Privacy Policy
This policy explains what data we collect, why, who else sees it, and what you can do about it. It is specific on purpose: every category below corresponds to something the app actually stores, and the list of third parties is the complete list.
1. The short version
This summary is here so you actually know what happens to your data. It is not a substitute for the rest of the document, but nothing below contradicts it.
- We collect what we need to run a study app: your email, a display name, your grade and test track, your date of birth (to check your age), and whatever you save into the app — practice results, essays, activities, GPA, colleges, deadlines.
- We do not sell your personal information. We do not share it for cross-context behavioral advertising. We never have.
- Ads on this site are non-personalized for everyone, because our audience includes minors. Nothing you put into the app is used to target ads.
- We do not use your essays, coach conversations, scores, or any other content to train AI models — ours or anyone else's.
- You must be at least 13 to use the Service. We do not knowingly collect anything from children under 13.
- You can see, correct, export, or delete your data at any time, from the app or by emailing us. Deleting your account deletes your data.
This policy applies to https://medschoolprep.cloud and the MedSchoolPrep application. It does not apply to third-party sites we link to, which have their own policies.
2. Who we are
MedSchoolPrep is operated by MedSchoolPrep, a sole-operator educational technology service based in North Carolina, United States. For the purposes of the EU and UK General Data Protection Regulation, we are the "controller" of the personal data described here.
- Email: medschoolprepsupport@gmail.com
- Post: MedSchoolPrep, ADDRESS PENDING — SET BEFORE PRODUCTION, North Carolina, United States
We are small enough that the person who reads privacy email is the person who runs the service. Write to us and you will reach someone who can actually do the thing you are asking for.
3. Children and teenagers
Children under 13
We ask for a date of birth during onboarding and use it to enforce a minimum age of 13. A visitor who tells us they are under 13 is not permitted to create an account, and we do not retain the date of birth they entered beyond what is needed to remember that the check was not passed.
If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you are a parent or guardian and believe your child under 13 has given us information, email medschoolprepsupport@gmail.com and we will locate and delete the account and its data, and confirm to you when it is done. You do not need an account to make that request.
Teenagers, and the protections that apply to everyone
Most of our users are minors, so rather than treating minors as an exception, we apply the strongest of these protections to every user of the Service, at every age:
- We do not sell personal information, and we do not share it for targeted or cross-context behavioral advertising — regardless of age or consent. Several state laws, including Connecticut's, prohibit this outright for anyone under 18; we simply do not do it for anyone.
- We do not use personal data to build advertising profiles or to profile users for advertising purposes.
- We do not use design features intended to extend engagement time beyond what the study features themselves require, such as autoplaying feeds or infinite scroll.
- We collect only what the features you use actually need, and we delete it when you ask.
A parent or legal guardian of a user under 18 may request access to, correction of, or deletion of their child's information, and may direct us to stop further collection, by emailing medschoolprepsupport@gmail.com. We will verify the relationship proportionately to the sensitivity of what is being asked, and we will not require more information than is necessary to do that.
Under the EU GDPR, where processing is based on consent and the user is below the age of digital consent in their country (between 13 and 16, depending on the member state), that consent must be given or authorized by a parent or guardian. In the United Kingdom the age is 13. We rely on the parent or guardian who agreed to our Terms of Service for that authorization.
4. What we collect
Information you give us
- Account details: your email address, and — if you set them — a display name and your grade level. If you sign in with Google, we receive your Google account email address and whether it is verified; we never receive your Google password.
- Date of birth: collected during onboarding to verify you meet the minimum age.
- Authentication data: a hashed form of your password (we never store the password itself), and short-lived one-time sign-in codes together with the IP address that requested them, which we use to rate-limit abuse of the code-sending endpoint.
- Study data you create: practice and quiz results, flashcard review history, lesson completion, study sessions, streaks, and achievements.
- Portfolio data you create: colleges you are tracking and their deadlines and checklists; essays and every saved version of them; test scores you record; scholarships; activities and awards, with descriptions, hours, and any evidence links; GPA entries; research, skills and certification records; clinical or volunteer hours; and recommender records.
