Privacy policy – Postklar app and web app (beta)
Deutsche Fassung (verbindlich)
Draft (beta): this version is still being legally reviewed and may change. The German version is the binding one.
This policy covers the Postklar app (iOS, Android) and the web app (app.postklar.de). The website postklar.de has its own separate policy.
1. Controller
ARCH VISION UG (haftungsbeschränkt)
Unterbiberger Straße 20
81737 Munich
Germany
Represented by the managing director: Maryam Rabiee
Phone: +49 155 6340 4170
Privacy requests: privacy@postklar.de
General contact: info@postklar.de
Register: Amtsgericht München, HRB 316080
2. Data protection officer
Not yet fixed.
3. What this is about, in short
Postklar is a digital archive for letters. You photograph a letter, upload a file, share it from another app or forward it by email to your personal Postklar address. An AI reads the letter, summarises it in your language, picks out sender, deadlines and amounts, files it into categories and answers questions about your own archive.
Principles that apply throughout:
- Encryption: Every page is encrypted on your device with its own key per letter (AES-256-GCM) before it is uploaded. The summary, full text, extracted details and notes are also stored encrypted with that letter's key. The letter key itself is protected by a master key held only on the server. This is not end-to-end encryption: for the AI to read a letter, our server decrypts it briefly for processing.
- Processing in the EU: Database, file storage and server functions run in Frankfurt am Main. AI processing uses Google Vertex AI in EU regions (see section 6).
- No advertising, no tracking: no advertising IDs, no location data, no tracking across other apps or websites. We do not sell data.
- No advice: The AI describes what a letter says. It gives no legal, tax or medical advice and makes no decisions for you (see section 9).
4. Beta
Postklar is in a free test phase (beta). Features may change, and some are enabled only for individual test accounts (in particular the health record, section 5.10). Payments are not active yet.
5. What we process, why, and on what legal basis
5.1 Account and sign-in
- Data: email address, sign-in times, technical session data; profile details you enter (display name, interface and summary language, optional profile photo).
- Sign-in: email link / one-time code. Sign-in emails are sent via Resend. Alternatively you can sign in with Apple or Google; the provider then sends us your email address (with Apple possibly an anonymous relay address) and an identifier.
- Profile photo: re-encoded on the device, which removes metadata (e.g. location, EXIF).
- Purpose: providing the account and the service. Legal basis: Art. 6(1)(b) GDPR.
5.2 Capturing and storing letters
- Ways in: camera, file upload, sharing from other apps, email forwarding (5.5).
- Data: images/PDFs of letters and everything in them. Letters regularly contain personal data about you and third parties (senders, case workers, family members), identifiers (tax, insurance, customer, case numbers), amounts and bank details, and may contain special categories of personal data (health data in medical letters, residence status, court or criminal proceedings).
- Storage: encrypted (section 3) in the database and file storage in Frankfurt.
- Purpose: archiving and showing your letters.
- Legal basis: Art. 6(1)(b) GDPR. For special categories: For third parties' data in your letters:
5.3 AI reading of letters
- What happens: After upload our server decrypts the letter briefly in memory and sends the pages to Google Vertex AI (EU region). The result: a summary in your language, title, sender, categories, deadlines, amounts and payment details, a flag for sensitive letters (e.g. court, police, immigration office, fines, termination, debt collection), the full text of the pages, structured details with the verbatim quote and page reference (e.g. identifiers, contract terms, lab values), embeddings (vectors) for search, and translations on request.
- Card numbers: card numbers on card-terminal slips are not stored.
- Identifier matching: case numbers and similar numbers used to group letters are not stored in clear text, only as a keyed hash (HMAC) per user.
- Purpose: the core function of the service. Legal basis: Art. 6(1)(b) GDPR; special categories see 5.2 .
- No training:
5.4 Ask and voice input
- Ask: You can ask questions about your archive. Your question and the matching passages from your own letters (and letters you have access to, e.g. in a family or company space) are sent to Google Vertex AI (EU). The answer describes what the letters say, with sources. Questions and answers are kept as a conversation history in your account.
- Voice input: The device's own speech recognition is used first, in on-device-only mode. Where that is not possible (e.g. in the browser), the recording (max. 60 seconds) is sent to our server and transcribed via Google Vertex AI (EU). The audio is not stored; it is processed in memory only. You see the transcript and can correct it before it is sent as a question.
