Who we are
Medora is a practice-question and exam-preparation service for medical students, operated by Shekhar. This policy explains how Medora handles information when you visit the site, create an account, practice questions, or provide feedback.
For privacy questions or requests concerning your information, contact shekhargugnani@gmail.com.
Information we collect
- Account information: your account identifier, name, email address, email-verification status, and account role. Our sign-in provider, Clerk, also manages your profile, connected sign-in methods, and sessions.
- Study activity: the subjects, sections, and questions in your practice sessions; answers and results; saved position; flags, crossed-out choices, and highlights; and session dates and active study time.
- Preferences: your display theme, highlight settings, and question controls. The browser also remembers test-builder selections on your device.
- Feedback and support: messages and files you choose to share with us, together with relevant account, page, question, and submission details. Administrative feedback can include images, recordings, annotations, comments, and transcripts. Question reviewers' comments and review actions are also recorded.
- Technical information: our authentication and hosting providers may process information such as IP addresses, browser and device details, request times, and error or security logs to deliver and protect the service.
Google sign-in
If you choose Google sign-in, Google shares basic identity information with Clerk, including your Google account identifier, email address and verification status, name, and profile picture when available. Medora requests only basic sign-in permissions: OpenID, email, and profile.
We use this information to sign you in, identify your account, display your profile, apply account access, and associate your saved work with your account. Clerk stores authentication and profile information. Medora stores the account identifier, name, and verified email in its application database, alongside your role and study records.
Medora does not request access to your Gmail messages, Google Drive files, calendar, or contacts. Signing in with Google does not give Medora your Google password. We do not sell Google account information or use it for advertising.
You can remove Medora's Google connection through your Google Account's third-party connections settings. Removing the connection does not itself delete information already stored by Clerk or Medora. Contact us to request deletion of that information.
How we use information
We use information to operate accounts and control access, save and resume practice sessions, calculate and display results, remember preferences, respond to support requests, review question corrections, and investigate bugs or misuse.
Feedback can be reviewed by the team maintaining Medora. Administrative recordings may be transcribed through OpenAI, and feedback, screenshots, and transcripts may be reviewed with AI-assisted development tools to understand and fix reported problems. These workflows concern submitted feedback, not a feature that automatically sends every student's study history to an AI service.
Service providers and access
Medora uses Clerk for authentication, Convex for application data and uploaded files, and Vercel for website hosting. Google handles Google sign-in. OpenAI is used when administrative recordings are transcribed. These services receive information needed for their respective functions. The development team may also process feedback with its development and review tools.
Authorized administrators and maintainers can access information needed to manage accounts, support users, maintain the service, and review feedback. Access to administrative and question-review features is controlled by account role. Other students are not given access to your private study records through the app.
Feedback files can be accessible to someone who has a direct file link. Avoid including passwords, patient information, or other sensitive material in screenshots, recordings, and support messages.
We may disclose information when required by law or when necessary to investigate abuse or protect the service and its users.
Cookies and browser storage
Clerk uses cookies and related browser mechanisms to support authentication and sessions. Medora uses local browser storage to remember question-selection and test-builder choices. Some display preferences are also stored with your account.
You can clear or restrict cookies and local storage through your browser. This can sign you out or reset preferences. Clearing browser storage does not delete study records stored with your account.
Retention and deletion
Medora retains account information and saved study activity so you can return to your work. Study records do not currently expire automatically. Feedback, attachments, transcripts, and review history may remain available after an issue is marked resolved.
To request access to, correction of, or deletion of your information, email shekhargugnani@gmail.com from the address associated with your account. Tell us whether your request covers your account, study records, feedback, or particular files. We may need to verify that the request comes from the account holder.
Deletion requests need to cover both authentication records and application records. Disconnecting Google or deleting an authentication account does not automatically remove Medora's separate study and feedback records. We will assess requests across the relevant systems and explain any information that needs to be retained for legal or security reasons. Provider backups and logs may follow separate retention schedules.
Security
Medora uses HTTPS, authenticated sessions, and account-based access checks to protect information. No online service can guarantee complete security. Contact us if you believe your account or information has been accessed without authorization.
Intended audience
Medora is intended for medical students and exam preparation. It is not designed to collect patient records or provide medical care, and it is not directed to children under 13. Do not submit identifiable patient information. If you believe a child under 13 has provided personal information, contact us so we can investigate and address it.
Policy updates and contact
We will update this page when our information practices change and identify the date of the current version. If we propose a new use of Google account information, we will provide the disclosures and request consent required before using it for that new purpose.
Operator: Shekhar. Privacy and deletion requests: shekhargugnani@gmail.com.