Privacy policy
This policy explains how VEHI Digital UG (haftungsbeschränkt) processes personal data when you use the HeyOlaf website and application.
Last updated: 29 September 2026
Controller
VEHI Digital UG (haftungsbeschränkt)
Am Pichelssee 58
13595 Berlin
Germany
No data protection officer is appointed. Privacy questions go to: info@heyolaf.com
What this covers
HeyOlaf is a workspace for projects, tasks, documents, files, team chat, and the assistant Olaf. Olaf only proposes. The application writes a change after a person confirms it.
Data we process
Depending on what you use, we process account data, session data, workspace content, invitations, notifications, contact-form messages, billing data, prompts sent to Olaf, and — only with consent — usage and advertising data. If you connect Google Calendar or Outlook, we also store the titles and times of the calendars you choose to show.
Legal bases
- Contract (Art. 6 (1) (b) GDPR): account, workspace, invitations, support, and Olaf when you use the assistant.
- Legal duty (Art. 6 (1) (c) GDPR): keeping invoices and accounting records.
- Legitimate interest (Art. 6 (1) (f) GDPR): secure operation, abuse prevention, and the session list. You can object where your particular situation outweighs that interest.
- Consent (Art. 6 (1) (a) GDPR and § 25 TDDDG): statistics, marketing cookies, and product email. You can withdraw consent at any time with effect for the future.
Account and session
An account needs a name and email address. With email and password we store the password only as a hash. If Google or Microsoft is offered on the sign-in page, you can create the account that way. We then take the name and email from the provider and do not receive its password. For a password account, the email must be verified before a workspace can be used. The session cookie better-auth.session_token lasts up to seven days. With the session we store IP address and browser so you can see active sessions in settings. Language is kept in the NEXT_LOCALE cookie for the browser session and, once you are signed in, on your profile.
Workspace content
Projects, tasks, comments, chat, documents, and files are visible to people who can open that workspace. We keep an audit log of administrative organization actions. Files are private. Downloads use short-lived signed links. You can create a personal calendar link. Anyone with the link can read those events. You can rotate the link in settings. Content in a shared workspace stays with the organization after you delete your account. We delete the profile and the membership.
Hosting and storage
When you open HeyOlaf, the host processes the data needed to serve the page: IP address, date and time, requested address, browser, and sometimes the previous page. The application, PostgreSQL database, and private file storage run at Hetzner Online GmbH in the EU, on the server in Nuremberg. Optional statistics and marketing scripts load only after you opt in. The domain is resolved through Vercel DNS. Vercel does not serve the application.
Email and contact
Verification, password reset, invitations, notifications, and contact requests are sent by Postmark (ActiveCampaign, LLC, USA). The contact form sends name, email, an optional company name, and the message. The legal basis is the contract or our interest in answering the request.
Product email
Product updates are sent only after a separate double opt-in. The confirmation link is valid for 48 hours. This consent is independent of the account. You can withdraw it from the unsubscribe link or by emailing us.
Payment
Personal subscriptions are billed to the account. Team subscriptions are billed to the organization. Stripe processes the payment. We do not store full card numbers. Included Olaf credits reset monthly. Purchased credit packs remain until they are used.
Assistant Olaf
Olaf is optional. A request leaves HeyOlaf only when someone uses the assistant in a workspace that person is allowed to open. The server assembles context from that access: names, projects, tasks, comments, and document text. If a calendar is connected, that request can include those event titles and times. The recipient is the IONOS AI Model Hub of IONOS SE in Germany, Berlin region. That call does not go to OpenAI. Olaf proposes. The application writes nothing until a person confirms.
Connected calendars
Connecting Google Calendar or Outlook is optional. HeyOlaf only reads the calendars you select. Refresh tokens are stored encrypted. We keep event titles and times, not descriptions, attendees, or meeting links. The same titles and times can be included when you ask Olaf a question, and then go to IONOS in Germany. Disconnecting a calendar deletes that account and its cached events. Deleting your HeyOlaf account does the same.
