Minnehimmel™
Norsk · English

Privacy Policy for Minnehimmel™

Last updated: September 17, 2026

This is an English translation provided for convenience. The Norwegian version (Personvernerklæring) is the authoritative version; in case of any discrepancy, the Norwegian text prevails.

Minnehimmel™ lets you create a memorial page for someone you have lost, where family and friends can light a star with a greeting. This policy explains what personal data we process, why, who gets access, how long we keep it, and what rights you have.

It covers three surfaces:

A memorial page is the same page wherever it was created. We process personal data in accordance with the Norwegian Personal Data Act (personopplysningsloven) and the EU General Data Protection Regulation (GDPR).

1. Data controller

The controller of the personal data is:

"We" and "us" refer to the controller.

2. What personal data we process

Account and sign-in

How you sign in depends on where you are:

From the sign-in we receive your name, email address and a unique user ID. We never receive your password. If you use Apple's "Hide My Email", we only receive an anonymized forwarding address. It is still linked to your account.

Guest mode

In both apps, and when you visit a memorial page on the web without signing in, an anonymous user ID is created with Firebase. It grants access to content within our security rules and does not say who you are, but it is still personal data. In the apps we store which platform and app version was used and the time, as statistics only. On the web the identifier is stored in your browser. To write a greeting you must sign in.

Memorial pages, stars and greetings

We process the content you enter yourself:

We may also receive data about you from others, for example if you are mentioned or pictured in a memory. The source is then the user who entered the content.

About the deceased and the bereaved: as a general rule the GDPR does not apply to data concerning deceased persons alone. Texts and photos on a memorial page nevertheless often contain personal data about living people, including surviving relatives and others who are pictured. Those are covered by this policy.

Ordering a QR plate

When you order a physical QR plate we process name, delivery address, email address and optionally phone number, along with information about the order and the payment.

Purchases in the apps

Purchases inside an app are handled by the store you use: Apple in the App Store, Google in Google Play. Payment for a QR plate is handled by Stripe. We never receive card numbers or card security codes. We receive purchase data such as product, amount, time, status and a transaction reference.

Technical information

To deliver and protect the service we process IP address, browser and device information, requests to the service and security events. The website is protected by Google reCAPTCHA Enterprise via Firebase App Check, which processes technical device and usage data to tell humans from bots. reCAPTCHA is not used in the apps.

The website uses Vercel Analytics for visitor statistics. See section 7.

Location

If you grant permission, the device's approximate location is used only locally on the device to show the moon at the right angle in the night-sky theme. The location is not sent to us and is not stored. If you refuse, the moon is shown for a default location and everything else works as before.

When you contact us

We process your email address and what you write, in order to reply and follow up. Do not send more personal data than necessary.

3. Why we process it, and on what legal basis

PurposeLegal basis
Creating and administering your account, delivering memorial pages and publishing content at your requestContract, Art. 6(1)(b)
Processing purchases, delivering QR plates and answering questions about the orderContract, Art. 6(1)(b)
Storing and displaying data about other living persons that a user enters into a memoryLegitimate interest, Art. 6(1)(f). The interest is being able to offer a place for memories. See the note below
Secure sign-in and operation, preventing abuse, investigating security incidentsLegitimate interest, Art. 6(1)(f)
Visitor statistics for the websiteLegitimate interest, Art. 6(1)(f)
Answering enquiries that do not concern a contractLegitimate interest, Art. 6(1)(f)
Meeting obligations under bookkeeping and data protection lawLegal obligation, Art. 6(1)(c)
Location for the moon displayConsent, Art. 6(1)(a). Can be withdrawn in the device settings

About data concerning people other than yourself: when you enter a memory that mentions or shows other living people, it is you who choose to share it. Your use of the service is not in itself consent from the people concerned. We store and display the content on the basis of legitimate interest, and those concerned may object and ask for erasure, see section 9.

Do not enter health data, religious or political beliefs or other particularly sensitive data about other living people without having cleared it with them.

You do not need an account to read a memorial page. Account data is necessary for features that require sign-in, and delivery data when we are to send you a plate. You can ask for more information about our balancing of interests at post@minnehimmel.no.

4. Who can see the content

A published memorial page can be read without signing in. Names, memorial texts, photos and public greetings can therefore be seen by anyone who has the link or the QR code, and can be copied or shared onward outside Minnehimmel.

Private greetings: if you choose "private", only the person who wrote the greeting can read the text. No other user sees it, neither other visitors, the family nor the page owner. The star itself remains visible on the page with the name you gave, its position and the time.

