Back to home

Privacy Policy

Effective 23 Sep 2026 v1.2

This page explains what information MedPal collects when you use our mobile app and admin services, why we collect it, and the choices you have.

At a glance

  • We collect: your account details (email, name), your learning activity (courses, quizzes, progress), and — only if you add one — a profile picture.
  • We never see your card number. Purchases in the iOS app are handled by Apple; purchases on our website are handled by Paymob. MedPal's own servers don't touch or store your card details.
  • We don't sell your data, and we don't use advertising, ad-tracking or third-party analytics. We only count, ourselves, which days students use the app, to see how many are active.
  • You can delete your account and data at any time — see "Your choices" below.

01 Who we are

MedPal is a mobile app and companion admin platform for medical students, offering recorded lectures, a question bank, and practice quizzes. This policy covers the MedPal mobile app (Android and iOS) and the services behind it. It does not cover other apps or websites you may reach through links inside MedPal.

02 What we collect

We collect only what's needed to run your account, deliver course content, and keep the service secure.

Account information

  • Your name and email address, used to create and identify your account.
  • Your password — hashed by our authentication provider (Firebase Authentication) before storage; MedPal never sees or stores your password in plain text.
  • A phone number, only if you use phone-based verification during account recovery.

Content you add

  • A profile picture, if you choose to upload one — requires your permission to access your camera or photo library.

Learning activity

  • Which courses and lectures you view, and your progress through them.
  • Your quiz and question-bank results, so you can track your own progress over time.
  • Whether you're currently online, when you were last active, and which days you used the app — used to show our team how many students are active each day and week.

Subscription & payment

  • Which plan or course you've purchased, and its status (active, expired).
  • Purchases made in the iOS app are processed by Apple through the App Store, under Apple's own terms and privacy policy. Apple sends us a signed record of the purchase — the product, the purchase date, a transaction identifier, and whether it was later refunded — together with an anonymous account token we create so the purchase is linked to your MedPal account. Apple does not share your name, Apple ID, or payment details with us.
  • Purchases made on our website are processed by Paymob, our payment provider — MedPal's servers never receive or store your full card number.

Device & security signals

  • A random device identifier that the app creates on first launch and keeps in your device's secure storage. It is linked to your account so it can be used on one device at a time. It is not your phone's advertising identifier and is not shared with anyone.
  • Security events linked to your account: attempts to take a screenshot or screen recording of a lecture, and sign-in attempts from a device other than your registered one.
  • A short-lived device attestation token (via Google Play Integrity, Apple App Attest, or reCAPTCHA on the web dashboard) used to confirm requests come from a genuine copy of the app — not to identify or track you personally.

03 How we use it

  • To create and maintain your account, and let you sign in securely.
  • To deliver the lectures, quizzes, and content your subscription entitles you to.
  • To process payments and keep your subscription status accurate.
  • To send you account-related messages — verification codes, password resets, and service notices — via our email provider, Brevo.
  • To detect and prevent abuse, such as automated bot sign-ups or credential-stuffing attacks, account sharing across devices, and screenshots or recordings of course content.
  • To count how many students are active each day and week, for our own dashboard.

We do not use your information for advertising, and we do not build an advertising profile of you.

04 Who we share it with

We don't sell your personal information. We share it only with the service providers that help us run MedPal, each strictly for the purpose below:

ProviderWhat they handleWhy
Firebase (Google)Account sign-in, your profile and progress data, uploaded profile picturesCore authentication and data storage
MuxVideo streaming for lecturesHosts and securely delivers course video
Apple (App Store)Payment for purchases made in the iOS app; sends us a signed purchase recordProcesses in-app purchases and refunds on iOS
PaymobPayment card details, transaction dataProcesses payments made on our website
BrevoYour email addressSends verification codes and account emails
RenderEncrypted data in transit to our backendHosts our application server

We may also disclose information if required by law, or to protect the rights, safety, and security of MedPal, our users, or the public.

05 How we protect it

  • All traffic between the app and our servers is encrypted (HTTPS), and the mobile app additionally verifies our server's certificate directly (certificate pinning) to guard against interception.
  • Passwords are never stored in plain text — they're hashed by Firebase Authentication.
  • One-time verification codes are stored as cryptographic hashes, never in plain text.
  • Access to your data is restricted by rule-based permissions — you can only read or modify your own records, and administrative access is separately authenticated and logged.
  • Sign-in and password-reset requests are rate-limited to slow down automated attacks.

No system is perfectly secure, but we apply layered, industry-standard practices throughout MedPal.

06 How long we keep it

We keep your account and learning-activity data for as long as your account is active, so your course history and progress stay available to you. If you delete your account, we delete or anonymize your personal data within a reasonable period, except where we're required to retain certain records (for example, payment records) to meet legal or accounting obligations. In particular, we keep the record of each App Store purchase after an account is deleted — the product, dates, transaction identifier, refund status and an internal account identifier, but not your name or email — so that a purchase can be refunded or supported correctly and cannot be claimed by a different account.

07 Your choices

  • Access or update your information anytime from your profile inside the app.
  • Delete your account — open Profile → Delete My Account in the app to permanently delete your account and data immediately (apart from the purchase records described in "How long we keep it"). If you can't access your account, email us at the address below instead and we'll complete the deletion within 30 days.
  • Ask us what we hold about you, or correct inaccurate information, by contacting us the same way.

08 Age requirement

MedPal is intended for medical students and is not directed at children. You must be at least 16 years old to create an account. If you believe a child has provided us with personal information, please contact us and we will delete it.

09 Changes to this policy

We may update this policy as MedPal evolves. If we make material changes, we'll update the effective date above and, where appropriate, notify you in the app. We encourage you to review this page occasionally.

10 Contact us

Questions about this policy, or a request to access or delete your data, can be sent to:

Email Medpalapp13@gmail.com
Response time Within 1-2 days