Pralia DE

Privacy policy

This policy applies to the website pralia.de and to the Pralia app in its closed beta. The app can only be used with a personal invitation.

This is a courtesy translation. The legally binding version is the German Datenschutzerklärung.

Last updated: 1 August 2026 · Version 2026-08-01

1. Controllers

Controllers within the meaning of the GDPR:

Prakrisht Dahiya and Julia Kampa
c/o YETI Dresden
Leubnitzer Str. 28
01069 Dresden, Germany
Email: prakrisht@pralia.de

No data protection officer has been appointed at this time. Contact details will be added here as soon as the processing reaches the scale at which an appointment becomes mandatory (Art. 37 GDPR, § 38 BDSG).

2. The essentials

Pralia shows you how much care budget you are still entitled to and when it expires. We process as little as possible for that:

  • Your email address and a password — for your account.
  • The care level (Pflegegrad) of the person you care for, and the expenses you log (amount, date, type, optionally a provider).
  • Optionally: the contents of a photographed care-level notice (Pflegebescheid) — processed in memory only; the photo is never stored.

What we do not collect: no name of the person cared for, no postal address, no date of birth, no phone number, no insurance number, no diagnoses.

All data is stored encrypted on servers in Frankfurt am Main. We never sell data and never train AI models on your data. One click in the settings deletes your account completely — including all entries, cached analyses and your login.

3. Health data and your consent (Art. 9 GDPR)

The care level and the contents of a care-level notice are health data — special categories of personal data under Art. 9(1) GDPR. We process them exclusively on the basis of your explicit consent (Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR), which you give at registration. Registration is not possible without it.

You can withdraw this consent at any time by deleting your account in the settings (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before it. Deletion removes all data stored for your account — see section 9.

If you enter data about another person (such as a relative's care level), you may only do so if you are authorised to — for example as their authorised representative.

4. The Pralia app in detail

4.1 Account and sign-in

For your account we process your email address and a password (stored as a hash). Sign-in runs through our processor Supabase (Frankfurt region). Legal basis: Art. 6(1)(b) GDPR. At registration we additionally store the time, wording and version of your consent — as evidence under Art. 7(1) GDPR.

4.2 Care level and entries

You record the care level and your expenses (amount, date of care, type of service, optionally provider, description, status). From this, Pralia computes your remaining budgets and deadlines. The computation happens in our own software; no AI model computes or stores your amounts.

4.3 Notice photo (optional)

You can photograph a care-level notice or upload it as a PDF. The file is processed in memory only, transmitted to our processor Anthropic for text extraction (see section 7), and then discarded — it is never stored on our servers. Only the details you confirm are kept: care level, notice date, name of the care insurance fund. This step is optional; you can enter everything by hand instead.

4.4 Reminder emails

Pralia reminds you by email before budgets or claim deadlines expire. By default these emails contain no amounts, no care level and no benefit names — only the fact that a deadline is approaching, the date, and a link into the app. In the settings you can additionally enable amounts in emails, opt out of individual reminders, or unsubscribe from all reminders with one click. Sending runs through our processor Resend (EU region). Legal basis: Art. 6(1)(b) GDPR; where contents allow inferences about health data (only with amounts enabled), your consent under Art. 9(2)(a) GDPR.

4.5 Abuse protection

At registration we transiently process your IP address to rate-limit automated signup attempts. It is not stored permanently. Legal basis: Art. 6(1)(f) GDPR.

5. The website pralia.de

Server logs: our hosting provider processes technically necessary access data (IP address, time, page requested, user agent) to deliver the site securely (Art. 6(1)(f) GDPR); logs are deleted automatically after a short period. Fonts, scripts, icons are entirely self-hosted — no third-party CDN connections. Cookies: no analytics, tracking or advertising tools; the app uses only technically necessary session cookies, which is why there is no cookie banner. Waitlist and email contact: we process your email address to inform you about the launch (Art. 6(1)(a) GDPR, withdrawable at any time) and enquiry details to answer you, deleting them once no longer needed.

6. What we do not do

7. Processors and transfers

We use the following processors. A data processing agreement under Art. 28 GDPR is in place with each.

ProviderRolePlace of processing
SupabaseDatabase, file storage, authenticationFrankfurt am Main (AWS eu-central-1). Data remains in the EU.
VercelHosting and execution of the applicationExecution in Frankfurt (region fra1). US parent company; any transfers to the USA are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Anthropic PBCText extraction from uploaded noticesUSA. Transfers based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). We process the photo in memory only and never store it; Anthropic does not use the inputs to train models and deletes them within the contractually agreed periods.
ResendSending reminder emailsEU region (Ireland). US parent company; any transfers to the USA are based on the EU Standard Contractual Clauses.

There are no other recipients unless we are legally required to disclose.

8. Security

All data is encrypted in transit (TLS) and at rest. Row-level security restricts every access strictly to your own account; registration requires an invitation code. For transparency: this is not end-to-end encryption — our servers must be able to process the data to compute budgets and send reminders. We claim nothing else anywhere.

9. Retention and deletion

10. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR), and the right to withdraw any consent at any time with effect for the future (Art. 7(3) GDPR). In the app you can export your data yourself at any time (Settings → "Export all data") and delete your account completely. For anything else, an informal email to prakrisht@pralia.de is enough.

11. Right to lodge a complaint

You have the right to complain to a data protection supervisory authority (Art. 77 GDPR) — for instance the Saxon Commissioner for Data Protection and Transparency, Devrientstraße 5, 01067 Dresden, or the authority at your place of residence.

12. Changes

We update this policy when the processing changes. The current version, with its version number, is always at pralia.de/datenschutz. For material changes affecting your consent, we will ask you again.