MedFlashBack to home

Privacy Policy

What we collect, why we collect it, and how we handle your data.

Last updated · 21 May 2026

1. Data we collect

  • Account details — name, username, email, the university you select at signup, an optional profile picture, and (hashed) password (handled by Supabase Auth).
  • Study data — the cards you review, the tests you take, your ratings, streak, and dynamic deck entries. These power the spaced-repetition engine and your dashboard.
  • Purchases — order IDs, line items, redeem codes used, and PayHere’s payment status callbacks. Card numbers are never seen by us; they go directly to PayHere.
  • Technical data — error reports (via Sentry), basic analytics on which features are used, and standard server logs (IP, user agent, timestamp).
  • Things you send us — messages submitted via the Contact or Feedback pages.

2. How we use it

  • Run your account and the spaced-repetition algorithm.
  • Process purchases and grant module access.
  • Detect abuse, debug errors, and improve the product.
  • Reply to support requests and feedback.
  • Send essential service emails (password resets, payment confirmations). We do not send marketing emails.

3. We do not sell your data

MedFlash does not sell, rent, or trade your personal information to anyone. We do not run advertising, we do not share your email or study activity with third-party marketers, and we do not pass your data to data brokers. The only sharing that happens is with the infrastructure providers listed in section 4 — and only the minimum data each of them needs to operate.

We may disclose information only when:

  • an infrastructure provider needs it to operate the service (database, hosting, payments; listed below);
  • we are legally required to (a valid court order or formal request from a Sri Lankan authority);
  • we need to investigate fraud, abuse, or a credible security threat against you, us, or other users.

4. Where your data lives

MedFlash runs on third-party infrastructure. By using the service you accept that data is shared with these providers under their own terms:

  • Supabase — database, auth, file storage (avatars, question images).
  • Vercel — hosting and serverless functions.
  • PayHere — payment processing. Card numbers are never seen or stored by us.
  • Sentry — error reporting (sampled, with IPs scrubbed where possible).

5. Data security

Account passwords are hashed by Supabase Auth (bcrypt) — we never see them in plain text. All connections to medflash.org use HTTPS. Card details go directly from your browser to PayHere over their secure checkout and never touch our servers. Administrative access to the database is restricted by role-based RLS policies and per-table audit trails.

No system is perfectly secure. If you suspect your account has been compromised, change your password immediately and email support@medflash.org.

6. Content protection

The MedFlash study app applies basic deterrents against bulk screenshots and copying. These do not collect any extra data about you — they simply blur the screen when the window loses focus and intercept common copy/print shortcuts to protect our content.

7. Cookies & local storage

We use the browser’s local storage to remember your session, your theme choice, and a small offline cache of your study data so the app works without a connection. We do not use third-party advertising cookies.

8. Your rights

You can, at any time:

  • view and edit your name, username, and email in Settings;
  • export your study data on request;
  • delete your account from Settings, which removes your profile, study data, bookmarks, and entitlements. Payment records are retained for legal/accounting purposes (anonymised after deletion).

9. Retention

Study data is retained for as long as your account exists. Payment records are retained for at least 7 years to comply with Sri Lankan tax and accounting requirements. Submitted contact and feedback messages are retained for up to 24 months unless deletion is requested.

10. Children

MedFlash is not intended for users under 16. If you believe a child under 16 has created an account, email us and we will delete it.

11. Changes & contact

We may update this policy as the service evolves. Material changes will be flagged in-app. For any privacy questions or data-access requests, email support@medflash.org.