arrow_backPolicy centre
shield_personEffective August 23, 2026 · Version 2026-08-23

Privacy Notice

This notice explains Medu's personal-data practices for accounts, learning tools, community features, payments, AI tools, advertising, and support.

Scope Data collected Purposes and bases Public content Service providers AI and medical data Ads and analytics Sharing International transfers Retention Your rights Security Age limit Contact

1. Who this notice covers

The operator of medu.courses ("Medu", "we", or "us") decides how personal data is used for the Medu service and acts as the controller or equivalent responsible organization where applicable law uses those terms. This notice applies to website visitors, account holders, purchasers, course participants, contributors, instructors, community members, and people who contact support.

Medu is international. This notice does not claim that one country's privacy law applies everywhere. If a mandatory privacy law gives you stronger rights, those rights remain available.

2. Personal data Medu may collect

  • Account and identity data: email address, authentication identifier, verification status, nickname, profile photo, language, country or broad location you choose to provide, and account role. If you choose Telegram authentication, this also includes your Telegram numeric user ID, optional username and display name, link status, and confirmation timestamps.
  • Community data: profiles, group memberships, friend relationships, messages, comments, ratings, reports, moderation records, voice-room participation, and content you upload or publish.
  • Learning data: course enrolment and progress, question-bank answers and scores, flashcard progress, saved items, study notes, tool settings, achievements, and AI usage counts.
  • Purchase, subscription, and referral data: product, price, currency, access period, order and subscription references, PayPal status and payer-related references returned to Medu, Bankak transaction ID and verification status, refund records, an opaque referral code, the selected referrer's account and public Member ID snapshot, referral reward and reversal records, policy versions accepted, and fraud-prevention signals. Medu does not receive your complete card number, CVV, PayPal password, Bankak password, or OTP.
  • Content submitted to tools: text, study material, prompts, answers, images, audio, filenames, and optional context that you choose to send to an AI or upload feature.
  • Support and communications: support tickets, email address, order reference, complaint details, attachments, and Medu's response.
  • Technical data: IP address and user agent processed by hosting, authentication, security, payment, advertising, or embedded-content providers; App Check and reCAPTCHA signals; timestamps; page path without query text in Medu's first-party analytics; broad device/browser category; coarse referrer category; performance timing; error events; cookie or local-storage identifiers; short-lived Telegram authentication challenge, confirmation, and abuse-prevention records; and short-lived verification-email and login-code-email delivery records linked to your account, including an opaque request reference, a one-way recipient digest, delivery state, and a limited failure category such as mailbox full, invalid address, temporary delay, or provider block.
  • Advertising data: where ads are active, Google and its partners may collect online identifiers, IP address, device/browser information, page interaction, consent signals, and inferred interests under their own notices.

Medu receives data directly from you, from your use of the service, from other users who interact with you, and from providers such as Firebase, PayPal, Bankak verification records, and Google advertising services.

3. Why Medu uses personal data

Depending on the feature and the law that applies, Medu relies on performance of a contract, steps requested before a contract, legitimate interests, consent, or compliance with a legal obligation.

  • Provide the service and purchases: create accounts, authenticate users, deliver courses and content, save learning progress, operate community features, process orders, maintain entitlements, and answer support requests. Usually necessary to perform the user agreement.
  • Safety and integrity: verify email, prevent abuse and payment fraud, enforce limits, moderate content, protect accounts, and investigate incidents. Usually based on legitimate interests and, where necessary, legal obligations.
  • Improve Medu: measure aggregate usage, reliability, errors, and feature performance. Usually based on legitimate interests; consent is used where required for device storage or analytics.
  • Communicate: send verification, security, purchase, service, and policy notices; notify the operator through a private Telegram bot message when a payment needs manual review or changes status. These are contractual or operational messages. Promotional email requires a separate lawful basis and an unsubscribe method.
  • Advertising and sponsorship: display, measure, limit, and, only where permitted, personalize ads. Consent or an opt-out is provided where applicable law requires it.
  • Legal and business administration: keep financial records, respond to valid legal requests, establish or defend claims, and manage a sale or restructuring of the service.

Medu does not use AI output to make a decision that produces legal or similarly significant effects about you. Automated systems may flag suspected spam, fraud, unsafe content, or usage-limit breaches; Medu may review consequential account action and provide an appeal where appropriate.

4. Public and shared information

Your nickname, profile photo, Member ID, public profile fields, public groups, course listings, posts, comments, ratings, and other content marked public can be viewed, indexed, copied, or reshared by others. When referral search is used, Medu returns at most a small set of public-profile matches using nickname or an exact Member ID; it does not return email addresses or Firebase account identifiers. Private messages and private learning records are not intentionally made public, but recipients can retain or disclose what you send them.

