Privacy Policy
This policy explains what MedX collects when you use the app, why we collect it, who else sees it, and what you can do about it. It covers the MedX student app and the servers behind it.
Who is responsible
MedX operates this service from the Republic of Iraq and decides how the information described here is used. You can reach us at [email protected] about anything on this page.
What we collect
Your account. When you register we store your mobile number, your full name, and your password. The password is stored only as a one-way hash — we cannot read it, and neither can anyone with access to our database. You also choose a field of study, a stage and a university, which we use to show you relevant courses.
Verifying your number. Sending you a verification code creates a record containing the number, the reason for the code, a one-way hash of the code itself, the time, and the IP address the request came from. The IP address is there to stop someone requesting thousands of codes for numbers that are not theirs.
Your devices and sessions. When you sign in we store, for each signed-in device: the platform (iOS or Android), the app version, the language you have chosen in the app, the IP address of the sign-in, and — if you allow notifications — the notification token issued by your phone's operating system. This is what makes the device list in your profile possible, and what lets you sign another device out.
What you do in the app. Courses you are enrolled in, access codes you redeem, lectures you favourite, and the questions and reviews you write.
Things you post publicly. Questions on a lecture and reviews of a course are shown to other students of that course, and to the lecturers who teach it, with your full name attached. Please do not put anything in them that you would not want another student to read.
Reports and blocks. If you report a question, an answer or a review, we store which post you reported, the reason you chose, anything you typed in the note, and that it was you who reported it — a report we cannot attribute is one we cannot act on. If you block another student, we store that you have blocked them; they are never told, and blocking is only ever visible to you.
Screenshots and screen recordings. Course material is paid for by the students who buy it, so the app tries to prevent it being copied. On Android your phone refuses to take a screenshot of the app at all, and we are told nothing. On iPhone that is not possible — no app can stop an iPhone taking a screenshot — so instead the app tells us when one is taken, or when a screen recording or mirroring session starts while the app is open. What we record is your account, what was on screen at the time, how many times it has happened, and when. We use it to contact students who are copying lectures, and nothing else. If you delete your account, these records are deleted with it.
Administrative records. When a member of staff acts on your account — granting, revoking or restoring access, or hiding something you posted — we record who did it, when, and from which address. These records are how a mistake or an abuse can be traced afterwards.
What we do not collect
- No device fingerprint and no advertising identifier. We do not build or store any value that would let us recognise your phone across a reinstall, or across other apps.
- No location. The app never asks for it and never reads it.
- No contacts, photos, microphone or camera.
- No analytics or tracking. The app contains no analytics toolkit and no advertising toolkit. Nothing you do in the app is measured for a third party, and nothing about you is used to target advertising anywhere. The promotional banners you may see on the home screen are our own, chosen by field, stage and university — never by anything bought from an ad network.
- No payment details. Access codes are bought from your lecturer outside the app. We never see a card, a wallet or a bank transfer.
Who else sees your information
We do not sell your information, and we do not share it for advertising. We use a small number of service providers, each for one job:
- The verification-code provider. To send your code by WhatsApp, your mobile number is passed to the messaging service that delivers it. This happens when you register, when you resend a code, and when you reset your password.
- Our video provider. Video lessons are hosted and protected by a specialist video service. Playing a lesson contacts that service and our own server, which checks that your access is still valid.
- Our file storage provider. PDFs, images and other course files are stored on a content-delivery network.
- The notification service. If you allow notifications, your phone's operating system issues a token which we store and use to send you notifications through Google's Firebase Cloud Messaging.
Your lecturers see your name, the courses of theirs you are enrolled in, and anything you post on their courses. They do not see your password, your devices or your IP addresses.
We will also disclose information where the law of the Republic of Iraq requires it of us.
How long we keep it
- Your account — until you delete it. See below.
- Verification-code records — 30 days, then deleted automatically, including the mobile number in them.
- Signed-out and expired device records — 90 days, so that "why was I signed out?" can still be answered, then deleted.
- Records of a purchase — kept indefinitely, because a lecturer is paid from them. After you delete your account these records no longer carry your name or your number.
Deleting your account
You can delete your account from inside the app: Profile → Delete my account. You will be asked for your password, every signed-in device is signed out immediately, and your name, your mobile number and your password are removed. Access to any course you had ends at that moment and does not come back if you sign up again with the same number. If you cannot reach the app, write to [email protected] from the number on the account, or tell us that number, and we will verify it before acting.
Your other choices
- Correct your name, field, stage or university at any time from your profile.
- See every device signed in to your account, and sign any of them out.
- Turn notifications off in your phone's settings; we stop sending them.
- Ask us what we hold about you by writing to [email protected].
Keeping it safe
Traffic between the app and our servers is encrypted. Passwords are stored only as one-way hashes. On your phone, the token that keeps you signed in is held in the operating system's secure storage — the iOS Keychain or Android's encrypted storage — and never in ordinary app storage. No system is perfect, and we will tell you if something happens that affects you.
Course videos carry a small moving label showing the last digits of your phone number and your account number. It is drawn on your own device from information you already gave us, appears only on your screen, and is not sent anywhere or stored. It is there to discourage re-recording paid lectures, which is what makes it possible for lecturers to sell them at all.
Children
MedX is built for university-level medical students. It is not directed at children, and we do not knowingly create accounts for anyone under 13. If you believe a child has an account, write to us and we will remove it.
Changes to this policy
When this policy changes, the date at the top of this page changes with it, and the version you are reading is always the current one. If a change is significant we will say so in the app.