← Home
MedFlash

Privacy Policy

📅Version: 2026-09-06 · Last updated: 06.09.2026
ℹ️
This Privacy Policy is drawn up in accordance with the Israeli Privacy Protection Law (חוק הגנת הפרטיות, 5741-1981) and its Amendment No. 13. It applies to all data processed when using the MedFlash platform.

A. Data controller

MedFlash operator and data controller: Adam Tsitrin, private individual
Privacy enquiries: support@med-flash.com

B. Personal data categories

We process the following categories of personal data only to the extent necessary for the purposes described below:

1. Account identification data:

  • First and last name (as provided at registration).
  • Email address.
  • Password hash (processed exclusively by Supabase Auth; MedFlash does not store plain-text passwords).
  • Specialisation (country of origin).
  • Planned examination month.
  • Instructor code (optional, if provided).
  • Profile photo (if uploaded).

2. Study activity data:

  • Exam attempt records (mode, result, date, time spent).
  • Question answers (correct/incorrect, question speciality).
  • Performance statistics and analytics.
  • Error list (incorrectly answered questions).
  • Bookmarked questions.
  • Medical terminology study status (progress, review history).
  • Completed exam history.

3. Support request data:

  • Subject and text of the request.
  • Screenshots (if uploaded by the user).
  • User's email and name at the time of the request.
  • URL of the page from which the request was submitted.
  • Context (question or term on which the problem arose, if any).

4. Technical and security data:

  • Authentication logs (Supabase Auth).
  • API usage records (user_id, endpoint) — for abuse protection.
  • Authentication cookie session data (Supabase session token).

5. Legal document acceptance data:

  • Record of acceptance of the Terms of Use and Privacy Policy (version, date — set by the server).

C. Purposes of data processing

  • Account creation and user authentication.
  • Provision of the service and personalisation of preparation.
  • Saving study progress and exam history.
  • Performance analytics and recommendations.
  • Management of error list, bookmarks and terminology.
  • Processing support requests.
  • Account security protection and abuse prevention.
  • Compliance with legal requirements.
  • Product improvement based on aggregated, anonymised data.

D. Notice under Article 11 of the Privacy Protection Law

In accordance with the Israeli Privacy Protection Law, we inform you of the following:

  • Providing data at registration (name, email, specialisation, examination month) is required to create an account. Without this data an account cannot be created.
  • Providing an instructor code and profile photo is voluntary.
  • Study activity data is generated in the course of using the service.
  • The data controller is MedFlash, contact: as specified in section A above.
  • You have the right to access the personal data held about you and to request correction of inaccurate, incomplete, outdated or unclear data.

E. Legal basis for data processing

Data processing is carried out on the basis of: (1) consent given at registration, (2) performance of the service agreement, (3) legitimate interests of the operator (security, fraud prevention), (4) compliance with applicable legal requirements.

F. AI-assisted data processing

⚠️
When requesting an explanation for a question, part of the content may be sent to an external AI service (Anthropic Claude). We take measures to minimise the data transmitted.
  • Anthropic receives: an educational system prompt, the question and selected answers (no personal user data).
  • Anthropic does NOT receive: email, username, profile data or history of other exams.
  • To improve performance, AI responses may be cached in the MedFlash database, linked to the question rather than to the user.
⚠️
Do not enter personal patient data or other confidential medical information into AI queries.

G. Data sharing with third parties

MedFlash uses the following data processors. All of them act under our instructions and in accordance with applicable law:

ProviderPurposeData
SupabaseDatabase, authentication, file storageAll account and activity data
VercelWeb application hosting and CDNTechnical request data (standard logs)
ResendTransactional email notificationsEmail address, name (in support notifications)
AnthropicGeneration of question explanationsQuestion context only (no personal data)

We do not sell or transfer personal data to third parties for commercial purposes. Data may be disclosed upon request from competent authorities in accordance with the law.

H. International data transfers

Data processors (Supabase, Vercel, Resend, Anthropic) may store and process data outside Israel. Data transfers are carried out with appropriate protection safeguards as required by applicable Israeli law.

I. Data retention periods

Personal data is retained for the period necessary for the processing purposes described above, as well as to comply with legal requirements and ensure security. Account data is retained until the account is deleted or closed. Support request records are retained for a period reasonably necessary for quality management and claim resolution.

J. Data security

MedFlash implements reasonable organisational and technical measures to protect personal data, including: user data isolation, restricted database access, encryption in transit, and secure URLs for attachments and profile photos. We do not claim 100% security — no system can guarantee complete protection.

K. Data subject rights

In accordance with the Israeli Privacy Protection Law, you have the right to:

  • Access the personal data held about you at MedFlash.
  • Request correction of inaccurate, incomplete, outdated or unclear data.

Account closure requests and related data are reviewed within a reasonable timeframe, taking into account legal data retention and security requirements. The 'right to be forgotten', where not mandated by law, is not automatic; however we endeavour to accommodate reasonable deletion requests.

To exercise your rights contact: support@med-flash.com. Identity verification proportionate to the nature of the request may be required.

L. Security incidents

In the event of a security incident affecting personal data, MedFlash will take reasonable steps to address it and notify affected users in accordance with applicable law.

M. Minors

MedFlash is not intended for persons under 18 years of age. We do not intentionally collect personal data of minors. If you become aware that a minor has created an account, please inform us.

N. Cookies and local storage

See the dedicated Cookies and local storage page.

O. Marketing communications

MedFlash currently sends only transactional and service emails (account confirmation, support notifications). If we introduce marketing communications in the future, this will only be possible with your explicit separate consent, which you can withdraw at any time.

P. Changes to this Policy

For material changes to this Policy we will notify registered users by email or through the platform. Continued use of the platform after the update constitutes consent to the changes.

Q. Privacy contact

For all questions related to the processing of personal data and the exercise of rights, contact: support@med-flash.com

© 2026 MedFlash·Last updated: 06.09.2026Terms of usePrivacyDisclaimerAccessibilityCookies