Built in Europe. For Europe.

Europe's most secure
messenger.

Private. Punkt

Messaging, marketplace, events, jobs and calls in one app. End-to-end encrypted, running exclusively on servers inside the EU, built under European law.

X3DH key exchange Servers in Germany GDPR by design
Verified and evidenced
X3DH key exchange GDPR compliant Servers in the EU Open source client planned ISO 27001 in progress
E2E
Always on, not optional
100 %
Servers in the EU
0
Trackers in the product
€0
For private users
Security

Not even we can read along.

Every message is encrypted on your device before it leaves it. We run the servers, but we hold no key. This is not a setting you have to switch on, it is how the system is built.

ProtocolX3DH
EncryptionStandard, not optional
Server locationsGermany · Nuremberg
Legal jurisdictionEU · GDPR · Schrems II
Company domicileAustria
Client source codeIn preparation
One account, seven modules

Everything you would otherwise need seven apps for.

Every module sits behind the same encryption and the same account. No switching, no second profile, no new data trail.

Messenger

One-to-one and group chats, voice messages, files. End-to-end encrypted, including in large groups.

E2E · X3DH

Marketplace

Buy and sell locally. Straight from the chat, with no middleman.

0 % commission

Lending

Drill, trailer, party tent. Borrow instead of buy, within your neighbourhood and with a clear return.

Borrow, don't buy

Events

Parties, matches, meetups. RSVPs, group chat and reminders are linked automatically.

Local & private

Jobs

Openings nearby. Apply by message, without an account on a third-party portal.

No profile selling

Calls

Voice and video calls, one-to-one or in groups. Encrypted like every message.

Encrypted

Business

For clubs, schools and companies: verified profiles, team channels, clear roles.

For organisations

Encrypted in Europe. Not administered elsewhere.

heloo Built in Europe. For Europe.
Pricing

Free for private use.
Enterprise on request.

Private
€0 / forever
No trial period · no credit card
  • All modules: messenger, marketplace, lending, events, jobs, calls
  • Unlimited messages, calls and listings
  • Up to five devices per account
  • 0 % commission in the marketplace
  • Full end-to-end encryption without limitation
Start for free
Enterprise
Price on request
States · schools · public bodies · companies
  • Dedicated instance, optionally in your own data centre
  • Management of users, roles and groups
  • Verified organisation profiles
  • Data processing agreement, SLA and support
  • Interfaces to existing systems
Enterprise

For everyone who carries
responsibility for others.

The same encryption as in the private version, plus a dedicated instance, administration, contract and support. Six categories, one system.

Companies

Internal communication, team channels and customer contact on an encrypted basis. Verified profiles, roles, audit compliance.

States and regions

Digital sovereignty without dependence on providers outside Europe. Optionally operated in your own data centre.

Cities and municipalities

Administration, emergency services, schools and citizen contact in one structure. Multi-tenant, with clear separation of roles.

Police and emergency services

Situational communication and alerting with robust encryption. Separated channels, defined permissions, logging.

National defence

Can be operated fully separated from the public network. Own key sovereignty, documented supply chain, auditable sources.

Intelligence services

Self-contained instances without external dependencies. Need-to-know access, no metadata leaving the system.

Pricing on request

Every organisation has different requirements for operation, certification and acceptance. Tell us what you need and we will come back with a concrete proposal.

Send request
Why now

Insecure communication
is a balance sheet risk.

Data protection has long stopped being a matter of attitude. It is a matter of liability. Three figures that set the frame.

USD 4.44m
Average cost of a data breach

That is what a single incident cost on global average in 2025. In the US the figure was USD 10.22 million. It covers investigation, downtime, notification duties and follow-up costs.

IBM COST OF A DATA BREACH REPORT 2025
4 %
Of global annual turnover as the maximum fine

For serious infringements the GDPR provides for up to 4 % of global group turnover or EUR 20 million, whichever is higher. Since 2018 around EUR 5.88 billion has been imposed across Europe, the largest single fine being EUR 1.2 billion against Meta.

