loading them transfers no data to third parties, including Google. The font files are cached on your device so the app looks the same without a connection.

12. Android app

The Android app opens Heimrunde in a full-screen view of Chrome (Trusted Web Activity). The same processing as in the browser applies; the app itself reads no further data from your device. To point out new versions, it asks our server for the current version number. If you install the app from an app store, that store's terms apply in addition.

13. Recipients and transfers to third countries

We pass on personal data only as far as necessary for the purposes described, namely to:

We have agreements under Art. 28 GDPR with our processors. Where data is transferred to countries outside the European Union, in particular the USA, this is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework for certified recipients or on the European Commission's standard contractual clauses (Art. 45, 46 GDPR).

14. Retention and deletion

Statutory retention obligations remain unaffected. How to delete your account is described on the page Delete account.

15. Your rights

Under the GDPR you have the right to

Right to object: where we process data based on our legitimate interest (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation (Art. 21 GDPR).

Please use the contact details in section 1. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.

16. Further information

Provision of data: without an e-mail address or Google sign-in no account can be created and Heimrunde cannot be used. The AI features, notifications and connections are optional.

No automated decisions: we make no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). You can always accept, change or dismiss the app's suggestions.

Children: children under 16 use Heimrunde in their parents' household and with their consent. The parents decide which data about their children is entered.

Security: all connections are encrypted. We store passwords only as a hash, deliver pictures only through signed links, and every access to household data is checked on the server against the member's role.

Changes: we update this privacy policy when the app or the legal situation changes. The version published here applies.

Last updated: September 2026