Privacy
Privacy Policy
Effective Version 1.0
The short version. Your documents stay on your device. Cloud AI only ever sees your words when you explicitly choose a cloud model — and never trains on them. Analytics are off until you opt in. You can delete your account and its records inside the app at any time.
1. Who we are (controller)
The controller responsible for processing your personal data within the meaning of Art. 4(7) GDPR is:
A. KhayatiPostfach 12 34 56
Bielefeld, NRW 33516
Germany
Email: [email protected]
2. Scope of this policy
This policy explains what personal data NaKlar processes when you use the NaKlar mobile and desktop apps (iOS, iPadOS, macOS, Android), including cloud AI features, accounts, subscriptions, and optional analytics, as well as this website at naklar.app.
Where a feature is provided by a third party (for example an AI model provider or the App Store), that provider's own privacy terms apply in addition — we link them below.
3. On-device first: how NaKlar handles your data
NaKlar is designed so that your paperwork never has to leave your hands:
- Scanning, text recognition, and document organisation happen locally on your device.
- Your documents, recognised text, and chat conversations are stored locally on your device — not in our backend databases.
- Cloud AI processing happens only when you choose it. If you select a cloud AI model for a query, the query and the document excerpts needed to answer it are transmitted to that provider (see sections 5 and 6). If you use an on-device model, nothing leaves your device.
- Nothing is sent autonomously. Draft replies always open in your own email app for review — NaKlar never sends mail on your behalf.
4. Data we process, and why
| Category | Purpose | Legal basis |
|---|---|---|
| Document content you scan or import (letters, forms, reference numbers) | Understanding, summarising, and organising your paperwork on your device | Art. 6(1)(b) GDPR (performance of contract) |
| Chat queries and document excerpts, when you select a cloud AI model | Answering questions, explaining documents, drafting formal German replies | Art. 6(1)(b) and Art. 6(1)(a) GDPR (requested service; explicit model choice) |
| Account records: credit balance, subscription status, purchase validation tokens, rate-limit counters | Providing paid features, preventing abuse, restoring purchases | Art. 6(1)(b) GDPR (performance of contract) |
| Technical telemetry (token counts, latency), only aggregate — never message text | Operating a reliable service, diagnosing faults | Art. 6(1)(f) GDPR (legitimate interest in a stable service) |
| Optional analytics events (screen views, button taps), only with your opt-in | Crash reporting and aggregated usage trends | Art. 6(1)(a) GDPR and § 25 TDDDG (explicit consent) |
5. Cloud AI of your choice: Mistral AI (EU)
When you choose to interact with the assistant using Mistral AI, your query and relevant document excerpts are transmitted to our third-party processing provider:
- Provider: Mistral AI SAS, 15 rue des Halles, 75001 Paris, France.
- Purpose: Processing natural-language chat queries, document explanations, and formal German draft correspondence.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract / service requested by user) and Art. 6(1)(a) GDPR (explicit consent when selecting the cloud AI model).
- Data handling and retention: Data transmitted via the commercial API is processed on servers located within the European Union. The provider maintains temporary operational logs solely for automated security and abuse prevention in accordance with its commercial Data Processing Addendum (currently up to 30 rolling days), after which they are deleted.
- No model training: Our commercial API agreement contractually prohibits the provider from using your queries or document excerpts to train AI models.
- Further information: The provider's Data Processing Addendum is the authoritative source for its current security measures and sub-processing details: Mistral AI Privacy Policy and Mistral AI Data Processing Addendum.
6. Cloud AI of your choice: Google Gemini (global / USA)
When you choose to interact with the assistant using Google Gemini, your query and relevant document excerpts are transmitted to Google:
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for EEA users; parent entity: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
- Purpose: Processing natural-language chat queries, document explanations, and formal German draft correspondence.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract / service requested by user) and Art. 6(1)(a) GDPR (explicit consent when selecting the cloud AI model).
- Data handling and retention: We access the Gemini API via Google's commercial Paid Services tier. Prompts and responses are logged transiently for a limited period solely for system integrity and abuse prevention, as described in Google's Paid Services terms.
- No model training: Our commercial agreement contractually prohibits Google from using your prompts or generated responses to train Google AI models, and human reviewers do not read submissions.
- International data transfers: Processing may take place on Google infrastructure globally, including in the United States. Data transfers to the USA are safeguarded under the EU-U.S. Data Privacy Framework (DPF) and Google's Standard Contractual Clauses (SCCs).
- Further information: Google's terms are the authoritative source for its current security measures and sub-processing details: Gemini API Additional Terms of Service, Google Cloud Data Processing Addendum, and Google Privacy Policy.