ART. 83 DSGVO · DLA PIPER GDPR FINES SURVEY
USD 10.5tn
Estimated global cybercrime damage per year

Projected total damage from cybercrime worldwide for 2025. The figure covers far more than data breaches and is an estimate, not a measured value.

PROGNOSE CYBERSECURITY VENTURES
Comparison

Nine criteria.
Nine times met.

Nine criteria that determine security, sovereignty and scope. Each one is either met or not, with no shades in between. Other providers meet individual criteria well. To our knowledge, only heloo meets all nine.

Comparison von heloo mit WhatsApp, Telegram, Signal und Threema anhand von neun Securitys- und Funktionskriterien
Criterion heloo WhatsApp Telegram Signal Threema
End-to-end in every chat
Company domiciled in the EU
Servers in the EU
GDPR directly applicable
Open source client planned
Usable without a phone number
Marketplace, lending, events and jobs included
Offering for public bodies and schools
Free for private users
Criteria met 9 / 9 2 / 9 2 / 9 3 / 9 4 / 9
AS OF JULY 2026 · BASED ON PUBLICLY AVAILABLE INFORMATION AND PROVIDER DOCUMENTATION.
SWITZERLAND IS NOT AN EU MEMBER, SWISS DATA PROTECTION LAW APPLIES THERE INSTEAD OF THE GDPR. THREEMA COSTS PRIVATE USERS A ONE-OFF EUR 3.99.
ALL TRADEMARKS BELONG TO THEIR RESPECTIVE OWNERS. WE WELCOME CORRECTIONS AND WILL ACT ON THEM PROMPTLY.
Frequently asked

What you should know.

What makes heloo more secure than other messengers?

Three things together: encryption is the standard in every chat, not just in a special mode. Operations and company domicile are entirely within the EU, so European law applies and no third-country access rights do. And for the encryption we rely on open source libraries that can be verified independently. Competitors meet these individually. In this combination, to our knowledge, nobody does.

What exactly does end-to-end encrypted mean?

Your message is encrypted on your device and only decrypted again on the recipient's device. In between it sits on our servers as an unreadable block of data. For the key exchange we use X3DH, modelled on the Signal protocol. Forward secrecy via the Double Ratchet is in preparation and not yet active.

Where are the servers?

In Nuremberg, with a European provider. There is no data processing in the US and no US provider in the stack. heloo therefore falls outside access rights that expose European user data in third countries.

What does heloo cost for a school or a state?

That depends on size, mode of operation and requirements. A school with its own instance involves different effort than a state administration running it in its own data centre. So there are no list prices, but a quote after a short conversation.

What happens if an authority demands the release of messages?

We answer every lawful request, but we can only hand over what we hold. Message content is not part of that, because on our servers it exists only as an unreadable block of data. What we do hold is minimal technical data such as the time of the last connection. Every request received is published in anonymised form in our transparency report.

How do I know the app runs the published source code?

Not yet: the client source code has not been published so far, that is planned for the open beta. Open source alone is not enough anyway, because nobody can see what a provider actually compiled. That is why we additionally plan reproducible builds: anyone compiling the source themselves should end up with exactly the same file as the one in the store.

What metadata is generated and how long is it stored?

What can arise: connection timestamps, approximate message sizes and technical error logs. What does not arise: who writes to whom, how often and about what. Operational data is deleted after 30 days, error logs after 7. The full list is in the privacy notice, not just a summary.

How do I know I am really writing to the right person?

Every chat has a safety number that must be identical on both devices. You compare it once in person or by QR code. If it later changes unexpectedly, heloo warns you actively, because that is precisely the sign of an attack on the connection.

What happens to our instance if heloo ceases to exist?

For enterprise contracts: the source code of the server components is held in escrow, and in the event of insolvency or discontinuation you receive the right to keep running it yourself. If you operate in your own data centre, the instance keeps running independently of us anyway. This is in the contract, not in a letter of intent.

heloo

Start in the browser, no installation. For organisations we set up a dedicated instance.

Launch the web app

Free for private users · No credit card · End-to-end encrypted