Privacy Policy

Last updated: [date] · Draft — see the note at the bottom before relying on this page.

This page explains what information Memorize Medicine (the "Platform", operated by [legal entity name]) collects, why, and what a student can do about it.

1. What we collect

Only what the Platform actually needs to run — no data broker feeds, no ad tracking. Specifically:

CategoryExamplesWhy
Account detailsFull name, email, phone number, passwordSign-in, identifying your enrollment
Payment recordsThe receipt image you upload, transfer number, payment method, amountVerifying a payment and enrolling you — we do not process card numbers ourselves
Study activityLectures watched, quiz/qbank answers, flashcard reviews, study plan progressYour progress bars, spaced-repetition scheduling, "behind schedule" alerts
Your own notesNotes and highlighted passages you save on a lecture or questionShown back to you, and included if you export your notes
MessagesMessages to tutors/support, announcements you've readCourse-related communication
Device & notificationsA device identifier, if you turn on push notificationsDelivering payment/enrollment/message alerts to your phone

2. What we don't do

3. Who can see it

Your account and study data are visible to you and to Memorize staff (support/admin) who need it to verify payments or help with an issue. A tutor can see messages you send them and, in aggregate, how students in their course are doing — not your private notes. Question and flashcard content you study is licensed from the Platform, not shared with other students.

4. How long we keep it

[Fill in: how long you retain an account after it goes inactive, and how long payment receipt images/records are kept — many countries have a minimum retention period for financial records, so check local law before setting this short.]

5. Your choices

6. Security

Passwords are never stored in plain text. Access to student data is restricted to staff roles that need it (support, admin) — a tutor account cannot browse other students' payment records.

7. Contact

Questions about this policy, or a request to see/delete your data: [support contact].

8. Changes to this policy

If this policy changes in a way that matters (what we collect, who sees it), we'll flag it on this page.

Note for the owner: this draft lists only what the Platform's own code actually collects and stores today (see schema.sql) — it doesn't invent categories. The highlighted fields (entity name, retention period, support contact) and the retention question in particular need your input, and if you plan to serve students outside your home country, a lawyer should confirm whether GDPR, a similar regional law, or specific medical-data rules apply before this is relied on as a binding policy.
© 2026 Memorize Medicine. All rights reserved.