# Privacy policy

> What is collected, where uploaded document text goes, which AI processors receive it, how long each kind of data is kept, and how to use your UK GDPR rights.

Markdown copy of https://meduniexam.com/privacy (the HTML page), published by MedUni Exam. Published September 11, 2026, updated September 24, 2026. Site guide for agents: https://meduniexam.com/llms.txt.

Last updated September 24, 2026

This English text is the binding version. The copies of this page in other languages are translations, for convenience.

## Who is responsible

MedUni Exam is operated by an individual trading as MedUni Exam, based in England. That person is the data controller for personal data processed through meduniexam.com, at Hailsham, East Sussex, BN27, United Kingdom. Contact us at [support@meduniexam.com](mailto:support@meduniexam.com) about anything in this policy, including a request to see or delete your data.

## What we collect

| Data | Why | Legal basis |
| --- | --- | --- |
| Email address and password hash (registered accounts) | To sign you in and keep your library across devices | Performance of the contract |
| Documents you upload and the text extracted from them | To generate and verify questions | Performance of the contract |
| Questions, answers, grades, mastery and review history | To grade you and schedule review | Performance of the contract |
| Session cookie | To keep you signed in; required for the site to work | Strictly necessary |
| IP address for short-lived rate limiting, and a daily one-way hash of it for the per-network counters | To stop abuse of sign-in, registration, uploads and generation | Legitimate interest in keeping the service available |
| Payment records: amount, currency, plan, Stripe identifiers | To give you what you paid for and to keep accounts | Contract and legal obligation |
| Two-letter country code of your network, kept with each upload, generation and exam start | To count how the service is used. The network address and the city are read only to leave out our own testing and are never stored: the address is compared, as a keyed hash, with networks we have marked as ours | Legitimate interest in knowing how the service is used |
| Referral records, if you share your link or arrive through someone else's: your referral code, which workspace a link brought in and when, and whether the bonus was credited | To credit the bonus questions to both sides, once | Performance of the contract |
| A daily one-way hash of your network, kept with the referral records: for a workspace that has a referral link (one is made the first time the app shows you your invite link, or when you share an exam), each time it loads the site, uploads a file or starts a generation; for the new workspace, when the referral is recorded and when it is credited | To refuse a referral credit when both workspaces were on the same network on the same day, which is how a person would refer themselves | Legitimate interest in preventing abuse of the bonus |
| A quote you choose to leave after rating the site 4 or 5 stars: the text, an optional first name and school, your rating and the time you gave consent | To show it on the site, and only after we have approved it | Consent, which you can withdraw at any time |
| Anonymous page views and conversion events | To see which pages bring people to the service | Consent for the analytics and advertising tools; legitimate interest for the anonymous first-party counter |

We do not ask for your name, your university or any health data about you, apart from two things you can choose to give: a first name on an exam link you share, and a first name and school with a quote you leave. Do not upload documents containing personal data about other people, including patient records.

## Where your document text goes

Generating a question means sending passages of your document to an AI provider. Depending on your plan and which providers are configured, that can be any of: OpenRouter, Groq, Cerebras, SambaNova, Mistral, Google, NVIDIA and Cloudflare Workers AI for generation, and Anthropic (Claude) for premium mode. Only the passages needed for the request are sent, together with the instructions for the task. These providers process the text to return a response; the ones used here state that data sent through their paid interfaces is not used to train their models, while free tiers of some providers may use submitted content for model improvement, so a free-plan job carries that risk; the app shows which lane a job will run on before you start it, and a paid plan keeps every job on the paid interfaces. Scanned pages are additionally sent to Google Cloud Vision for text recognition. If you are not comfortable with a document leaving our servers, do not upload it.

## Other processors

- **Cloudflare**: hosting, the database, file storage and network protection. Files and database records are stored in Cloudflare infrastructure. When the human check on the upload box is switched on, it is Cloudflare Turnstile, which sets no cookie for advertising and is used only to tell a person from a script.
- **Stripe**: payments. Stripe receives your email and billing details directly and we never see your card number. Stripe is a controller for its own fraud prevention.
- **Resend**: transactional email, for example a password reset link. Your address is also used for the weekly review digest, sent only in a week when questions are due, and for one reminder seven days before the exam date you set. Both are on by default for a registered account, and both stop when you switch them off on the account page or use the unsubscribe link in every message.
- **Google (Analytics and Ads) and Meta**: measurement and advertising, loaded only after you accept in the cookie banner.
- **Fonts**: the heading typeface is served from meduniexam.com itself, so no third party is contacted for it and nobody outside this site sees your IP address or browser when a page loads. No cookie is set by it, and the site falls back to a font already on your device if the file is blocked.

Some of these providers are outside the United Kingdom and the European Economic Area. Those transfers rely on the UK International Data Transfer Addendum and the European Commission’s standard contractual clauses.

