Hopp til innhold
HeatPump AI
Merker Søk
EN NO SV FI
Last ned appen
Hjem / Personvernerklæring

Privacy policy

Denne siden finnes bare på engelsk.

Last updated 2026-09-05

How NordMind AI Solutions AB handles your personal data in the HeatPump AI app and on this site — what we collect, who else sees it, how long we keep it, and how to get it deleted.

On this page

  1. Who we are
  2. What we collect
  3. What we do not collect
  4. Why we process it, and on what legal basis
  5. Who else handles your data
  6. How long we keep it
  7. Deleting your account
  8. Your rights
  9. Children
  10. Manufacturer content on this website
  11. Changes to this policy
  12. Contact

Who we are

NordMind AI Solutions AB, Forskningsringen 71B, 174 61 Sundbyberg, Sweden, is the data controller for the personal data described on this page. You can reach us about anything on it — including a request to see, correct or delete your data — at info@nordmindai.com.

This policy covers the HeatPump AI app for iOS and this website. It does not cover what Apple, Google or a heat pump manufacturer does with data you give them directly.

What we collect

  • Your account. When you sign in with Apple or Google, or continue anonymously, Firebase Authentication gives your account an identifier. If your sign-in provider passes us an email address, we store that as well. We never see your Apple or Google password.
  • Your heat pump. The brand and model family you select, so answers come from the right manual.
  • Your home, if you give it. When you ask the assistant to help your pump run better, you can tell us a city or area, a country, whether you live in an apartment or a house, and a size band. All of it is typed by you — we do not read your device location, and the app never asks for location permission. The city or area is a coarse place name, not your device location and not a street address. It is stored on your phone, and a copy is attached to the diagnosis session it was used for, which is deleted after 30 days like the rest of that session.
  • Diagnosis conversations. The messages you type and the answers the AI returns, including error codes you look up.
  • Photos you choose to send. Optional. A photo is sent together with your message to our AI provider so the model can see what you see. We do not store it — no photo is written to our database, our file storage or our logs; the copy we handle exists only for the length of that one request. What the AI provider does with the content of a request it receives is governed by that provider's own terms, which we do not control.
  • Purchases. Which credit pack you bought, when, how many credits it granted, and whether delivery succeeded. Payment itself is taken by Apple — we never receive your card details.
  • App language. Which of English, Norwegian, Swedish or Finnish your app is set to, so the answer comes back in your language.
  • Service logs. Ordinary server logs used to run and debug the service. Some of these contain your account identifier, and for a signed-in account, your email address.
  • Usage analytics. If you leave Settings → "Share usage analytics" on (it is on by default), the app records pseudonymous product events through Firebase Analytics: which screens you open, which pump brand and family you selected, whether an error-code lookup found a match, whether a diagnosis turn was sent or refused, whether a purchase completed, and whether a maintenance reminder was opened or completed. Every value is a fixed code or a yes/no — there is no message text, no photos, no location and no email address in any of them. Firebase Analytics identifies the install with a random app instance id, not with you by name, email or account. Alongside these events, Google also records standard technical details — your device model, operating system version, app version and app language — and derives an approximate country or region from your IP address. That is a network-level inference made by Google, not a location we send: the app never reads your device's location. Turning the setting off stops collection immediately.

What we do not collect

The app contains no advertising SDK and no attribution or tracking SDK. Ad personalization signals are switched off in the analytics SDK, we do not track you across other companies' apps or websites, and nothing we collect is linked to an advertising identifier — which is why the app never shows you an App Tracking Transparency prompt. We do not collect your device location, contacts, health data, financial data or browsing history, and we do not sell personal data or share it for advertising.

This website is a set of static pages. It sets no cookies and runs no analytics.

Why we process it, and on what legal basis

  • To run the service you asked for — your account, your heat pump, your conversations and any photo you attach. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)). Photos are optional and entirely under your control: if you do not attach one, none is processed.
  • To sell and meter credits. Legal basis: performance of the contract, and for the accounting records behind a purchase, our legal obligations (Art. 6(1)(c)).
  • To prevent misuse — the allowance ledger and rate-limit counters that stop one person from consuming the service through repeated throwaway accounts. Legal basis: our legitimate interest in keeping the service available and not paying for automated abuse (Art. 6(1)(f)).
  • To keep a record of the AI notice you accepted, and when. Legal basis: our legitimate interest in being able to establish or defend a legal claim about what was disclosed to you (Art. 6(1)(f)).
  • To keep the service secure and working — logs and diagnostics. Legal basis: legitimate interest (Art. 6(1)(f)).
  • To understand how the app is used — the pseudonymous usage analytics described above, so we can see which parts of the app people actually reach and where they get stuck, and improve it. Legal basis: our legitimate interest in understanding and improving our own product (Art. 6(1)(f)). You do not have to write to us to object to this one: switching Settings → "Share usage analytics" off in the app is the objection, and it takes effect immediately.