- Legal basis: Art. 6(1)(b) GDPR.
5.5 Personal email address for letters
- Each account gets a personal inbound address under
in.postklar.de. Forwarded emails are accepted only if the sender is an address you have verified and the SPF, DKIM and DMARC checks pass. Only certain attachment types are accepted (image, PDF, DOCX, text), with size and volume limits (by default 20 MB per message, 20 messages per hour, 100 per day). - Path: Cloudflare Email Routing receives the email, a Cloudflare Worker parses it and hands it to our server in Frankfurt, where each attachment is encrypted and read like an uploaded letter.
- Data: sender and recipient addresses, subject, body, attachments, result of the sender check.
- Legal basis: Art. 6(1)(b) GDPR.
5.6 Reminders and notifications
- Push notifications (e.g. "letter read", deadline reminders): we store your device's push token. Messages go through Expo's push service (650 Industries, Inc., USA) to Apple (APNs) or Google (Firebase Cloud Messaging). A notification may name the sender and type of letter. With the app lock on, it names neither.
- Email reminders and invitations are sent via Resend (EU sending region, Ireland).
- You can turn push notifications off in the app or in device settings.
- Legal basis: Art. 6(1)(b) GDPR.
5.7 Share by link
- You can share one letter by link, optionally with a passcode. We store only a hash of the link. A link is valid for 7 days by default, 30 days at most, and can be revoked at any time. Anyone with the link can view the letter without signing in.
- Legal basis: Art. 6(1)(b) GDPR. Who gets the link is your decision.
5.8 Family
- On the Family plan up to 8 people form one household. Everyone has their own private archive; single letters can be shared with the family; there is a shared family cabinet.
- Family admin access: The person who manages the family can read, but not change, members' archives – only after that member has confirmed a notice about it. Before that the admin sees nothing of theirs. Health letters and sensitive letters (court, police, immigration office, fines, termination, debt collection) stay hidden from the admin unless the member turns on their own switch; they can turn it off again at any time. The admin never sees a member's chat history, reminders, profile or consents. A member who does not want this can leave the family.
- Extra cabinets for people without an account (e.g. young children or relatives being cared for) are created by the family admin, who decides which members can see them.
- Legal basis: Art. 6(1)(b) GDPR towards each member.
5.9 Company spaces
- A company can create a company space with the roles admin, finance, member, submitter and tax advisor. Letters in a company space belong to the company; who can see or edit which letters depends on role and allowed categories (e.g. "Employees & HR" is not allowed by default; tax advisors see receipts only).
- Every change is recorded in an append-only log (who, when, what – no letter content, no email address), readable only by the space's admins.
- If a user account is deleted, letters it uploaded into a company space stay with the company; only the membership ends.
5.10 Health record (special category, Art. 9 GDPR)
- Status: switched off server-side for all users, enabled only for individual test accounts. It will be released only after legal review.
- What it does: values from lab reports (e.g. HbA1c, cholesterol) are copied into a personal table with unit, date, verbatim quote and page reference. No assessment (no high/low/normal, no recommendation). Values can be corrected and exported as a PDF with sources. They are visible only in the locked view (Face ID / device passcode) and not reachable via Siri, Apple Watch or Ask.
- Legal basis: your explicit consent under Art. 9(2)(a) with Art. 6(1)(a) GDPR, asked for separately from everything else. The rest of the app works without it.
- Withdrawal: at any time in the app, for the future. After withdrawal no new values are recorded; existing values remain until you choose "Delete health record".
- Family: a member's values are hidden from the family admin unless the member allows it (5.8).
5.11 Service metrics
- Data: events such as sign-up, first letter read, letters read per day by channel (camera, upload, email, share), errors with an error code, use of features (e.g. Ask, export, deadlines, watch), plus platform, app version, language and plan. These events are linked to your account (pseudonymously, via the internal account id).
- Not collected: letter text, summary, sender, amounts, identifiers, health values, advertising IDs, location. A database rule accepts only short tokens from a fixed list, never free text.
- Purpose: operation, debugging, cost control, pricing.
