Skip to content
MeinHelfer
Menu

Privacy Policy

Draft – not yet legally reviewed. Highlighted parts are still to be added. This English text is a convenience translation. The German version is binding. Status: draft of 1 October 2026

This policy explains which personal data MeinHelfer processes, for what purpose, on which legal basis and for how long. It applies to the website meinhelfer.app, the web app and the apps for iOS and Android.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Pratiush Sharma

Email: info@meinhelfer.app

We have not appointed a data protection officer because we are not required to (Art. 37 GDPR, § 38 BDSG).

2. The essentials

MeinHelfer explains letters from authorities, insurers and other organisations, keeps track of deadlines and drafts replies that you approve yourself. To do this we have to process your letters.

We show no ads, sell no data and build no profiles for advertising. We use no tracking services.

Your data is kept in data centres in the EU. Some service providers are based in the USA; special safeguards apply to them (section 17).

3. Website meinhelfer.app

The website sets no cookies, uses no tracking and loads no content from other providers. We serve fonts and images ourselves.

The website runs on a server of Hetzner Online GmbH in Germany. When you visit it, the server processes your IP address and technical details of your browser, because it cannot deliver the page otherwise. The website’s web server writes no access logs. [to be added: whether and for how long the upstream proxy keeps logs]

The legal basis is our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR).

4. Name resolution (DNS)

Name resolution for meinhelfer.app is handled by Cloudflare, Inc. (USA). Cloudflare only answers the question of which address our server can be reached at. The page request itself does not go through Cloudflare but directly to our server in Germany.

The legal basis is our legitimate interest in reliable availability (Art. 6(1)(f) GDPR).

5. Account and sign-in

For an account we need your email address. You sign in with a code we send you by email. We also store your language setting, your name (if you give it), your acceptance of the terms and this policy with date and version, and technical sign-in details (times, sessions).

Supabase, Inc. runs the account, database, file storage and server functions for us as a processor. Our project is located in the Frankfurt am Main region (EU). Some server functions may run in the Supabase data centre nearest to you; we therefore do not claim that all processing takes place in Germany.

The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).

6. Your letters and documents

You can upload photos and PDF files of letters or forward letters by email to your personal MeinHelfer address. We store the files and what we recognise in them: sender, content, amounts, deadlines, reference numbers, translations, tasks and reply drafts.

Forwarded emails are received by our own mail server on our server in Germany.

Such letters may also contain information about other people, for example family members. We process it only to explain the letter to you.

The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR); for information about other people, our and your legitimate interest in understanding and dealing with your own mail (Art. 6(1)(f) GDPR).

7. Explanation by artificial intelligence

To read a letter (text recognition) and explain it, we send the photo or PDF file and the recognised text to TensorX Ltd., Dublin, Ireland. TensorX processes the data as a processor exclusively in data centres in the EU (Helsinki and Dublin), does not store requests or responses and does not use them to train AI models. The data processing agreement is part of TensorX’s terms.

The same applies to questions you ask the assistant in the app: for this we send your question and relevant details from your household’s letters to TensorX.

The AI makes no decisions about you. It produces explanations and suggestions; you decide what happens with them. No automated decision-making within the meaning of Art. 22 GDPR takes place.

The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).

8. Health data

Letters from a health insurer, for example, may contain health data. This is a special category of personal data. We store and show the content of such letters only if you have given your explicit consent beforehand (Art. 9(2)(a) GDPR).

How it works: before you upload your first letter, we ask you once whether you consent to the processing of health data. No letter is sent to the AI before that.

If you do not consent, we ask on every upload whether the letter contains health data (for example from a health insurer or a doctor). Letters you mark this way are not sent to the AI; only the uploaded file stays stored until you consent or delete it. Letters you forward by e-mail are read without consent only after you have confirmed in the app that they contain no health data.

If the AI still finds health data in a letter you marked as not health-related, processing stops: everything read from it is deleted until you consent or delete the letter.

Health letters of other household members are not shown to you and are not given to the assistant.

You can withdraw your consent at any time in the settings. We then delete all health letters you uploaded, together with everything derived from them. Processing up to the withdrawal remains lawful.

9. Deadlines, reminders and emails

We remind you of deadlines and send you sign-in codes and household invitations by email. We send the emails through our own mail server on our server in Germany (Hetzner Online GmbH as hosting provider); this processes your email address and the content of the email.