7. Backend and cloud infrastructure (EU)
Our app uses cloud infrastructure hosted within the European Union to manage authentication, entitlement quotas, and service availability:
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- Purpose: Relaying API requests, managing subscription status and credit balances, and preventing service abuse.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract).
- Zero document and prompt storage: Backend request processing is designed to be stateless. Document scans, recognised text, and chat conversations remain stored locally on your device and are not stored in our backend databases. Operational diagnostic logs record only high-level technical telemetry (such as token counts and latency metrics). Prompts, document contents, and personal message text are excluded from operational server logs.
- Administrative data stored: Persistent records are strictly limited to non-content administrative data: remaining credit balances, active subscription status, purchase validation tokens, and temporary rate-limiting counters. All records are associated only with pseudonymised account identifiers.
- Right to erasure (Art. 17 GDPR): You can request full account deletion directly within the app at any time. This permanently deletes your associated account records and entitlement balances, subject to any statutory retention requirements under applicable law.
- Governing agreement: Google Cloud Data Processing Addendum.
8. Optional app analytics (opt-in only)
To monitor app stability and improve user experience, the app includes optional analytics:
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- Purpose: Technical diagnostics, crash reporting, and aggregated feature usage trends.
- Legal basis: Art. 6(1)(a) GDPR and § 25 TDDDG (explicit opt-in consent).
- Strict opt-in by default: Analytics collection is completely disabled by default upon app installation. No telemetry is gathered or transmitted unless you explicitly grant permission.
- Privacy safeguards: IP addresses are masked or discarded at ingestion and are not stored. Only generic aggregated actions (such as screen views or button taps) are recorded. The app is designed not to collect or transmit document contents, recipient names, or case reference numbers (Aktenzeichen) to analytics services.
- Consent revocation: You can enable or disable analytics at any time in the app settings.
9. In-app purchase verification
For managing in-app subscriptions and credit purchases made through the Apple App Store:
- Provider: RevenueCat, Inc., 680 Green St, San Francisco, CA 94133, USA.
- Purpose: Verifying purchase receipts, validating active subscriptions, and restoring purchases.
- Legal basis: Art. 6(1)(b) GDPR (performance of contract).
- Data transmitted: Pseudonymous App Store transaction identifiers, purchase timestamps, and subscription product IDs. Document content, letter text, and chat queries are not shared with RevenueCat.
- Governing terms: Covered under RevenueCat's Data Processing Agreement incorporating Standard Contractual Clauses (SCCs).
10. Data on this website
This website is a static information page. We do not run analytics, tracking pixels, advertising, or third-party cookies here, and we load no remote fonts or scripts.
- Local preferences only. Your language, theme, and zoom choices are stored in your browser's local storage on your own device. They are never transmitted to us.
- Server logs. Our hosting provider necessarily processes technical connection data (such as IP address, date and time, and requested URL) to deliver the pages securely. This processing is based on Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning website).
11. Your rights
Under the GDPR you have the following rights concerning your personal data:
- Access (Art. 15) — confirmation of whether we process your data, and a copy of it.
- Rectification (Art. 16) — correction of inaccurate data.
- Erasure (Art. 17) — deletion, including full account deletion inside the app.
- Restriction (Art. 18) — limited processing in certain circumstances.
- Data portability (Art. 20) — receiving your data in a portable format.
- Objection (Art. 21) — objecting to processing based on legitimate interests.
- Withdrawal of consent (Art. 7(3)) — withdrawing opt-in consent (for example for analytics) at any time with future effect.
To exercise any of these rights, contact us at [email protected]. We respond within one month as required by Art. 12(3) GDPR.
12. Supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in particular in the EU member state of your residence, your workplace, or the place of the alleged infringement. A list of EU supervisory authorities is published by the European Data Protection Board at edpb.europa.eu.
13. Children
NaKlar is not directed at children under 16, and we do not knowingly process personal data of children under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.
14. Security and retention
- Security. All network connections use TLS encryption. Backend access follows the least-privilege principle, and document content is excluded from server logs by design.
- Retention. We keep personal data only as long as necessary for the purposes above: account records persist while your account exists and are deleted when you delete it; provider-side retention (for example Mistral's abuse-monitoring window) is governed by each provider's terms linked above. Statutory retention obligations (for example tax law) remain unaffected.
15. Changes to this policy
We may update this policy when our processing or the law changes. The current version is always published at this address with its effective date. If a change materially affects your rights, we will notify you in the app before it takes effect.
16. Contact
Questions about this policy or your data? Reach us at [email protected].