Cookies
Necessary cookies are always on. Statistics and marketing stay off in the European Economic Area, the United Kingdom, Switzerland, and when the country is unknown, until you allow them. In a recognized country outside those regions they may run without a notice until you change the choice. The choice is stored for 180 days in the heyolaf_consent cookie. You can change or withdraw it at any time from Cookie settings, in the site footer, and in account settings.
Theme (light, dark, or system) is stored in the browser’s local storage under the key theme, and on your profile. It is not a cookie.
heyolaf_consent
Stores your statistics and marketing choice. 180 days. Necessary.
better-auth.session_token
Keeps you signed in. 7 days. Necessary.
NEXT_LOCALE
Remembers the website language. Browser session. Necessary.
_ga
Distinguishes visitors for Google Analytics. 2 years. Statistics.
_ga_*
Keeps Google Analytics 4 session state. 2 years. Statistics.
_gcl_au
Measures ad clicks for Google Ads. 3 months. Marketing.
_fbp
Recognizes the browser for the Meta pixel. 3 months. Marketing.
Google Tag Manager and Google Analytics
Google Analytics 4 measures how HeyOlaf is used: pages, approximate region, device, browser, and interactions. Google Tag Manager loads that measurement and can fire further tags. The container loads, but Consent Mode is denied first. analytics_storage is granted only after statistics consent. The legal basis is consent.
Google Ads and Meta
Google Ads and the Meta pixel measure advertising. They may set cookies and build an ad profile only after marketing consent sets ad_storage, ad_user_data, and ad_personalization to granted. Without Google Tag Manager, the Meta pixel loads only after that consent. With Google Tag Manager, the container receives the pixel ID and may fire Meta only with the same consent.
Google Search Console
We confirm site ownership with a meta tag for Google Search Console. The tag sets no cookie and sends no visitor profile. Google may still fetch public pages as a search engine.
Recipients
Data goes to these parties when the step needs them. The links open their own notices.
Application hosting, PostgreSQL, and private object storage in the EU.
Postmark (ActiveCampaign, LLC), USA
Sends transactional and product email.
Stripe Payments Europe Ltd., Ireland, and Stripe, Inc., USA
Payments, invoices, and the customer portal for Personal, Team, storage, and Olaf credit packs.
Olaf replies, only when someone uses the assistant.
Google Ireland Limited, Ireland, and Google LLC, USA
Sign-in with Google when you choose it. Also Tag Manager, Analytics, Ads, and Search Console verification. If you connect Google Calendar, HeyOlaf also reads the calendars you select.
Sign-in with Microsoft when you choose it. HeyOlaf reads Outlook calendars only after you connect an account.
Meta Platforms Ireland Limited, Ireland
Advertising pixel, only after marketing consent.
Countries outside the EU
IONOS and Hetzner process data in the EU. Postmark, parts of Stripe, Google, Microsoft, and Meta may process data in the United States. That relies on the European Commission’s standard contractual clauses. Where a provider is certified under the EU-US Data Privacy Framework, we also rely on that certification. You can ask for a copy of the safeguards at the privacy address.
Retention
We keep account data until you delete the account or the contract ends. Sessions end after seven days at the latest, or when you sign out. Team content stays while the organization keeps it. Product-email confirmation links expire after 48 hours. The cookie choice lasts 180 days. We keep invoices for the statutory period, usually ten years. Server logs are deleted once they are no longer needed for operation and security. Olaf threads live in the workspace and are deleted with it.
Your rights
You can request access, correction, deletion, restriction, and portability, and you can object to processing based on legitimate interest. You can withdraw consent with effect for the future. In settings you can export a copy of your account data and delete the account. If you are the only owner of an organization that still has other members, ownership has to be transferred first.
Complaint
You can lodge a complaint with a supervisory authority. Ours is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59-61, 10555 Berlin, Germany. datenschutz-berlin.de
Required data
Email and password are required to create an account. Statistics, marketing, and product email are optional. HeyOlaf works without them.
Automated decisions
There is no solely automated decision that produces a legal effect or similarly significant impact. Olaf proposes. A person decides.