Privacy Policy
Last updated July 2, 2026
This Privacy Policy explains what information MedAtlas collects, why, and what we do with it. We try to collect the minimum we need to run the product.
1. What we collect
- Account information: your email address, and — if you sign up with a password — a securely hashed version of it (we never store or can see your plaintext password). If you sign in with Google or Microsoft, we receive your email and account identifier from that provider, not your password.
- Payment information: if you subscribe, payment is handled entirely by Stripe. We receive your email, subscription status, and a Stripe customer reference — never your full card number.
- Usage data:which organs, mechanisms, and features you use, so the product can save your progress and (for signed-in users) resume where you left off. We use Vercel Analytics for aggregate, cookieless traffic and conversion metrics (which pages get visited, whether an upgrade completes) — it does not use cookies or build an advertising profile of you. We run no advertising trackers, and don't sell or share this data.
- Cookies: a single essential, HTTP-only session cookie that keeps you signed in. No advertising cookies.
2. What we don't collect
We don't ask for or store health information about you personally — MedAtlas teaches anatomy and physiology in general, not about your own body. We don't sell your data to anyone, ever.
3. How we use it
- To provide the service — authenticate you, remember your learning progress, process payment.
- To respond when you contact support.
- To improve MedAtlas — understanding which content is used and which mechanisms/features need work.
- To send you account-related email (password resets, receipts) — never marketing email without opting in.
4. Who we share it with
Only the processors we need to run the service: Stripe for payment, Vercel for hosting, and (once configured) Resendfor transactional email like password resets. We don't share your data with anyone else, and we don't sell it.
5. Your choices
- You can use most of MedAtlas without ever creating an account.
- You can request deletion of your account and associated data by emailing support@medatlas.app.
- You can cancel a subscription at any time (see Support).
6. Data retention
We keep account data for as long as your account is active, and for a reasonable period afterward in case you return or for legal/accounting reasons (e.g. payment records). Deleted-account requests are honored within a reasonable time.
7. Security
Passwords are hashed (never stored in plaintext), session cookies are HTTP-only and signed, and payment data never touches our servers directly — it goes through Stripe. No system is perfectly secure, but we take reasonable, industry-standard precautions.
8. Changes to this policy
If we materially change how we handle your data, we'll update the date above and, where required, notify you directly.
9. Contact
Questions about your data? Email support@medatlas.app.