- Information about other people that you choose to enter — most commonly the name, email, and relationship of a teacher, mentor, or supervisor you list as a recommender or verifier. Only enter these with that person's permission.
- Account type: whether an account belongs to a student or to a parent or guardian. This is set when the account is created and cannot be changed afterwards.
- Family connections, if you use them: the email address invited, who invited whom, the relationship label you chose, and the date each connection was created, accepted, or ended. See "Parent and guardian access" in section 7 for what a connected parent can and cannot see.
- Anything you type into the AI coach, including essays or drafts you ask it to review.
- Anything you send us by email.
Information collected automatically
- Server logs from our host, which record IP address, user agent, requested URL, and timestamp for each request. These are ordinary web-server logs, kept short-term for security and debugging.
- A session token stored in your browser so you stay signed in.
- Local application data stored on your own device (see Section 9), which stays on your device unless a feature syncs it to your account.
- Ad requests to Google AdSense, which necessarily disclose your IP address and the page being viewed. These requests are tagged as child-directed, which disables personalized advertising and remarketing.
What we do not collect
- We do not collect payment card or financial account information — the Service is free and we take no payments.
- We do not collect government identifiers such as Social Security numbers.
- We do not ask for health or medical information, and you should not enter any. Despite the name, this is a study product, not a health product.
- We do not collect precise geolocation.
- We do not use analytics, tracking pixels, session recording, or advertising cookies of our own.
- We do not access your camera, contacts, or files. The interview simulator can use your microphone, but only if you switch voice answers on and grant your browser's permission prompt, and only while you are answering a question. We never receive, see, store, or transmit that audio ourselves — but on most browsers, your browser sends it directly to its own speech service to turn it into text, which is a third-party disclosure we do not control. See "Voice answers in the interview simulator" in Section 6, and the corresponding entry in the Section 7 provider table.
5. Why we use it, and our legal basis
We use personal data only for the purposes below. For users in the EU, UK, and other jurisdictions requiring a lawful basis, the basis for each purpose is given alongside it.
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights — and given that most of our users are minors, we have resolved that question in favor of the user wherever it was close. That is why there is no analytics package, no advertising profiling, and no model training on your content.
We do not use your personal information for automated decision-making that produces legal or similarly significant effects about you. Score estimates, study plans, and coach feedback are study aids; they do not decide anything about you, and no admission, award, or eligibility decision is made by us on the basis of them.
6. AI features and what happens to what you type
The coach, essay feedback, résumé feedback, study-plan generation, practice generation, and interview simulator send text to a third-party AI provider (currently Groq) to produce a response.
What gets sent
The message you wrote, plus the profile context that specific feature needs — for example, your grade, test track, and target score for a study plan, or the text of the essay for essay feedback. Nothing is sent to the AI provider until you use one of these features.
What we do with it
- We do not use your prompts or the AI's responses to train any model, and our agreement with our AI provider does not permit them to either.
- We keep a short-lived cache of AI responses (currently ten minutes) so that identical requests do not need to be re-sent. It is keyed to the content of the request, holds no account identifier, and is discarded on that timer.
- Coach conversations are held in your browser for the session. We do not maintain a server-side archive of your conversations.
Do not enter health information, government identifiers, financial account details, passwords, or another person's personal information into the AI features. They are not designed to hold that kind of data, and once text is sent to the AI provider we cannot pull it back.
Voice answers in the interview simulator
The interview simulator can speak its questions aloud, and can let you answer out loud instead of typing. Those are two different features with opposite privacy profiles, and it matters that you can tell them apart.
- The interviewer's voice is produced entirely by your own device's built-in speech synthesis. Nothing about it leaves your device, no network request is made to produce it, and it works exactly the same with your microphone switched off. This half of the feature never involves us or anyone else.