You can object to any processing we base on a legitimate interest — see Your rights.

Who else handles your data

We use a small number of service providers. Each one only gets what it needs:

  • Google (Firebase). Sign-in, database, server functions, logging and usage analytics (Firebase Analytics). Our database and server functions run in Google's European regions. Firebase Authentication and Firebase Analytics are operated by Google as global services, so account identifiers and usage events may be processed outside the EU/EEA.
  • OpenAI. The AI provider that generates the answers. Your message, the conversation so far and any photo you attach are transmitted to it to produce a reply. Processing takes place in the United States.
  • RevenueCat. Validates App Store purchases and tells our server how many credits to add. It receives your account identifier and purchase events.
  • Apple. Takes payment, and provides Sign in with Apple. For the payment itself, Apple acts on its own account under Apple's privacy policy, not ours.

Transfers outside the EU/EEA. Some of the processing above happens outside the EEA, most clearly with OpenAI in the United States. Firebase Analytics is another: unlike our database and server functions, it is a global Google service and the usage events it collects are processed by Google on its own infrastructure, which is not limited to European regions. Where processing happens outside the EEA, we rely on the provider's standard data-processing terms, which incorporate the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. Write to info@nordmindai.com if you want to know which mechanism applies to a specific recipient.

How long we keep it

  • Diagnosis conversations — messages, answers and the cost record attached to a session: 30 days from the start of the session, after which a daily job deletes the whole session and everything under it.
  • Photos: not stored by us at all, so there is no retention period on our side to state.
  • Purchase and misuse-prevention records — the credit ledger and rate-limit counters: 13 months from the last time each record was written. This is a billing and abuse audit window, long enough to answer a late dispute or chargeback.
  • The record of which AI notice you accepted, and when: 13 months.
  • Your account and your credit balance: until you delete your account.
  • Service logs: 30 days, the default retention of Google Cloud Logging.

Deleting your account

You can delete your account from inside the app, under Settings → Delete account. No email to us is required.

Deleting removes your account, every diagnosis session, and any credits still in your balance. Remaining credits are destroyed, are not refunded, and cannot be recovered afterwards. Deletion is refused while a diagnosis answer is actually being generated — wait a few seconds and try again.

Two things deliberately survive deletion, and are then removed on the periods above:

  • the record of which AI notice you accepted and when, and
  • the misuse-prevention records, which are tied to the allowance rather than to your account — deleting them would reopen the exact abuse route they exist to close.

We keep both on the basis that they may be needed to establish or defend a legal claim (GDPR Art. 17(3)(e)).

Your rights

Under the GDPR you can ask us to:

  • give you access to the personal data we hold about you, and a copy of it;
  • correct anything that is wrong;
  • erase it (the in-app deletion above does this immediately for everything except the two categories named there);
  • restrict how we use it;
  • give it to you, or to another provider, in a portable form (portability); and
  • object to processing we base on a legitimate interest.

Email info@nordmindai.com. We answer within one month.

If you think we have handled your data wrongly, you can complain to the Swedish supervisory authority — Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden, imy@imy.se, imy.se — or to the supervisory authority in the EU/EEA country where you live or work.

Children

HeatPump AI is meant for heat pump owners and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to info@nordmindai.com and we will delete it.

Manufacturer content on this website

The error-code pages on this site are written from published manufacturer manuals. We synthesise the facts in our own words, quote at most short attributed passages, and link to the manufacturer's own PDF rather than hosting or reproducing it.

If you are a rightsholder and want content removed, write to info@nordmindai.com with the page address, the brand and model concerned, and what you are asking us to remove and why. Our indexes are removable one brand at a time, so we can act on a notice without taking the whole site down.

Changes to this policy

If we change this policy we update the date at the top of the page. If a change materially affects how we use your data, we will also tell you in the app.

Contact

NordMind AI Solutions AB
Forskningsringen 71B, 174 61 Sundbyberg, Sweden
info@nordmindai.com
HeatPump AI
Hjem Personvernerklæring Bruksvilkår Kontakt

HeatPump AI gjengir informasjon fra produsentenes bruksanvisninger med våre egne ord. Vi lenker til de offisielle bruksanvisningene i stedet for å publisere dem selv. Følg alltid lokale sikkerhetsforskrifter. Arbeid på kjølekretsen, det elektriske anlegget og gassanlegg må utføres av en sertifisert tekniker.

NordMind AI Solutions AB · Forskningsringen 71B, 174 61 Sundbyberg, Sweden

Merke- og modellnavn er varemerker som tilhører sine respektive eiere. HeatPump AI er et uavhengig produkt uten tilknytning til noen produsent, og er verken godkjent eller sponset av noen av dem.