Privacy policy
This policy describes how the operator of MedStudy at medplanner.prepwing.app handles information for its MBBS study-planning service. Contact the operator for support or privacy requests: Support email is being configured by the site operator.
Information we collect
- Google account information: your Google account identifier, Gmail address and display name, to create and authenticate your MedStudy account.
- Your student profile and study data: the name and college you enter, subject and topic progress, book chapter progress, confidence and revision records, notes, resource links, exam dates, study sessions and practical checklists.
- Files you upload: study attachments you choose to add, such as PDF, image and text files.
- Authorization and session data: Google access and refresh tokens needed to perform the Drive backups you authorize, and session records needed to keep you signed in.
- Connection information: web requests include technical details such as IP address and browser headers. Operational logs may record errors needed to maintain and secure the service.
Google Drive permissions and backups
MedStudy requests the drive.file permission to create,
read back and update its backup files, and to work with files you
explicitly authorize for the app. It does not request unrestricted
access to your entire Drive or access to Gmail messages. The current
backup feature operates on dated MedStudy JSON files created by this
app.
When you choose a Drive backup, or when the nightly backup runs with your continuing permission, MedStudy sends the latest synced workspace to your Google Drive. That file includes study data and references to attachments; it does not include attachment bytes. MedStudy reads the saved file back to verify it. Multiple backups on the same date update that date’s file. Changes still offline on your device are not included until they sync.
How information is used and shared
We use your information to authenticate your account, save and synchronize your study workspace, provide the study tools you use, create requested and authorized backups, and maintain the service. Your backups are sent to Google Drive under your authorization. The hosting provider processes server traffic and stores the service’s files as part of operating the VPS.
MedStudy does not sell your Google user data, use it for advertising, or use it to train AI models. Operator access is limited to providing support with your permission, investigating security or service issues, and meeting legal obligations. MedStudy’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Storage and security
Your account records, synced workspaces, attachments and account backups are stored in private files on the MedStudy VPS. Account APIs authorize access using your signed-in session. Google tokens are encrypted at rest, and HTTPS protects traffic to the site. Session cookies are HttpOnly and are used for sign-in, rather than advertising.
The browser also stores workspace and recovery copies in local storage to support saving and synchronization. These local copies can remain on a device after you sign out. Clear this site’s browser data to remove them from that device. Files in your Google Drive are subject to your Google account’s storage and sharing settings.
Retention, access and deletion
Server account and study data are retained while your account is in use and until you request deletion or the operator removes the service. Dated backups remain stored until removed. You can export your study workspace from Account & sync, edit your profile and study records, and delete study items using the app’s controls.
To request deletion of your server account, stored study data, attachments and server backups, contact the operator: Support email is being configured by the site operator.. We may need to confirm account ownership before removing data. Deleting a server account does not delete copies you downloaded, browser-local copies, or backup files in your Google Drive; remove those separately.
Revoking Google access
You can revoke MedStudy’s access at any time from your Google account’s third-party connections. Revocation stops further authorized Google access; future Google sign-in or Drive backup may require reconnection. Revocation does not automatically delete existing server data or Drive backup files.
Android app
The MedStudy Android app uses the same account and study workspace as this website. Google sign-in opens in your external browser. The app keeps an encrypted MedStudy account session and an encrypted copy of study data in its private device storage, using Android Keystore. Google access and refresh tokens remain on the server.
Study edits can stay on your device until they sync. The app checks workspace revisions before saving to avoid silently replacing another device's changes. Sign out from the app to remove its stored session, cached workspace and local recovery copy. JSON exports saved through the Android file picker, and copies in Google Drive, must be deleted separately.
Policy changes and contact
If the service’s data practices change, this page will be updated. Changes requiring additional Google permissions will require your consent. For questions, support or privacy requests, contact: Support email is being configured by the site operator.