This is important for you to know: the text is shielded by access rules, not by encryption. It is stored unencrypted, and whoever operates the service has the technical ability to read it, the same as in most online services. We do not read private greetings as part of normal operation, but we do not promise that it is technically impossible. So do not write anything in a private greeting that you would not entrust to a service provider.

If you believe a memorial page or greeting contains data about you that should be corrected or removed, contact post@minnehimmel.no.

5. Suppliers

We do not sell personal data. We use the following suppliers, who process data on our behalf under a data processing agreement unless stated otherwise:

SupplierWhat they do for us
Google (Firebase)Sign-in, database and file storage. Processes user ID, account data, everything you enter, and necessary technical data
Google (reCAPTCHA Enterprise)Protects the website against automated abuse
Apple"Sign in with Apple" and purchases in the App Store. Apple is an independent controller for its own services
Google (Play)Purchases in the Android app, once it is released. Google is an independent controller for its own services
VercelOperation of app.minnehimmel.no and visitor statistics. Processes IP address and request data among other things
StripePayment for QR plates. Stripe is both a processor and an independent controller, among other things for fraud prevention and its own statutory duties
ResendSending email confirmations for plate orders. Processes the recipient address and the contents of the email

We may also disclose data where we are legally obliged to, for example on a lawful order from a public authority.

6. Where the data is stored, and transfers outside the EEA

Most of the data is in Europe, but not all of it. This is how it actually stands:

WhatWhere
The database: memorial pages, greetings, accounts, ordersEU (Google Cloud, Europe multi-region)
The server functions that publish and deleteEU (Belgium)
The website and the memorial pages, which are rendered on the server on each visitEU (Germany)
BackupsEU (Finland)
Photos you upload to memorial pages and greetingsUSA

The photo storage is located in the USA. That applies to every photo on a memorial page and every photo attached to a greeting. The transfer takes place on the basis of the European Commission's Standard Contractual Clauses (SCC), which form part of our agreement with Google.

In addition, the other suppliers may process data outside the EEA, for instance during support. The basis is:

If you want to know which safeguards apply to your data, or to get a copy of them, contact post@minnehimmel.no.

7. Local storage in the browser, and analytics

The website stores technical information in your browser in order to handle sign-in and guest access, including Firebase data in the browser's local storage (IndexedDB). If you choose to hide greetings from a sender, that choice is stored only locally and does not apply on other devices.

You can delete local data in your browser settings. That signs you out and resets local choices, but it does not delete your account or your content with us.

Visitor statistics: the website uses Vercel Analytics to see how many people visit the pages and which pages are used. We do not use Google Analytics or similar tracking tools, and we do not build profiles of individual visitors across websites.

8. How long we keep data

DataRetention
Account dataFor as long as the account exists. Deleted when you delete the account, see delete account and data
Memorial pages, greetings and photosFor as long as the memorial page exists
Memorial pages in the trash8 days. After that they are permanently deleted, by the app when the owner opens it, and by a nightly server job if the owner does not come back
Anonymous guest accountsThe guest account itself is deleted automatically by Firebase after 30 days of no use. The statistics entry recording which platform the visit came from, with no name and no content, is kept for now
Operational logs30 days
Log of administrator actions400 days. Set by Google and cannot be shortened
Database backups30 days
Point-in-time recovery7 days
QR plate orders5 years. The plate is meant to last considerably longer than two years, so the complaint period is five years, and the accounting records are covered by the Bookkeeping Act in any case
Accounting records for purchases5 years, cf. the Norwegian Bookkeeping Act (bokføringsloven) § 13
Support emails that do not concern an orderDeleted when the matter is closed, normally within 12 months

If you delete your account, the data disappears from the live service immediately. It may nevertheless remain in a backup or in the recovery window for up to the periods stated above. The copies are only used to put right a failure, never for anything else.

9. Your rights

You have the right to:

Delete it yourself: in the app under Innstillinger (Settings), or at app.minnehimmel.no/en/account. The procedure, and two limits you should know about, are described on delete account and data.

Send other requests to post@minnehimmel.no. We reply without undue delay and normally within one month. You also have the right to lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority (datatilsynet.no).

10. Children

The service is not directed at children. Children may consent to information society services themselves from the age of 13, cf. the Norwegian Personal Data Act § 5. For younger children, consent from a holder of parental responsibility is required. Take particular care with photos and information about children in a memory.

11. Security

Data is transferred encrypted, access is restricted, and the database has rules governing who can read what. See section 4 for what this means for private greetings.

12. Changes

We may update this policy. Material changes will be announced in the app or on minnehimmel.no.

13. Contact

Questions about privacy? Contact post@minnehimmel.no.

Delete account and data · Terms · Guidelines

© 2025–2026 Minnehimmel™ – All rights reserved · minnehimmel.no