- Retention: raw events 90 days; after that only daily totals without reference to a person. Deleting the account deletes all its events.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a working, viable service).
5.12 AI cost per account
- For every AI call we store purpose (e.g. reading, question, translation, transcription), model, token count and cost, linked to your account – no content.
- Purpose: cost control, quotas (e.g. number of letters on the free plan), abuse prevention. Legal basis: Art. 6(1)(b) and (f) GDPR.
5.13 Error reports (Sentry)
- On crashes and errors the app and server send a report to Sentry (Functional Software, Inc.), EU data region (Germany).
- Server: only an allowlist is sent: error type, an error code from a fixed list, stack trace (file/function/line), environment and a one-way fingerprint of the message. No message text, request data, user identifiers or other context.
- App: error messages are scrubbed of recognisable personal patterns on the device before sending; free-form extra context is dropped.
- Purpose: finding and fixing errors. Legal basis: Art. 6(1)(f) GDPR.
- Retention:
5.14 Operator administration (admin panel)
- An internal admin panel is accessible only to the operator, with two-factor sign-in (TOTP). It shows totals and – where needed for support, billing or abuse – account data only (email, plan, usage figures, errors, storage, billing events), never letter content; the panel technically cannot decrypt letters. There is no "sign in as user". Every access is recorded in an append-only log.
- Legal basis: Art. 6(1)(b) and (f) GDPR.
- The panel is served from Cloudflare Pages and additionally protected by Cloudflare Access (one allowed email address, then an email code and TOTP).
5.15 Payments (not active yet)
Payments are not active in the beta. Planned: in-app subscriptions via Apple/Google with RevenueCat, Inc. (USA) to manage subscription status (pseudonymous user id, receipts), and for companies payments via Stripe (Stripe Payments Europe Ltd., Ireland).
5.16 Contact and support
If you write to us (info@postklar.de or privacy@postklar.de), we process your details to answer (Art. 6(1)(b) or (f) GDPR). Mail to these addresses is forwarded to the operator's mailbox via Cloudflare Email Routing.
5.17 Data on your device
- Sign-in session: on the phone in the device's secure storage; in the web app in browser storage (localStorage).
- Offline reading: the reading (not the page image) of recently opened letters is cached encrypted on the device, with a key in the device keystore; signing out deletes key and files.
- App lock: Face ID / fingerprint are checked only by the operating system; we receive no biometric data.
5.18 Serving the web app
The web app (app.postklar.de) is served via Cloudflare Pages. Cloudflare processes technically necessary connection data (IP address, time, requested address, browser details) to deliver the page and protect it against attacks (Art. 6(1)(f) GDPR).
6. Recipients and processors
We use the following service providers. Contracts under Art. 28 GDPR are or will be in place with processors.
| Provider | Purpose | Data | Location | Transfer basis where a third country is involved |
|---|---|---|---|---|
| Supabase, Inc. (USA), on AWS | database, auth, file storage, server functions, scheduled jobs | all app data (letter content encrypted) | Frankfurt am Main (AWS eu-central-1) | Not yet fixed. |
| Google Cloud (Vertex AI) | AI reading, summary, facts, full text, embeddings, translation, Ask, speech-to-text (fallback) | letter content in clear during processing, questions, audio | EU: multi-region "eu" (EU member states only) and single EU regions | Not yet fixed. |
| Cloudflare, Inc. (USA) | serving the web app and admin panel (Pages); receiving and parsing inbound email (Email Routing, Worker); forwarding contact addresses | connection data; for inbound email the full email content incl. attachments | global network | EU-US Data Privacy Framework (certified per the website policy); SCCs if needed |
| Functional Software, Inc. (Sentry) (USA) | error reports | technical error data (5.13) | EU data region (Germany) | Not yet fixed. |
| 650 Industries, Inc. (Expo) (USA) | push notifications; app builds and updates (EAS) | push token, notification text (possibly sender and letter type) | USA | Not yet fixed. |
| Apple Inc. / Google LLC (APNs, FCM) | delivering push notifications | push token, notification text | worldwide | Not yet fixed. |
| Resend (Plus Five Five, Inc.) (USA) | sign-in, reminder, invitation and confirmation emails | email address, email content | EU sending region (Ireland, eu-west-1) | Not yet fixed. |
| RevenueCat, Inc. (USA) – planned, not active | in-app subscription management | pseudonymous user id, receipts | USA | Not yet fixed. |
| Stripe Payments Europe Ltd. (Ireland) – planned, not active | payments, invoices and VAT for companies | name, email, payment and billing data | EU/USA | Not yet fixed. |
| Apple / Google (App Store, Google Play, TestFlight) | app distribution, in-app billing (planned), beta distribution | per the platform's terms | – | own controllership |
Inside Postklar, your letters are seen only by you and by people you give access through sharing, family or a company space (5.7–5.9). The operator cannot view letter content through the admin panel.
