Privacy Policy
Last updated: 11 July 2026
1. Who We Are
Medyra ("we", "us", "our") is an educational service that explains medical documents in plain language, available on the web at medyra.de and as a mobile app for Android and iPhone. We are the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR).
Contact: hello@medyra.de
Our full provider details and postal address are in our Impressum.
2. What Data We Collect
- Account data: Your email address, name, and authentication credentials, collected when you sign up via our authentication provider Clerk. Sign-in with Google or LinkedIn is also supported.
- Uploaded documents: Medical documents you upload for analysis, such as lab reports, doctor letters, prescriptions, and health insurance letters (PDF, images, or text).
- Extracted health values and explanations: The values we read from your documents (for example lab results), the plain-language explanations we generate, and, if you save a document to a health profile, the biomarker history used for your trends.
- Health profiles: Optional profiles you create for yourself or family members (name, date of birth, relationship, gender). These fields are encrypted at rest.
- Payment data: If you purchase a paid plan, payment is processed by Stripe. We never receive or store your full card details.
- Usage data: Pages visited, features used, and technical information such as IP address and browser type, collected via Google Analytics only with your consent.
- Cookies: Essential authentication cookies (Clerk) and, with consent, analytics cookies (Google Analytics). See Section 8.
3. Legal Basis for Processing
- Explicit consent for health data (Art. 6(1)(a) and Art. 9(2)(a) GDPR): Medical documents contain special category health data. Before your first upload we ask for your explicit consent, and we process this data only to generate your explanation and, if you choose, to build your health history. You can withdraw this consent at any time.
- Contract performance (Art. 6(1)(b) GDPR): Providing your account, analysing documents, and delivering the features of your plan.
- Consent (Art. 6(1)(a) GDPR): Analytics cookies are only set with your consent.
- Legal obligation (Art. 6(1)(c) GDPR): Retaining payment and invoicing records where tax law requires it.
- Legitimate interest (Art. 6(1)(f) GDPR): Basic security logging and fraud prevention.
4. How Long We Keep Your Data
You control how long your documents are kept, in your Data & Privacy settings:
- Auto-delete after 30 days (default): Each uploaded document and its explanation are permanently deleted 30 days after upload, automatically.
- Keep as encrypted backup: If you choose this, your documents and health history stay available until you delete them or switch back. They remain encrypted at rest.
- Account data: Retained until you delete your account.
- Payment records: Retained for up to 10 years where required by German tax and commercial law (§ 147 AO, § 257 HGB).
- Analytics data: Retained by Google Analytics for 14 months.
You can delete any individual document, or your entire account and all associated data, at any time from within the product.
5. Third-Party Data Processors
We use the following processors under Art. 28 GDPR. Each operates under a data processing agreement and, for transfers outside the EU/EEA, EU Standard Contractual Clauses. Your medical documents are processed by Anthropic (Claude AI) solely to generate your explanation; Anthropic does not use API data to train its models.
| Processor | Purpose | Location |
|---|---|---|
| Clerk | User authentication | USA (SCCs applied) |
| MongoDB Atlas | Encrypted data storage | EU (Frankfurt) |
| Anthropic (Claude AI) | AI document analysis — Privacy Policy | USA (SCCs applied) |
| Stripe | Payment processing | USA/EU (SCCs applied) |
| Vercel | Website hosting | EU (Frankfurt) |
| Expo (EAS) | Mobile app build and delivery | USA (SCCs applied) |
| Google Analytics | Usage analytics (with consent) | USA (SCCs applied) |
SCCs = Standard Contractual Clauses, the approved EU mechanism for international data transfers under Art. 46 GDPR.
6. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of your data.
- Right to rectification (Art. 16): Correct inaccurate data.
- Right to erasure (Art. 17): Delete your account and all associated data.
- Right to restriction (Art. 18): Ask us to limit how we process your data.
- Right to data portability (Art. 20): Receive your data in a machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)): Withdraw any consent, including for health data processing or analytics, at any time, without affecting processing already carried out.
To exercise any right, email us at hello@medyra.de. We respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. The authority competent for us is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (LDA Brandenburg). You may also contact the authority in your own EU country of residence.
7. Automated Processing
Your documents are analysed automatically by AI to produce your explanation. This does not produce a legal or similarly significant decision about you within the meaning of Art. 22 GDPR. The result is educational information, not a diagnosis or a decision, and no human at Medyra reviews your documents manually.
8. Cookies
We use the following cookies:
- Essential cookies: Set by Clerk for authentication. These are necessary for login and cannot be disabled.
- Analytics cookies (Google Analytics): Collect usage data to help us improve the service. These are only set after you give consent in our cookie banner (Consent Mode; analytics storage is denied by default).
You can withdraw consent at any time by clearing your browser cookies or contacting us.
9. Data Security
All data is transmitted over HTTPS (TLS). Your medical documents, the extracted values, explanations, and health-profile fields are encrypted at rest using AES-256-GCM before they are stored, so the raw data is not readable in the database. Data is stored in the EU (Frankfurt). Access is restricted to authenticated service processes, and we perform no manual review of your uploaded documents. Because we run automated AI analysis on your behalf, the content is briefly processed in plain text in memory during analysis; it is never persisted unencrypted.
10. Children
Medyra is not directed at children under 16. You may add a child as a health profile to manage their documents as their parent or guardian, but the account holder must be an adult.
11. Changes to This Policy
We may update this policy from time to time. We will notify registered users by email of any material changes. The "Last updated" date at the top always reflects the current version.
12. Contact
For any privacy question or to exercise your rights:
Email: hello@medyra.de
Website: medyra.de