Cloudinary-hosted profile and banner images may be delivered through public URLs. Never upload patient-identifying images, identity documents, financial credentials, or other sensitive material. Deleting an item from Medu may not remove copies already saved by other people or indexed by independent services.

5. Service providers and independent services

Medu shares only the data reasonably needed for the relevant service. A provider may act for Medu, act independently under its own terms, or do both depending on the feature.

  • Google/Firebase: hosting, authentication, databases, Cloud Functions, Realtime Database, App Check/reCAPTCHA Enterprise, Google sign-in where selected, and security. Firebase Authentication may process email, IP address, user agent, and authentication credentials. Firebase privacy information.
  • PayPal: one-time card/PayPal checkout, recurring subscriptions, payment status, fraud controls, cancellations, and refunds. PayPal receives payment credentials directly. PayPal privacy information.
  • Bankak and participating banks: the transfer occurs outside Medu. Medu stores the transaction reference, expected amount, user/order link, and manual review result. Never send Medu a Bankak password, OTP, PIN, or complete account credentials.
  • Brevo: transactional email delivery, including verification and security messages. Medu sends Brevo the destination email and message content. Brevo also sends Medu delivery events such as accepted, delivered, delayed, bounced, invalid, or blocked so Medu can show you a safe diagnostic without exposing raw provider responses. Brevo privacy information.
  • Groq: AI generation, summarization, transcription, image analysis, question generation, flashcards, revision coaching, and case-answer scoring. The submitted text, audio, image, prompt, or limited study-performance data is sent to Groq. Groq privacy information and GroqCloud data information.
  • Cloudinary: user-selected profile photos and group/course images, upload tooling, transformation, and content delivery. Uploaded media may be publicly accessible. Cloudinary privacy information.
  • Cloudflare: temporary TURN credentials and network relay for voice-room connectivity where that feature is used; this can involve IP and connection metadata. Cloudflare privacy information.
  • YouTube/Google: embedded educational videos. Loading or playing an embed can disclose the page URL, IP address, device information, cookies, and viewing interaction to Google/YouTube. Google privacy information.
  • Telegram: optional authentication, private operator payment-review alerts, and links to communities, course groups, or support channels. For Telegram sign-in or account linking, Medu creates a short-lived challenge that you send to the MeduLogin bot and receives your numeric Telegram user ID, private-chat ID, optional username/display name, and confirmation interaction. Payment-review alerts sent to the operator's linked account contain a bounded status summary, Medu order reference or one-way reference digest, and the affected internal account identifier when needed for review; they do not contain passwords, OTPs, complete payment credentials, or the full Brevo payload. The linked identity is private by default, is not placed in your public Medu profile, and Medu does not request your Telegram phone number. Ordinary messages sent to the bot are not saved as Medu account content. Telegram is an independent service and processes bot interactions under its own terms. Community groups may expose your Telegram profile and activity to members according to your Telegram settings. Telegram privacy information.
  • Google advertising services: ad delivery, frequency control, measurement, fraud prevention, and, when allowed, personalization. How Google uses data from partner sites.

6. AI tools and sensitive medical information

AI inputs are sent through Medu's server to Groq to return a result. Medu records account-level usage and may record limited error metadata, but does not intentionally save raw AI prompts, source text, audio, or image files as permanent account content unless a feature clearly says that it saves them. Provider-side handling depends on Medu's provider settings and Groq's current terms.

Do not submit a real patient's name, face, voice, date of birth, record number, contact details, unique clinical history, or any protected or identifiable health information. Medu is not designed as an electronic health record or a service for regulated clinical data, and no healthcare privacy agreement is offered. Use de-identified educational material that you have the right to process.

7. Analytics, cookies, and advertising choices

For signed-in users, Medu's first-party analytics records allow-listed information such as page path, coarse device/browser category, coarse referrer type, page performance, and error counts. Medu excludes query text, message content, question answers, payment references, and email addresses from this analytics event. Session and account references are stored as one-way hashes.

Medu respects the browser's Do Not Track signal for its own first-party analytics. You can also change the first-party analytics setting for this browser below. This does not disable storage required for authentication, security, purchases, or settings.

Google ads may use cookies or similar identifiers. Medu does not sell personal data for money. However, advertising disclosures can be treated as a "sale," "sharing," or targeted advertising under some laws. Where applicable, use Medu's or Google's consent/opt-out controls. See the Cookie and Advertising Technology Notice and Advertising and Sponsorship Policy.

