Privacy Policy

Last updated: 17 September 2026

This policy explains what Med Guru collects, why, and what you can do about it. The data controller is Med Guru, contactable at support@med-guru.com.

We do not sell your data, we do not use advertising trackers, and we do not use your study content to train AI models. Usage analytics are pseudonymous — a first-party identifier, never your email or name. We record how the interface is used to find and fix problems, but everything you type and all study content is masked before it leaves your browser.

What we collect

  • Account details — your name, email address, and a password stored only as a salted hash (we never see your password).
  • Study content — your conversations, questions asked, practice answers, written reasoning, bookmarks, course progress, and the results generated for you.
  • Usage and billing records — which AI features you used, the computed cost of each call (used to enforce your budget), your subscription status and periods, and a record of payments received (amount, currency, and the payment provider’s transaction reference).
  • Technical data — server logs containing IP address, timestamps, and request details, kept for security and debugging.
  • Usage analytics — which pages are viewed, which features are used, interface interactions (clicks and taps), performance measurements, and session recordings of how the interface is used. In recordings, everything you type and the content of your questions, answers, and study material is masked before it leaves your browser — we see the shape of a session, not your words. All of it is tied to a pseudonymous account identifier plus your role and subscription tier, never to your email or name.
  • Error reports — when something breaks, we receive the technical error: what failed, on which page or endpoint, and in which browser. Never the content of the request.

We do not collect health data about you or anyone else, and you should not enter real patient information into the Service.

Why we use it, and on what basis

  • To provide the Service you asked for — answering your questions, storing your history, tracking course progress (performance of our contract with you).
  • To meter usage against your budget, take payment, and prevent abuse (performance of contract, and our legitimate interest in running the Service sustainably).
  • To keep the Service secure and diagnose faults (legitimate interest).
  • To send you reminders and offers about the Service by email — study nudges, what your plan includes, when a trial or offer is ending (our legitimate interest in telling our own account holders about the product they signed up for). Every such email carries a one-click unsubscribe link, and there is a switch for it on your account page. Service messages — login codes, receipts, and notices about your subscription — are not marketing and are sent as part of our contract with you.
  • To understand how the Service is doing — sign-ups, subscriptions, revenue and study activity — from statistics about groups of students (legitimate interest).
  • To meet accounting and tax obligations (legal obligation).

Who we share it with

We use a small number of processors, and only what they need:

  • Google (Gemini API) — receives the text of your questions and the retrieved study passages in order to generate answers. Google processes this as our provider under its API terms, which state that it is not used to train its models.
  • Paddle — our payment processor and merchant of record. When you buy a subscription you deal with Paddle directly: it collects your payment and billing details under its own privacy policy, and returns to us only a customer reference, transaction id, amount, and status. Your card details never reach our servers.
  • Our hosting — the database and file storage that run the Service, which we operate ourselves on rented infrastructure.
  • PostHog — our product-analytics and monitoring provider, hosted in the EU. It receives usage events, masked session recordings, performance measurements, and error reports tagged with a pseudonymous identifier so we can see what is used, what is confusing, and what is broken. It never receives the content of your questions or answers, your email, or your name.
  • Resend — our email delivery provider. It receives your email address and the content of the emails we send you — verification codes, receipts, reminders — and returns whether each one was delivered. It never receives your study content.
  • Anthropic (Claude) — used by the Med Guru team to analyse how the Service is doing. It receives statistics computed from our database about groups of students — counts, totals and rates such as sign-ups, subscriptions, revenue and study activity — which, while the Service is small, can describe only a few people. For partners in our creator programme it also receives their partner code with the sign-ups, revenue and commission attributed to it. It never receives your name, your email address, the text of your questions or answers, or your card or billing details.

Apart from the providers listed above, we do not share your data with anyone else, except where the law requires it or to establish or defend legal claims. Because these providers operate internationally, your data may be processed outside your country; where required, transfers rely on the providers’ standard contractual clauses.

Cookies and local storage

Med Guru stores two things in your browser: a strictly-necessary httpOnly session cookie that keeps you signed in, and a first-party analytics identifier (in local storage and a cookie) that lets our analytics tell visits apart. The analytics identifier is set by us for our own product analytics only — there are no advertising or cross-site tracking cookies, and nothing follows you to other sites. If you would like it removed, clearing your browser data for med-guru.com deletes it, or email us and we will exclude your account. Paddle’s checkout may set its own cookies when you make a purchase, governed by Paddle’s policy.

How long we keep it

  • Account and study content: until you delete your account, or ask us to delete it.
  • Payment records: as long as accounting and tax law requires, typically several years, even after account deletion.
  • Server logs: a short rolling window for security and debugging.
  • A record of which emails we sent you and whether they were delivered: for as long as you have an account.
  • Analytics events and error reports: a limited period on our analytics provider; session recordings are automatically deleted after roughly a month.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or provide it in a portable form. Email support@med-guru.com and we will respond within 30 days. You can object to our reminder and offer emails at any time without writing to us: use the unsubscribe link in any of them, or the switch on your account page. Deleting your account removes your study content and personal details; it does not remove payment records we must retain by law. If you are in the EU/UK and believe we have mishandled your data, you may also complain to your local data protection authority.

Security

Passwords are stored hashed, sessions use httpOnly cookies, access to study material requires an authenticated request, and administrative functions are restricted to administrator accounts. No system is perfectly secure; if a breach affects your data, we will notify you and any regulator as required.

Children

The Service is intended for medical students and professionals and is not directed at children. We do not knowingly collect data from anyone under 16; if you believe a child has given us data, contact us and we will delete it.

Changes

If this policy changes materially we will notify you by email or in the app before the change takes effect.