- Answering out loud is different: it uses your browser's own speech-recognition feature, not ours. On Chrome, Edge, and most other Chromium-based browsers, your browser sends the audio captured from your microphone to its vendor's speech service — in practice, Google's — to be turned into text, under that vendor's own privacy policy, not this one. We are not a party to that transmission: we do not receive the audio, we do not see it in transit, and we do not store a recording of it, ever. What reaches us is the written transcript your browser hands back, and only once — when you press send on your answer.
- On recent versions of Safari, the transcription happens on your device and no audio is sent anywhere. We have no reliable way to detect which behavior a given browser actually uses, so we describe the more exposed case rather than assume the safer one in our own favor.
Because this can mean a minor's voice reaching a third party we do not control, voice answers are off until you turn them on. Before your microphone is ever opened, we ask — once, in plain language, in the app itself, not buried in a permission dialog — and you can say no. Declining costs you nothing: the interview simulator works identically by typing, start to finish, with every feature available either way. You can turn voice answers back off at any time from the same screen where you turned them on, and doing so takes effect immediately for every future answer.
AI output can be wrong. Section 5 of the Terms of Service explains what that means for how you should use it.
8. Advertising
The Service is free and supported by ads served through Google AdSense.
Because our audience includes minors, we tag every ad request from this Service for child-directed treatment. This turns off personalized and interest-based advertising, and remarketing, for every visitor regardless of age. You will see contextual ads — chosen by the topic of the page — not ads chosen by a profile of you.
- Nothing you enter into the Service — essays, scores, GPA, activities, colleges, coach conversations — is used for advertising, shared with advertisers, or used to build an advertising profile.
- We do not place advertising cookies of our own, and we do not run any advertising or analytics pixel of our own.
- Google still receives the IP address and page context that serving any ad requires. Google's handling of that is described in its own policy, linked in the table above.
Under the CCPA and CPRA, and under state laws that use similar definitions, none of this is a "sale" or a "share" of personal information, and there is accordingly no "Do Not Sell or Share My Personal Information" mechanism to offer — there is nothing to opt out of.
10. How long we keep things
We keep personal data only as long as it is needed for the purpose it was collected for — a requirement the amended COPPA Rule makes explicit, and one we apply to every user rather than only to children.
We do not retain personal information indefinitely, and we do not keep data after an account is deleted in order to build a profile, a mailing list, or a model.
11. How we protect it
- All traffic is encrypted in transit with HTTPS/TLS. Data is encrypted at rest by our database provider.
- Passwords are stored only as salted hashes. We cannot read your password, and nobody at MedSchoolPrep can tell you what it is.
- Sign-in codes are stored hashed, expire quickly, are single-use, and are rate-limited by both email address and IP address.
- Every database query is scoped to the signed-in user's own records, and our database tables have row-level security enabled so they cannot be reached with a public key even if one were exposed.
- The high-privilege database key is held only by server-side functions and is never included in anything sent to your browser.
- Our AI and email endpoints are rate-limited to limit both abuse and cost.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law — under the GDPR, without undue delay and within 72 hours of becoming aware where the breach is notifiable, and under North Carolina's Identity Theft Protection Act and other applicable state breach-notification laws on the timelines those set.
If you believe you have found a security vulnerability, please tell us at medschoolprepsupport@gmail.com before disclosing it publicly. We will not pursue legal action against anyone who reports a vulnerability in good faith, tests only against their own account, and gives us reasonable time to fix it.
12. Your rights and choices
Wherever you live, you can do all of the following, and we will honor the request:
- Access — get a copy of the personal data we hold about you.
- Correct — fix anything inaccurate, either in the app or by asking us.
- Delete — delete individual records from the app, or close your account to delete everything.
- Export — get your data in a portable, machine-readable format.
- Object or restrict — ask us to stop or limit a particular use.
- Withdraw consent — where we rely on consent, withdraw it at any time, without affecting what we did before you withdrew it.
- Complain — raise a concern with us, and with a regulator.
How to exercise them
Most of this you can do yourself in the app's settings, including account deletion. For anything else, email medschoolprepsupport@gmail.com from the address on your account, or tell us the address on the account if you are writing from somewhere else. We will respond within 30 days, and within 45 days where a US state law sets that period, and we will tell you if we need a permitted extension. Using your rights costs nothing and we will not treat you differently for it.
