Skip to download
Legal

Privacy Policy

This Privacy Policy describes how Mediceen (“Mediceen”, “we”, “us”) collects, uses, and protects personal data when you use the Mediceen mobile application (iOS and Android) and our public website at https://mediceen.app.

Effective date: 2026-08-24 · Last updated: 2026-08-17

1. Contact

Contact: hello@redisdigital.com
Address: Panipokhari, Kathmandu, Nepal

2. Scope

This policy applies to students using the mobile app. Staff use a separate admin dashboard governed by internal policies. This policy does not cover third-party websites linked from our app or site.

3. Data we collect

3.1 Account and profile

When you register or sign in, we collect:

  • Email address and password (password stored in hashed form by our auth provider)
  • Display name
  • Avatar image URL (including from Google Sign-In if you use it)
  • Email verification codes sent during signup (processed in transit; not stored as message content)
  • Mobile phone number (required verification at signup — see §3.5)

If you sign in with Google, we receive profile information Google shares with us (typically name, email, and profile picture URL). You still complete phone verification before full access to the app.

3.2 Learning and usage data

To provide the app, we store:

  • Quiz and practice sessions, your answers, scores, and timing
  • Spaced-repetition schedules and study streaks
  • Bookmarks
  • Flashcard ratings and session summaries

3.3 Technical and diagnostic data

  • Authentication session tokens
  • Server and security logs (may include IP address and device type)
  • Crash and error reports (if enabled): we use Sentry with sendDefaultPii disabled by default; we may attach your internal user id and email to diagnose issues you report

3.4 Leaderboards

If you participate in leaderboards, your display name and score may be visible to other users for weekly, monthly, or all-time rankings.

3.5 Phone number

We require a verified mobile phone number during signup (after you create your account with email or Google). We send a one-time SMS code to confirm you control the number. The verified number is stored on your account in our auth system (Supabase).

  • When: Once at signup (and again if you change your number in Profile, when that feature is available).
  • Login: Ongoing sign-in uses email/password or Google — we do not send an SMS code every time you log in.
  • Purpose: Reduce fake accounts, abuse, and duplicate registrations; support account recovery where applicable.
  • SMS providers: Messages are delivered through third-party SMS gateways (regional providers such as for Nepal and India). Providers process your number and message content only to deliver the OTP.
  • Marketing: We do not send promotional or marketing SMS.
  • OTP codes: Verification codes are processed in transit and are not stored as readable message content after verification.

If you do not complete phone verification, you may not be able to use the app beyond the signup flow.

3.6 What we do not collect

We do not collect payment card data, precise GPS location, contact lists, or use your data for cross-app advertising or sale to data brokers.

4. How we use data

PurposeLegal basis (summary)
Create and secure your accountContract / legitimate interest
Deliver practice, mocks, review, insightsContract
Operate leaderboardsContract / your participation
Send transactional email (OTP, password reset)Contract
Verify phone at signup (SMS OTP)Contract / legitimate interest
Monitor reliability and fix bugsLegitimate interest
Prevent fraud and abuseLegitimate interest

We do not use student data to train public AI models. AI tools on our platform are used by administrators only to assist with content ingestion (e.g. extracting questions from past papers) — not by students in the mobile app.

5. Third-party service providers

We use trusted processors, including:

ProviderPurpose
SupabaseAuthentication, database, and API hosting
GoogleOptional Sign-In
Resend (via Supabase Auth)Transactional email
SMS delivery providersOne-time phone verification at signup
Sentry (optional)Error monitoring
Expo / EASApp build and update delivery

These providers process data on our behalf under their own terms and security measures. Data may be stored in South Asia (Mumbai) and other regions where these providers operate.

6. Retention

We retain account and learning data while your account is active. If you request deletion, we delete or anonymize personal data within a reasonable period, except where law requires longer retention (e.g. security logs).

7. Security

We use industry-standard measures including encryption in transit (HTTPS/TLS), access controls, and row-level security on our database so users can only access their own data where applicable. No method of transmission over the Internet is 100% secure.

8. Your rights

Depending on applicable law, you may have the right to:

  • Access a copy of your personal data
  • Correct inaccurate data (e.g. display name in Profile)
  • Request deletion of your account and associated data
  • Object to or restrict certain processing
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact hello@redisdigital.com or follow the delete-account process.

9. Children

Mediceen is not directed at children under 10+. We do not knowingly collect data from anyone below that age. Contact us if you believe we have collected a child's data in error.

10. International transfers

If you use Mediceen from outside Nepal, your data may be processed in Nepal and in countries where our providers host infrastructure. We take steps to protect data in line with this policy.

11. Changes

We may update this policy. We will post the new version at https://mediceen.app/privacy and update the “Last updated” date. Continued use after changes means you accept the updated policy where permitted by law.

12. Contact

Privacy questions: hello@redisdigital.com
General support: hello@redisdigital.com
Mediceen, Panipokhari, Kathmandu, Nepal