← Dr. Katze

Information under GDPR Article 13

Privacy Notice

Updated 9 August 2026

The German notice is authoritative; this translation is provided for convenience.

1. Controller

The operator and contact details are listed in the Imprint.

2. Account and learning

We process email, profile, authentication, security, settings, learning progress and support records to create and perform the contract (GDPR Article 6(1)(b)); security also relies on legitimate interests under Article 6(1)(f). If you voluntarily sign in with Google or Facebook, we process the provider's stable identifier and profile data needed for sign-in. A Facebook email is not treated as verified; a new Facebook user confirms a chosen address through our own one-time link.

3. Voice and AI

Voluntary recordings, transcripts and AI feedback are processed for the requested learning feature and stored with the account for replay. Do not submit real patient data. Inputs can be sent to processors used for transcription and AI feedback.

4. Billing and communication

For paid features Stripe processes card data while we receive customer, session, subscription and payment-status identifiers. Transactional email and user-initiated support chat are handled through service providers.

5. Analytics

Optional analytics starts only after separate consent (GDPR Article 6(1)(a) and TDDDG section 25). Refusal does not restrict learning and consent can be withdrawn for the future.

6. Recipients and transfers

Depending on the feature, recipients and processors include AWS, Google or Meta Platforms for the external sign-in you choose, Stripe, Resend, Crisp, PostHog (only with consent), OpenAI and ElevenLabs. Transfers outside the EEA require a valid mechanism such as an adequacy decision or EU Standard Contractual Clauses.

7. Retention

Account and progress data are generally retained until account deletion; recordings, transcripts and feedback until replacement or deletion with the account. Log retention is limited to operations and security. Billing records remain only for statutory retention periods.

8. Rights

Subject to the GDPR, you may request access, correction, erasure, restriction, portability, object and withdraw consent. You may complain to the authority identified in the Imprint. We do not make solely automated decisions with legal or similarly significant effects.