{"kind":"privacy","version":"2026-08-28","body":"This says what M&M Surgical Review stores about you, where it is kept, who else can reach it, and what happens when you ask for it to go. It describes the app as it is built today, not as it might be later.\n\nMohammed Alismail\nMohammed Buhalim\n\n\nOne part of the system runs in the United States: the administration console, which is the private screen the owner uses to review content and look after accounts. It keeps no copy of the database — it asks the Amsterdam server for what it shows — but the account list it displays, which includes email addresses, is assembled by a program running in Washington, D.C.\n\nWHAT WE STORE\n\nYour account. Your email address. Your password, stored as an argon2id hash, so we never hold the password itself and cannot read it. When you confirmed your email address. When the account was created, and when it was last changed.\n\nYour devices. One row for every device you sign in from: a label that is one of three words — \"iPhone\", \"Android\" or \"Web\" — when you signed in, when the session was last used, and when it expires. We do not store your IP address, and we do not store which handset or which browser you use. The sign-in token itself is stored as a SHA-256 hash, so a copy of our database contains nothing anybody could sign in with.\n\nYour reading. Which topic you were last reading and how far through it you were, and which passages you bookmarked. That is all. We do not record how long you read for, how often you open the app, or what you searched for.\n\nWhat you agreed to. Two records: that you accepted the Terms of Service, and that you accepted this Privacy Policy — each naming the version of the document you were shown, and the date. That is what makes your consent evidence rather than an assertion.\n\nYour training level and exam target. These are kept on your phone and are never sent to us. Nothing on our server stores them.\n\nThe practice section. No question is being served yet, so there is nothing of yours in it.\n\nPayment. Nothing. No card is taken, stored or processed anywhere in this product, so there are no card details, no billing address and no payment history.\n\nWHY WE STORE EACH OF THESE\n\nYour address and your password are how you sign in, and how we can tell one account from another. Without them there is no account.\n\nYour devices are stored so you can see where you are signed in and end a session you do not recognise.\n\nYour reading position and your bookmarks exist because you asked for them, by reading and by bookmarking. They are the point of having an account at all.\n\nYour consent records exist because we have to be able to show which text you agreed to and when. They are kept for as long as the account exists.\n\nEach of these is a separate purpose, recorded separately, so that agreeing to one is not treated as agreeing to all of them.\n\nWHO ELSE CAN REACH IT\n\nRailway, in Amsterdam. They run the server and the database, and everything above is on their machines.\n\nCloudflare, which serves the illustrations in the book. Those are pictures from the book and carry nothing about you.\n\nGitHub, which holds the app's source code and the text of the practice questions. It holds nothing about you.\n\nNobody else. In particular there is no email provider: no email service is configured, which is why the app cannot currently send you a confirmation code, and why nothing outside the systems above holds your address. When an email provider is added, this document gets a new version naming it.\n\nAnd there is no crash-reporting service and no analytics. The app reports nothing to a third party about how you use it. There is no advertising, no tracking, and nothing is sold or shared with anybody.\n\nHOW LONG WE KEEP IT\n\nYour account and everything attached to it stay for as long as the account exists. When you delete it, what happens is set out below, and it happens immediately.\n\nSign-in codes and password-reset codes last fifteen minutes and are destroyed once used.\n\nSessions expire on their own. A session slides forward while you keep using it and lapses after thirty days without use, and it stops for good one year after you signed in, whatever happens in between.\n\nWHAT YOU CAN ASK FOR\n\nYou can ask what we hold about you, ask for something wrong to be corrected, and ask for it to be deleted. Deleting is something you can do yourself, from the app, and the section below says exactly what it does. Write to us for the first two, at the address at the top of this document.\n\nDELETING YOUR ACCOUNT\n\nYou can delete your account at any time from the app. You will be asked for your password first, because deleting is permanent and cannot be undone by us or by you.\n\nWhat we destroy. Your email address, your name, your password, your training level and exam track, your bookmarks and the notes in them, your reading progress, your practice attempts and answers, your saved questions and conversations, and your record of the terms and privacy versions you accepted. We also destroy every record of the devices you signed in from, including when you signed in and how long you stayed. These are deleted outright, not hidden or archived, and we cannot recover them.\n\nWhat remains, and why. Your account row itself is not removed. It is emptied and left in place holding a randomly generated identifier and a placeholder address at a domain that can never receive mail. We keep it because our medical governance records — the record of who approved each piece of clinical content, and when — refer to that identifier, and those records cannot be altered or deleted by anyone, including us. Removing your account row would either break those records or require us to rewrite them, and a medical approval trail that can be rewritten is not a trail.\n\nThis is deliberate, and it applies to you specifically if you reviewed content. If you were a reviewer or an administrator, the decisions you made — which topics you moved through medical review, approved or published, when, and any note you attached — stay linked to your identifier permanently. Deleting your account does not detach your name from a clinical approval, because the safety of the content depends on every approval remaining attributable. The identifier is not your name and cannot be turned back into your name or your email address by us or by anyone reading our database. But it is stable, and everything that identifier ever did stays visible against it.\n\nWhat our activity log keeps. We keep a permanent, unalterable log of account events: that an account was created, that its address was verified, that its password was reset, that its role changed, and that it was deleted. Each entry records the identifier, what happened, and when. It never records your email address, your name, your IP address or your device. This log cannot be edited or erased — that is what makes it worth keeping — so the timestamps of those events survive your deletion.\n\nWhat this means honestly. Because those timestamps remain, someone with direct access to our database could tell that an account was created at a particular moment, that it was deleted at a particular moment, and what content decisions it made in between. If they already knew when you signed up or when you asked us to delete your account, they could match that to the remaining record. We have removed everything we can without breaking the medical approval trail — your account's stored creation date is reduced to a date with no time, and all sign-in history is destroyed — but we do not claim the remainder is anonymous. It is stripped of everything that names you, and it is not reversible into your identity, but on a service of our size it may still be possible to single out one deleted account.\n\nSigning up again. The address you used is released when your account is deleted, so you can register again with it. That will be a new account with a new identifier, and it will not be connected to the old one.\n\nCHANGES TO THIS DOCUMENT\n\nThis document has a version, printed at the top of this screen. When it changes, the new text gets a new version and the old one is kept, so the version recorded against your account still means something and can still be read.","publishedAt":"2026-08-28T00:09:12.668Z"}