One consent lives entirely in the app rather than needing an email: voice answers in the interview simulator, described in Section 6. Turn them on or off from the same screen the interview simulator shows you, at any time — the change applies immediately and no request to us is needed.
We will ask for enough information to be confident you are who you say you are, and no more. A parent or guardian may make a request on behalf of a user under 18, and an authorized agent may make a request where state law allows it.
If you are in California
The CCPA, as amended by the CPRA, gives you the rights to know, delete, correct, and opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising them. In the twelve months before the date of this policy we collected the categories of personal information described in Section 4 — identifiers, education information, and internet activity limited to the server logs described there — for the purposes in Section 5, from the sources in Section 4, and disclosed them for a business purpose only to the providers in Section 7.
We did not sell or share personal information, and we did not sell or share the personal information of minors under 16. We do not use or disclose sensitive personal information for any purpose beyond those permitted without a right to limit.
If you are in the EEA, UK, or Switzerland
You have the rights of access, rectification, erasure, restriction, portability, and objection under Articles 15 to 22 of the GDPR, and the right to withdraw consent. You also have the right to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office. We would rather you came to us first, but you do not have to.
If you are in another US state
Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and a growing number of other states give residents rights to access, correct, delete, and port their data, and to opt out of targeted advertising, sale, and profiling. We honor all of these for every user regardless of state — and because we do not conduct targeted advertising, sale, or profiling at all, the opt-outs have nothing to act on. Some of these states provide a right to appeal a refused request; if we ever refuse one of yours, we will tell you how to appeal and, if the appeal fails, how to contact your attorney general.
North Carolina, where we are based, does not currently have a comprehensive consumer privacy statute. We apply the protections in this policy to North Carolina residents on the same terms as everyone else.
Global Privacy Control
We honor the Global Privacy Control and similar browser opt-out signals. Because we do not sell or share personal information or serve targeted advertising, such a signal does not change our processing — but it will never be ignored.
13. International data transfers
We operate from the United States, and our providers store and process data in the United States. If you use the Service from outside the United States, your personal data is transferred there.
For transfers of personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) in our agreements with providers, together with the supplementary measures described in Section 11 — encryption in transit and at rest, minimization of what is transferred, and no onward transfer for the providers' own purposes.
You may request a copy of the relevant transfer safeguards by writing to medschoolprepsupport@gmail.com.
14. Student records and schools
We provide the Service directly to students and families, not to schools. Data you enter is yours, not a school's: we do not receive rosters from schools, we do not provide a teacher or administrator dashboard, and no educator can view another person's records through the Service.
Because of that, the data we hold is not an "education record" under FERPA, and we do not act as a school official under FERPA's school-official exception.
If a school or district wants to adopt the Service in a way that would change this, contact medschoolprepsupport@gmail.com. That requires a separate written agreement covering FERPA, the Protection of Pupil Rights Amendment, and applicable state student-privacy laws before any such use begins.
We do not engage in targeted advertising to students, do not sell student data, and do not create a profile of a student for any purpose other than providing the study and planning features they are using — commitments that also track the substance of the state student-data-privacy laws modeled on California's Student Online Personal Information Protection Act.
15. Changes to this policy
We will update this policy when what we do changes. The "last updated" date at the top always reflects the current version.
If a change is material — a new category of data, a new purpose, a new recipient, or anything that would materially expand how your data is used — we will tell you in the app or by email before it takes effect, and where the law requires consent for that change, we will ask for it rather than assume it.
We will not apply a materially different use to data we already hold without giving you notice and, where required, obtaining consent.
16. How to reach us
For any privacy question, rights request, or complaint — including a parent or guardian request about a child's account:
- Email: medschoolprepsupport@gmail.com
- Post: MedSchoolPrep, ADDRESS PENDING — SET BEFORE PRODUCTION, North Carolina, United States
We aim to reply within a few days, and in every case within the deadlines set out in Section 12.