Privacy Policy
This Privacy Policy describes how Mediceen (“Mediceen”, “we”, “us”) collects, uses, and protects personal data when you use the Mediceen mobile application (iOS and Android) and our public website at https://mediceen.app.
Effective date: 2026-08-24 · Last updated: 2026-08-17
1. Contact
Contact: hello@redisdigital.com
Address: Panipokhari, Kathmandu, Nepal
2. Scope
This policy applies to students using the mobile app. Staff use a separate admin dashboard governed by internal policies. This policy does not cover third-party websites linked from our app or site.
3. Data we collect
3.1 Account and profile
When you register or sign in, we collect:
- Email address and password (password stored in hashed form by our auth provider)
- Display name
- Avatar image URL (including from Google Sign-In if you use it)
- Email verification codes sent during signup (processed in transit; not stored as message content)
- Mobile phone number (required verification at signup — see §3.5)
If you sign in with Google, we receive profile information Google shares with us (typically name, email, and profile picture URL). You still complete phone verification before full access to the app.
3.2 Learning and usage data
To provide the app, we store:
- Quiz and practice sessions, your answers, scores, and timing
- Spaced-repetition schedules and study streaks
- Bookmarks
- Flashcard ratings and session summaries
3.3 Technical and diagnostic data
- Authentication session tokens
- Server and security logs (may include IP address and device type)
- Crash and error reports (if enabled): we use Sentry with sendDefaultPii disabled by default; we may attach your internal user id and email to diagnose issues you report
3.4 Leaderboards
If you participate in leaderboards, your display name and score may be visible to other users for weekly, monthly, or all-time rankings.
3.5 Phone number
We require a verified mobile phone number during signup (after you create your account with email or Google). We send a one-time SMS code to confirm you control the number. The verified number is stored on your account in our auth system (Supabase).
- When: Once at signup (and again if you change your number in Profile, when that feature is available).
- Login: Ongoing sign-in uses email/password or Google — we do not send an SMS code every time you log in.
- Purpose: Reduce fake accounts, abuse, and duplicate registrations; support account recovery where applicable.
- SMS providers: Messages are delivered through third-party SMS gateways (regional providers such as for Nepal and India). Providers process your number and message content only to deliver the OTP.
- Marketing: We do not send promotional or marketing SMS.
- OTP codes: Verification codes are processed in transit and are not stored as readable message content after verification.
If you do not complete phone verification, you may not be able to use the app beyond the signup flow.
3.6 What we do not collect
We do not collect payment card data, precise GPS location, contact lists, or use your data for cross-app advertising or sale to data brokers.
4. How we use data
| Purpose | Legal basis (summary) |
|---|---|
| Create and secure your account | Contract / legitimate interest |
| Deliver practice, mocks, review, insights | Contract |
| Operate leaderboards | Contract / your participation |
| Send transactional email (OTP, password reset) | Contract |
| Verify phone at signup (SMS OTP) | Contract / legitimate interest |
| Monitor reliability and fix bugs | Legitimate interest |
| Prevent fraud and abuse | Legitimate interest |
We do not use student data to train public AI models. AI tools on our platform are used by administrators only to assist with content ingestion (e.g. extracting questions from past papers) — not by students in the mobile app.
5. Third-party service providers
We use trusted processors, including:
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, and API hosting |
| Optional Sign-In | |
| Resend (via Supabase Auth) | Transactional email |
| SMS delivery providers | One-time phone verification at signup |
| Sentry (optional) | Error monitoring |
| Expo / EAS | App build and update delivery |
These providers process data on our behalf under their own terms and security measures. Data may be stored in South Asia (Mumbai) and other regions where these providers operate.
6. Retention
We retain account and learning data while your account is active. If you request deletion, we delete or anonymize personal data within a reasonable period, except where law requires longer retention (e.g. security logs).
7. Security
We use industry-standard measures including encryption in transit (HTTPS/TLS), access controls, and row-level security on our database so users can only access their own data where applicable. No method of transmission over the Internet is 100% secure.
8. Your rights
Depending on applicable law, you may have the right to:
- Access a copy of your personal data
- Correct inaccurate data (e.g. display name in Profile)
- Request deletion of your account and associated data
- Object to or restrict certain processing
- Lodge a complaint with a supervisory authority
To exercise these rights, contact hello@redisdigital.com or follow the delete-account process.
9. Children
Mediceen is not directed at children under 10+. We do not knowingly collect data from anyone below that age. Contact us if you believe we have collected a child's data in error.
10. International transfers
If you use Mediceen from outside Nepal, your data may be processed in Nepal and in countries where our providers host infrastructure. We take steps to protect data in line with this policy.
11. Changes
We may update this policy. We will post the new version at https://mediceen.app/privacy and update the “Last updated” date. Continued use after changes means you accept the updated policy where permitted by law.
12. Contact
Privacy questions: hello@redisdigital.com
General support: hello@redisdigital.com
Mediceen, Panipokhari, Kathmandu, Nepal