8. When Medu may disclose data

  • To the providers above to operate the requested feature.
  • To other users when you post publicly, join a shared space, send a message, or otherwise choose to interact.
  • To instructors or content providers only as needed to provide a course, manage participation, or address a support issue, subject to appropriate restrictions.
  • To professional advisers, auditors, insurers, and prospective business successors under confidentiality duties.
  • To authorities or other parties when Medu reasonably believes disclosure is required by valid law, necessary to protect rights or safety, or needed to investigate fraud, abuse, or security incidents.

Medu does not disclose private messages, detailed learning performance, AI submissions, or payment credentials to direct sponsors for their own marketing without your separate permission.

9. International data transfers

Medu and its providers operate across multiple countries. Data may be stored or processed in the United States, European Union, United Kingdom, or other locations where the providers maintain infrastructure or personnel. Privacy protections may differ from those in your country.

Where applicable law requires a transfer mechanism, Medu will rely on an adequacy decision, contractual safeguards, a recognized certification framework, or another lawful mechanism. Contact Medu to request available information about safeguards relevant to your data.

10. How long data is kept

Medu keeps personal data only as long as reasonably needed for the purpose for which it was collected. The current service does not apply one fixed period to every record. Medu uses the following criteria and will delete or de-identify data when the relevant purpose ends, unless a valid legal, security, accounting, or dispute reason requires it for longer:

  • Account, profile, learning progress, and active community content: kept while the account or relevant feature remains active and then reviewed following a verified deletion request.
  • Orders, subscriptions, referrals, refunds, policy acceptance, and financial records: kept for entitlement history, accounting, fraud prevention, payment reconciliation, referral-reward integrity, consumer claims, and any legally required record period. Short-lived checkout intents and pending-payment prompt-suppression records carry expiration metadata; owner Telegram alert records are scheduled for deletion after seven days.
  • Support and complaint records: kept until the matter is resolved and for a reasonable period needed to handle follow-up, demonstrate the response, or address a claim.
  • Security, moderation, fraud-prevention, and payment-attempt records: kept while needed to investigate the issue, protect the service, enforce a restriction, or establish or defend a claim.
  • Verification-email and login-code-email delivery diagnostics: account-linked delivery state, recipient digest, limited failure category, and provider-message digest are scheduled for deletion 72 hours after the request.
  • Telegram authentication: the linked Telegram identifier is kept while it remains attached to your account. Login challenges and request-rate records are short-lived, carry expiration metadata, and are scheduled for deletion after they expire.
  • First-party analytics: some visitor, session, and presence records carry expiration metadata; aggregate daily statistics may be kept longer to compare service performance. Medu will delete or aggregate identifiable analytics when it is no longer needed.
  • Raw AI submissions: not intentionally saved by Medu as permanent account content after the request completes unless you choose a feature that clearly says it saves the material. Provider retention is governed by provider configuration and terms.
  • Backups: deleted data may remain temporarily in restricted provider backup or disaster-recovery copies until the applicable backup cycle overwrites it.
  • Public or shared content: retained until you delete it, the account is deleted, or moderation removes it; copies held by other users or external services may remain.

Medu may retain a minimal suppression record after deletion to honour an opt-out, prevent fraud, establish a transaction, or avoid recreating a banned account where lawful. Aggregated information that no longer identifies a person may be retained.

11. Your privacy rights

Depending on your location, you may have the right to access, correct, delete, or receive a portable copy of personal data; restrict or object to processing; withdraw consent; opt out of targeted advertising or qualifying sale/sharing; appeal a refused request; and complain to your local privacy regulator. Withdrawing consent does not affect earlier lawful processing.

Email support@medu.courses from your registered address with the right you want to exercise. You may also use the data-deletion instructions. Medu may verify identity, ask an authorized agent for proof of authority, and refuse or limit a request only where applicable law permits. Medu will respond within the period required by applicable law and will not discriminate against you for exercising a right.

12. Security and incident response

Medu uses measures such as encrypted transport, managed authentication, access controls, server-side payment verification, App Check, rate limits, restricted administrative functions, and logging. No online service can guarantee absolute security.

If Medu confirms a personal-data incident, it will investigate, contain, document, and notify affected people and regulators where applicable law requires. You should use a unique password, protect your email account, and report suspected compromise promptly.

13. Adults only

Medu is restricted to users aged 18 or older and does not knowingly collect personal data from children. If Medu learns that an under-18 person has provided personal data, it will take reasonable steps to remove the account and data, subject to required security or legal records. A parent or guardian may report an underage account to the contact below.

14. Contact, complaints, and changes

Privacy questions or requests: support@medu.courses. Use the subject "Privacy request" and do not email passwords, OTPs, full payment credentials, or patient information.

Medu may update this notice as services, providers, or legal duties change. Material changes will be communicated where required, and the effective date and version will be updated. If you are not satisfied with Medu's response, you may complain to the data-protection or consumer authority available in your location.