Privacy Policy

Who we are

Medicine is a free, open-source study tool for medical students, available at medicine.necr.help. Its source code is public at github.com/neccrr/medicine. In this policy "we" means the people who run it.

Using Medicine as a guest

Without an account, your progress (flashcard reviews, quiz and exam results, reading position, study days and settings) is saved only in your browser's local storage on your device. We never receive it. Clearing your browser's site data deletes it; the Progress page lets you export it to a file first.

What we store if you create an account

DataWhy
Name, email address, and (optionally) your cohort or entry yearTo identify your account, and to compare scores within your class if you join the leaderboard
A password hash, if you sign up with email (never the password itself)To check your password when you sign in
If you use Google: your Google account ID, your profile picture link, and the sign-in tokens Google returns (stored encrypted)To sign you in with Google
Sign-in sessions: a random token, when it expires, and the IP address and browser that signed inTo keep you signed in, and to protect your account from abuse
Your study progress (the same data as guest mode, listed above)To sync it between your devices
Short-lived counters of sign-in attempts per IP addressTo slow down password-guessing attacks
If you join the leaderboard: the display name you choose, and scores worked out from your progressTo show the leaderboard

We use one cookie, which keeps you signed in. It is strictly necessary and isn't used for anything else.

Google sign-in

If you sign in with Google, we ask Google only for your basic profile: your name, email address and profile picture (the openid, email and profile permissions). We don't request or have access to your Gmail, Drive, contacts, calendar or any other Google data. We use what Google sends only to create and sign in to your Medicine account.

Medicine's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google user data for advertising, don't sell it, and don't transfer it to anyone except as needed to run the service (below) or as required by law.

Who else can see your data

We don't use analytics, advertising or tracking services.

How long we keep it

Your choices and rights

Depending on where you live, you may have further rights over your personal data, such as objecting to processing or complaining to a data protection authority. Contact us to use them.

Security

Connections to Medicine are encrypted (HTTPS). Passwords are stored only as salted hashes, Google sign-in tokens are encrypted, and each user's data can only be read with their own signed-in session. No system is perfectly secure, so please use a password you don't use anywhere else.

Children

Medicine is made for university students. It isn't directed at children under 13, and we don't knowingly collect their data.

Changes

If we change this policy, we'll update the date at the top. For significant changes we'll also show a notice in the app.

Contact

Questions or requests about your data: open an issue at github.com/neccrr/medicine/issues. Please don't include personal details in a public issue; ask for a private contact and we'll reply.