MEDICOREX

Privacy Policy

Last updated: 2026-01-01

This Privacy Policy describes how MEDICOREX ("we", "us") collects, uses, and shares information about you when you use our Service. We aim to collect the minimum data needed to operate, secure, and improve the platform.

What we collect

  • Account information: email address, name (optional), password (stored as a one-way bcrypt hash), and your selected role.
  • Usage data: test sessions, answers, time per question, flashcard reviews, notes, and highlights you create. This is yours — we use it to power your analytics and improve content quality (in aggregate, not individually).
  • Security logs: sign-in events (IP, browser, time) and audit entries for privileged actions. Used for fraud prevention and account recovery.
  • Payment information: card payments are processed by Stripe. We store a Stripe payment/customer reference and the amount — never your full card number, which Stripe handles on its PCI-compliant systems.

What we don't collect

  • Personal identifiers beyond email (no SSN, government ID, phone unless you provide it).
  • Real-time location, microphone, or camera data.
  • Browsing activity outside MEDICOREX.

How we use your data

  • To provide the Service (your test sessions, your subscription).
  • To send transactional emails (password resets, payment confirmations, expiry reminders).
  • To improve question quality (aggregated, anonymized accuracy stats per question).
  • To prevent abuse (rate limiting, lockouts, fraud detection on payments).

Sharing

We share data only with:

  • Infrastructure providers: our hosting, database, email, and storage vendors. They process data on our behalf under contract and cannot use it for their own purposes.
  • Payment processing: Stripe processes card payments on our behalf and handles your card details directly. We only receive a payment reference and confirmation, never your full card number.
  • Legal compliance: if required by valid legal process. We will notify you where lawful.

We do not sell your data. We do not run third-party advertising trackers.

Cookies

We use first-party cookies for authentication (your sign-in session) and locale preferences. We do not use cookies for advertising. A cookie consent banner is shown to new visitors per applicable law.

Data retention

  • Active accounts: data retained while your account exists.
  • Deleted accounts: data is removed within 30 days of deletion (cascade deletion in our database).
  • Audit and login logs: retained for 90 days for security analysis, then deleted.
  • Payment records: retained for 7 years for tax/accounting compliance.

Your rights

You can:

  • Access and download your data (contact us).
  • Correct inaccurate data via your settings.
  • Delete your account at any time from settings → Danger zone.
  • Object to specific processing, withdraw consent, or request data portability.

Security

We use industry-standard practices: TLS for all connections, bcrypt for password hashing, encrypted 2FA secrets, rate limiting, account lockout, audit logs. No system is perfectly secure — if you believe your account was compromised, contact us immediately.

International transfers

We may process data in countries outside your residence. We use standard contractual clauses or equivalent safeguards.

Children

The Service is not directed at children under 16. We do not knowingly collect data from them. If you believe a child has provided us data, please contact us so we can delete it.

Changes to this Policy

We may update this Policy. Material changes will be communicated by email. The "Last updated" date at the top reflects the current version.

Contact

For privacy questions or data requests, contact us via the support page.

Have questions? Contact us.