On your phone we can send you notifications (push) if you allow this on your device. For this we use the Apple or Google services through which your device receives notifications. [to be added: please confirm which push service is used]

The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR). We do not send marketing emails.

10. Reply drafts and PDF files

We create reply drafts as PDF files. This is done by our own service on our server in Germany; no data is given to other providers.

We send nothing on your behalf and pay nothing without your prior approval.

11. Household and shared use

You can invite other people into your household. Members of a household see the shared letters, deadlines and tasks – except other members’ health letters. For an invitation we process the invited person’s email address.

The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).

12. Plan and price choices in the app

When you are signed in, we record which plans and prices you look at and choose inside the app (for example the plans page, the monthly or yearly option, and what you do when an allowance runs out), together with your household, the time and whether you used the web version, the iOS app or the Android app. This is stored only in our own database: we set no cookies for it, store nothing on your device and never share it with anyone. We use it only to set fair prices. The records are deleted automatically after about 13 months. The legal basis is our legitimate interest in fair, sustainable prices (Art. 6(1)(f) GDPR). You can object to this at any time (Art. 21 GDPR).

13. Error reports

Only if you agree do we send technical error reports to Sentry (Functional Software, Inc., USA), to their servers in the EU (Frankfurt am Main). An error report contains, for example, the error message, the affected place in the program, device, operating system and app version. Before sending, we remove the content of your letters and personal details such as your name or email address.

The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw it at any time in the settings. Sentry deletes error reports after [to be added: retention period under the Sentry plan, e.g. 90 days].

14. Cookies and storage on your device

The website sets no cookies.

The web app only uses technically necessary cookies: for your sign-in (session), your language (mh_lang) and demo mode (mh_demo). The apps store your sign-in and settings on your device. No consent is needed for this because this storage is strictly necessary for you to use the service (§ 25(2) no. 2 TDDDG).

15. Bank connection (not active at present)

This feature is not active at present. When we introduce it, the following applies:

You can choose to connect your bank account so that MeinHelfer recognises payments relating to your letters. Access is read-only and runs through a licensed account information service provider: [to be added: provider, registered office, licence]. You enter your online banking credentials only with this provider; we never receive them. We receive the balance and transactions of the accounts you release. We cannot initiate transfers with it.

The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR). You can disconnect at any time; the release must also be renewed with your bank regularly.

16. Payments (not active at present)

There are no paid plans yet. Once there are, we will add here which payment provider (or Apple or Google for purchases in the apps) receives which data. [to be added: payment provider]

17. Recipients and transfers outside the EU

We only give data to the following service providers, which process it on our behalf and according to our instructions (Art. 28 GDPR):

– Hetzner Online GmbH, Germany: servers for website, web app, PDF service and backups

– Supabase, Inc., USA: database, sign-in, file storage and server functions; project region Frankfurt am Main

– TensorX Ltd., Ireland: text recognition and AI explanation; processing in the EU only

– Functional Software, Inc. (Sentry), USA: error reports, only with consent; servers in the EU

– Cloudflare, Inc., USA: name resolution (DNS)

For providers based in the USA it cannot be ruled out that data is transferred to the USA or accessible from there. We have agreed the European Commission’s standard contractual clauses with them (Art. 46(2)(c) GDPR). [to be added: whether each provider is also certified under the EU-US Data Privacy Framework (Art. 45 GDPR)]

Authorities and other bodies receive data only if we are legally obliged to provide it.

18. Storage period

We keep your letters and everything belonging to them until you delete them or delete your account.

We back up the database and files every night on our server in Germany. Each backup is deleted after 14 days. Deleted data may therefore remain in a backup for up to 14 days.

Plan and price choices are deleted after about 13 months (section 12).

Where we are legally required to retain data, for example invoices under commercial and tax law, we keep it for as long as required (Art. 6(1)(c) GDPR).

19. Deleting your account and taking your data with you

You can delete your account yourself at any time in the settings. You then have 14 days to change your mind. After that, we delete your account and your data.

You can download your data as a file (JSON format) at any time. The download link is valid for one hour; we delete the file itself after 7 days.

20. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR).

Right to object: where we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation.

You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR).

Just write to us at the email address above.

21. Complaint to a supervisory authority

You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example in the country where you live. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart.

22. Obligation to provide data

You are not obliged to give us data. Without an email address, however, we cannot create an account for you, and without a letter we cannot explain it to you.

23. Changes

When something about MeinHelfer changes, we update this policy. We will inform you about significant changes in the app.