Dra Lia legal

Privacy Policy

Canonical URL: https://dralia.app/privacy

Effective date: May 13, 2026

Version: 1.0

This Privacy Policy explains how Dra Lia collects, uses, stores, shares, and deletes information when you use the app, website, API-backed features, support channels, and related services.

1. Scope

Dra Lia helps users upload laboratory exam PDFs and view structured information extracted from those documents. Because laboratory exams can contain health-adjacent and identifying information, we treat uploaded documents and extracted exam data as sensitive product data.

2. Information We Collect

Depending on which features you use, we may collect:

3. How We Use Information

We use information to:

4. Automated Processing and AI Providers

Dra Lia may process uploaded documents using automated services, including language model or extraction providers such as OpenAI. We send document content and related processing context only as needed to extract exam information, classify documents, validate coverage, and return structured results. Automated extraction may be incomplete or inaccurate; users should verify information against the original laboratory report and professional medical guidance.

5. Storage and Security

Product data may be stored in PostgreSQL databases, object storage such as Cloudflare R2, and backend infrastructure such as Railway. We use access controls, authenticated API requests, resource-based authorization, and operational safeguards so users can access only their own documents and exam data through normal product flows.

No internet service can guarantee absolute security. You are responsible for keeping your devices, email account, and sign-in credentials secure.

6. Telemetry, Logs, and Analytics

Dra Lia may collect operational telemetry and logs to keep the service reliable. This can include crash reports, non-fatal error diagnostics, release metadata, environment tags, API status, timing, and redacted troubleshooting context. Crash and reliability tooling may include Firebase Crashlytics and Sentry where configured.

Product analytics may be used to understand feature adoption and core funnels, such as sign-in, upload started, upload completed, or exam viewed. Analytics events must not include raw PDF contents, OCR text, lab names, document titles, storage keys, national identifiers, bearer tokens, full email addresses, or other unnecessary sensitive fields. Where product analytics are enabled, users may have an opt-out control in Settings, subject to platform requirements and vendor limitations.

7. Push Notifications and Email

If enabled, Dra Lia may use push notifications to tell you about relevant product events, such as document processing completion or failure. Notification bodies should avoid sensitive document details unless a later policy and product decision explicitly allow them. Transactional email may be sent through server-side email providers such as Resend for account, diagnostic, or support flows.

8. Support Chat and Feedback

Help & Support may use a chat provider such as Crisp. If you contact support, your message, contact information, account context, and safe device/app metadata may be processed so the support team can respond. Do not send unnecessary sensitive medical content through support chat unless support specifically requests it for your case.

9. Sharing With Service Providers

We may share information with service providers that help us operate Dra Lia, including authentication, hosting, database, object storage, AI processing, observability, analytics, email, push notification, app-store, and support providers. These providers process information on our behalf or under their own applicable terms. We do not sell personal information.

10. Legal, Safety, and Abuse

We may access, preserve, or disclose information if reasonably necessary to comply with law, enforce the Terms of Service, protect users, investigate abuse or security incidents, prevent fraud, or maintain service integrity.

11. Retention

We keep account, document, extracted exam, support, log, and analytics information for as long as needed to provide the service, meet security and operational needs, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods can vary by data category and provider.

12. Account Deletion

When account deletion is completed, Dra Lia is designed to remove or irreversibly sever your product identity and user-owned domain data from primary product systems, including documents, extracted exam data, and related storage objects where applicable. Some information may remain for a limited time in backups, security logs, provider logs, fraud-prevention records, or records we must keep for legal reasons.

13. Your Choices

Depending on product availability and platform rules, you may be able to:

14. Children

Dra Lia is not intended for children. Do not create an account or upload information for a child unless you have the legal authority to do so and the product supports that use case in your region.

15. International Processing

Dra Lia and its service providers may process and store information in countries other than your own. Data-protection rules may differ by location. We apply the safeguards described in this Policy and any additional measures required for the markets where Dra Lia is offered.

16. Changes to This Policy

We may update this Privacy Policy when the product, data practices, providers, or legal requirements change. The effective date and version on this page identify the current version. Material changes may be surfaced in the app, at sign-in, or by another reasonable notice method.

17. Contact

For privacy questions, contact us through Help & Support in the app or by email at support@dralia.app.

Related Policy

Read the Terms of Service for the conditions that govern use of Dra Lia.