Information under GDPR Article 13
Privacy Notice
Updated 9 August 2026
The German notice is authoritative; this translation is provided for convenience.
1. Controller
The operator and contact details are listed in the Imprint.
2. Account and learning
We process email, profile, authentication, security, settings, learning progress and support records to create and perform the contract (GDPR Article 6(1)(b)); security also relies on legitimate interests under Article 6(1)(f). If you voluntarily sign in with Google or Facebook, we process the provider's stable identifier and profile data needed for sign-in. A Facebook email is not treated as verified; a new Facebook user confirms a chosen address through our own one-time link.
3. Voice and AI
Voluntary recordings, transcripts and AI feedback are processed for the requested learning feature and stored with the account for replay. Do not submit real patient data. Inputs can be sent to processors used for transcription and AI feedback.
4. Billing and communication
For paid features Stripe processes card data while we receive customer, session, subscription and payment-status identifiers. Transactional email and user-initiated support chat are handled through service providers.
5. Analytics
Optional analytics starts only after separate consent (GDPR Article 6(1)(a) and TDDDG section 25). Refusal does not restrict learning and consent can be withdrawn for the future.
6. Recipients and transfers
Depending on the feature, recipients and processors include AWS, Google or Meta Platforms for the external sign-in you choose, Stripe, Resend, Crisp, PostHog (only with consent), OpenAI and ElevenLabs. Transfers outside the EEA require a valid mechanism such as an adequacy decision or EU Standard Contractual Clauses.
7. Retention
Account and progress data are generally retained until account deletion; recordings, transcripts and feedback until replacement or deletion with the account. Log retention is limited to operations and security. Billing records remain only for statutory retention periods.
8. Rights
Subject to the GDPR, you may request access, correction, erasure, restriction, portability, object and withdraw consent. You may complain to the authority identified in the Imprint. We do not make solely automated decisions with legal or similarly significant effects.