## Cookies and similar storage

- **ef_session**: the sign-in cookie. Essential, set for 30 days, no consent needed.
- **ef_ref**: set only when you arrive on a referral link someone shared with you and tap the button that claims the bonus questions. Opening the link alone sets nothing. It holds the referral code, the time of the visit and a signature that stops it being written by hand, and nothing about you. First party and HTTP only, kept for 30 days and removed once the referral is settled.
- **meduni_consent** and **meduni_theme**: stored in your browser only, to remember your cookie choice for six months and your theme.
- **meduni_ui_lang**: the language you are reading the site in, kept for a year. It holds a language code and nothing else, and the server reads it so the page arrives in that language instead of switching after it loads. Essential to the choice you made, no consent needed.
- **Analytics and advertising cookies**: set by Google Analytics 4, Google Ads, the Meta pixel, the Reddit pixel and the TikTok pixel, each only when the owner has configured it and only if you choose Accept all. Until then Google Consent Mode is set to denied for analytics storage, ad storage, ad user data and ad personalization, and no advertising cookie is written.
- **First-party counter**: page views are counted server side as a day, a path and a referring website, with no identifier of any kind. Conversion steps (a sample exam finished, a file uploaded, a sign-up, a checkout, a purchase) are stored with your account id if you are signed in, with the campaign parameters the visit arrived on (utm tags or an ad platform's click id, kept in your browser's local storage for 30 days) and with the two-letter country code of your network. No IP address, no cookie and no name is stored by the counter. It runs whether or not you accept cookies because it uses none.

You can change your choice at any time from the Cookie choices link at the foot of this page, or from Cookie settings on your Account page in the app. Clearing site data in your browser also resets it.

## How long we keep things

- Documents, questions and results: until you delete them or delete your account, which you can do yourself at any time from the account page ([how deletion works](https://meduniexam.com/delete-account.md)).
- Messages sent through the feedback form: kept with the message, the page it was sent from and the browser it came from; the email address is removed when the account is deleted.
- Guest workspaces with no documents in them: deleted three days after the workspace is created.
- Guest workspaces that hold documents: the documents, and the stored files behind them, are deleted after 30 days with no activity in that workspace. Uploading, generating or taking an exam counts as activity, and so does signing in to it again. Create an account and your library is kept until you delete it.
- Sessions: 30 days, or until you sign out.
- Rate limiting records: a few hours. The per-network daily counters: three days, and the hash they are keyed by stops matching an address as soon as the salt rolls at midnight.
- Referral records: until either workspace is deleted. The daily network hashes of a workspace that has a referral link: 31 days, the life of a referral cookie and one day more, and like every daily hash they stop matching an address when the salt rolls at midnight. Both go sooner when you delete your account, or when a guest workspace expires.
- Exam share links, with the first name you typed on one: until you take the link down or delete your account. The links of a guest workspace go when the workspace expires.
- Student quotes: until you withdraw the quote or delete your account. A quote is shown only after we have approved it, and only while your rating of the site stays at 4 or 5 stars. To withdraw one, use the withdraw control under your quote in your account settings, or write to [support@meduniexam.com](mailto:support@meduniexam.com) and we delete it; deleting your account deletes it too.
- Password reset tokens: one hour.
- Payment records: six years, because tax law requires it.
- Anonymous traffic counters: kept as aggregates with no personal data.
- Usage records: one line for each upload, generation and exam start, with the time, the kind of action, the two-letter country of the network and, for a generation, the free or paid lane, the language and the number of questions asked. The line itself holds no account, name, document title or IP address, and is kept for 400 days. It points to the upload, job or exam record it counts, and only that record links it to your account. The record is deleted when you delete it, the document it belongs to or your account; after that, the line no longer links to you.

## Your rights

Under the UK GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to processing, and receive it in a portable form. Deleting the account does not need a request: the account page has a Delete account control, and [the deletion page](https://meduniexam.com/delete-account.md) says what goes and what tax law makes us keep. You can also withdraw consent for analytics and advertising at any time without affecting anything done before. Write to [support@meduniexam.com](mailto:support@meduniexam.com) and we will respond within one month. You can delete any document in your library yourself, which removes its questions and results at once. If you think we have handled your data badly you can complain to the Information Commissioner’s Office at ico.org.uk.

## Security

Passwords are stored as PBKDF2 hashes, never in readable form. Traffic is encrypted in transit. Session cookies are HTTP only, same site and secure. Access to a document is checked against its owner on every request. No system is perfect; tell us at [support@meduniexam.com](mailto:support@meduniexam.com) if you find a weakness and we will fix it.

## Children

The service is not intended for anyone under 16 and we do not knowingly collect their data.

## Changes

We update this page when the processing changes. The date at the top is the version in force, and material changes are announced in the app.

## Related pages

- [Terms of service: uploads, subscriptions, refunds, liability](https://meduniexam.com/terms.md): Terms of service.
- [Refund policy: 14 day cancellation and unused questions](https://meduniexam.com/refund-policy.md): Refund policy for subscriptions, passes and question packs.
- [Delete your MedUni Exam account from the website or the app](https://meduniexam.com/delete-account.md): How to delete your account yourself, and what is removed.
- [Contact MedUni Exam: support email, who replies and how fast](https://meduniexam.com/contact.md): Support contact details and a feedback form.
- [Exam questions in your own language, and what is checked](https://meduniexam.com/for/any-language.md): Every supported language in three tiers, and what each tier really covers.