7. Transfers to third countries
We choose providers and regions so that your letters' content is processed in the EU. Some providers are based in, or owned from, the USA; where data can reach the USA (e.g. push notifications, inbound email via Cloudflare, support access by providers), we rely on the adequacy decision (EU-US Data Privacy Framework, Art. 45 GDPR) where the recipient is certified, otherwise on standard contractual clauses (Art. 46(2)(c) GDPR).
8. Retention and deletion
| Data | Retention |
|---|---|
| Letters and everything derived (pages, summary, full text, facts, embeddings, notes, deadlines, payment details) | until you delete the letter or your account. |
| Deleted letters (bin) | restorable for 30 days, then permanently deleted by a daily job |
| Letters that could not be read | moved to the bin after 7 days, then 30 days as above |
| Account | deletable in the app at any time; deletes all letters, files, profile data, memberships and metrics. What remains: a log entry that a deletion happened (no personal reference, counts only) and an internal deletion job (internal id and counts) that proves the erasure. Letters in company spaces stay with the company (5.9). |
| Family on account deletion | letters shared with the family are deleted with the account. If the family admin leaves Postklar, admin passes to the longest-standing member. |
| Share link | 7 days (default), 30 days at most, revocable |
| Data export | download link valid for 1 hour; a new export replaces the old one. |
| Voice recordings | not stored |
| Service metrics | raw events 90 days, then anonymous daily totals only |
| Health record | until you choose "Delete health record" or delete the underlying letter or your account |
| Company space log | Not yet fixed. |
| Server logs, error reports, backups | Not yet fixed. |
Statutory retention duties (e.g. for invoices once paid plans exist) are unaffected.
9. No automated individual decision-making
The AI reading is not automated decision-making within Art. 22 GDPR. Postklar makes no decision based on it that has legal effect on you or similarly significantly affects you. The AI only describes what your letters say (summary, deadlines, amounts); every output is labelled AI-generated and replaces no legal, tax or medical advice. The AI can be wrong; the original always prevails. No profiling for advertising takes place.
10. Security
- Every page encrypted on the device before upload, one key per letter (envelope encryption), master key on the server only; everything derived from a letter stored encrypted.
- TLS on all connections.
- Database-level access control (Row Level Security): every request sees only the data its caller may see.
- No letter content, keys or plaintext in logs or error reports.
- App lock with Face ID / device passcode; notifications without content on locked devices.
- Admin access only with two-factor sign-in, no access to letter content, append-only access log.
- Checks on inbound email (SPF, DKIM, DMARC, verified senders), size and volume limits, rate limits on public endpoints.
11. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). Many of them you can exercise directly in the app:
- export everything (letters as original images, readings, deadlines, payment details, receipts, notes and more, as a ZIP file with an explanation),
- delete single letters and delete the account,
- correct details and values.
Otherwise, an email to privacy@postklar.de is enough.
12. Withdrawing consent
Where processing is based on your consent (e.g. health record, family switches), you can withdraw it at any time for the future, in the app or by email. Processing before the withdrawal remains lawful.
13. Right to complain
You can complain to a data protection supervisory authority. The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
14. Whether you must provide data
An email address is required to use Postklar. Without uploading letters the service cannot do its job. Consent to the health record is voluntary; the rest of the app works fully without it.
15. Children
Postklar is for people aged 18 and over. Children's letters can be kept in a family by the family admin in a separate cabinet (5.8); responsibility lies with the parents.
16. Changes
We update this policy when the service or the law changes. We inform you of material changes in the app or by email, and ask for new consent where needed.
Date: 29 Sep 2026