Privacy Policy
Last updated: September 9, 2026
This policy explains what Yanga Med QBank ("Yanga", "we") collects, why, who processes it, and the choices you have. It applies to the web app and the installable (PWA) version. The short version: we collect what the study tools need, we do not sell it, we do not run advertising trackers, and you can export or delete everything from Settings.
1. Who is responsible and how to reach us
Yanga Med QBank is the data controller for your information. For any privacy question or request, email kalangedavies@gmail.com. We answer within 30 days.
2. Information we collect
- Account: email address, a password (stored only as a bcrypt hash), an optional display name, your time zone, your study level (e.g. MS1), an optional @handle for the classmate directory, and the dates you accepted these policies.
- Study content you provide: study materials (pasted text or PDFs), lecture-schedule files or photos you import, notes, highlights, sketches on the question scratchpad, flashcards, bookmarks, study plans, curriculum blocks, exam dates, and histology slide sets you create.
- Performance data: answers, scores, time per question, confidence ratings, miss reasons, review schedules, streaks, and daily goals.
- Social features: assessments you choose to share with the community, follow requests you send or accept, blocks, and the metadata needed to deliver direct messages (sender, recipient, timestamps). Message bodies are encrypted on your device before they reach us; we cannot read them.
- Billing: your Stripe customer ID, subscription ID, and paid-through date. Card numbers are entered on Stripe's hosted checkout and never reach our servers.
- Communications: feedback, question reports, and support emails you send.
- Technical data: IP address, browser and device type, and request identifiers in server logs and error reports; cookieless, aggregated page-view statistics (see the Cookie Policy).
We do not collect precise location, contacts, health records, or government IDs.
3. How we use it
- Operate the study platform: generate questions, flashcards, plans, and analyses from your materials and performance.
- Schedule reviews (FSRS spaced repetition) and show your progress.
- Deliver community sharing, follows, and direct messages you opt into.
- Authenticate you, protect against abuse (rate limiting, CSRF protection), and debug errors.
- Bill subscriptions and honour trials and refunds.
- Send transactional email: verification, password reset, and a welcome message. We do not send marketing email.
- Comply with law and enforce our Terms.
Where the GDPR or UK GDPR applies, our legal bases are performance of our contract with you (Sections 3.1–3.3, 3.5), our legitimate interests in security, debugging, and product analytics that do not track individuals (3.4), consent where we ask for it, and legal obligation (3.7).
4. AI processing
Question writing, explanations, flashcards, study plans, performance analyses, and the AI tutor are produced by large language models operated by Anthropic (Claude) and, for lecture-schedule reading and question review, Google (Gemini). When you use these features, the relevant study-material text, topic, performance figures, or chat message is sent to the provider to produce the result you requested.
- Under the providers' API terms, your inputs are not used to train their models.
- Providers may retain API inputs for a limited period for abuse monitoring under their own policies, after which they are deleted.
- AI output can be wrong. It is study material, not medical advice. Use the report button on any question you believe is inaccurate.
5. Service providers (processors)
We rely on the following companies to run the service. Each processes data only on our instructions and under its own data-processing terms. All processing takes place in the United States.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Hosting, serverless functions, file storage (Vercel Blob) for histology slides and profile photos, cookieless page analytics, and page-speed measurement | All app traffic; uploaded images; anonymised page-view counts |
| Neon | Primary PostgreSQL database | Your account and all study data |
| Upstash | Redis for login rate-limiting and the encrypted chat transit queue | Hashed request identifiers; sealed chat envelopes for up to 48 hours |
| Anthropic | Claude models that write questions, explanations, flashcards, study plans, performance analyses, and tutor replies | Study-material text, topics, your performance figures, and your tutor-chat messages |
| Gemini models that read uploaded lecture-schedule files and photos, and act as a second reviewer on generated questions | Schedule files/photos you import; draft questions | |
| Stripe | Subscription payments | Email, payment details (entered on Stripe's pages, never on ours), subscription status |
| Resend | Transactional email | Email address; verification, password-reset, and welcome messages |
| Sentry | Error monitoring | Error reports with browser/device details; on an error only, a replay of the affected screen with all text masked and media blocked |
We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use advertising networks, social-media pixels, or embedded third-party widgets.
6. Community, classmates, and chat
- Community: when you share an assessment, its questions, topic, and your display name or @handle become visible to other signed-in students at your level. Your scores are never shared.
- Follows: your @handle and display name are searchable by other students so they can send follow requests. You can decline or block anyone.
- Direct messages: messages are encrypted end-to-end on your device. Our server holds only sealed envelopes, for at most 48 hours, until the recipient's device collects them. Message history lives only on your devices.
- Report abusive shared content or messages to kalangedavies@gmail.com. We may remove content and suspend accounts under the Terms.
7. Cookies and on-device storage
We use only strictly necessary cookies (your sign-in session and CSRF protection) and your browser's local storage for preferences such as theme and text size. We use no advertising or cross-site tracking cookies, so no consent banner is required. Details, including every storage key, are in the Cookie Policy.
8. Retention and deletion
- Your data is kept while your account is active.
- When you delete your account in Settings, deletion is scheduled with a 48-hour grace period during which you can cancel. After that, your account and everything linked to it (materials, quizzes, results, notes, flashcards, shared assessments, follows, and histology sets) is permanently deleted and any active subscription is cancelled.
- Stripe retains payment records for as long as tax and accounting law require.
- Error reports in Sentry expire automatically after 90 days; server logs are short-lived.
- Direct messages still in transit expire from our queue within 48 hours; copies on your devices are yours to clear.
- Unverified accounts and expired verification or reset tokens are purged by a scheduled job.
9. Your rights
Wherever you live, you can:
- Access and export: download a JSON copy of your data from Settings. Very large accounts may be truncated in the file; email us for a complete copy.
- Correct: edit your profile and content in the app.
- Delete: delete your account from Settings, or ask us by email.
- Object or restrict: tell us if you object to a particular use, such as error monitoring.
- Withdraw consent at any time where processing is based on consent.
If you are in the EEA, UK, or Switzerland you may also lodge a complaint with your supervisory authority. If you are a California resident, the rights above cover your CCPA/CPRA rights to know, delete, correct, and opt out; we do not sell or share personal information and we honour Global Privacy Control signals as an opt-out request. We will not discriminate against you for exercising any right.
10. Security
All traffic is encrypted with TLS (HSTS enforced). Passwords are hashed with bcrypt. Requests are protected with CSRF checks, origin validation, rate limiting, a strict Content Security Policy, and size limits. Direct messages are end-to-end encrypted. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authorities as the law requires.
11. International transfers
We operate from the United States and our providers process data there. If you use the service from elsewhere, your data is transferred to the United States. Where required, transfers rely on the providers' standard contractual clauses.
12. Children
The service is for medical and health-science students aged 16 or older. We do not knowingly collect data from anyone younger. If you believe a child has an account, email kalangedavies@gmail.com and we will delete it.
13. Changes
We will post any change here and update the date above. For material changes we will also notify you in the app or by email before they take effect.