What this site records, what the application stores, and the things MedGrades deliberately never wants to hold.
MedGrades is built to hold as little about a patient as possible.
You are asked never to enter a patient name, a hospital number or any other identifier, and the application warns you when it detects one. Case material is readable by your account alone. Photographs are read for their text and are not kept. Nothing about a case is ever sent to an advertising or analytics service.
Everything below states that in full, and names who to write to if any of it goes wrong.
Who this policy covers
MedGrades is an educational platform for medical students, interns and residents in India. This policy covers two separate things: the marketing website at https://medgrades.in, and the MedGrades application where students prepare cases. They collect different information and are described separately below.
What the marketing site collects
This website runs first-party analytics only. When you open a page, a small event is sent to this site’s own server recording what happened, not who you are.
- Event names come from a fixed allowlist. A page view, a call-to-action click, an FAQ panel being opened. Anything not on that list is discarded by the server rather than stored.
- Properties are enum-like and length-capped. A handful of permitted keys with short values. Free text cannot be sent through this channel.
- No third-party trackers run on this site. No advertising pixel, no session recorder, no social widget, no third-party tag manager. Fonts are self-hosted, so no request leaves your browser for a font provider either.
- No cross-site profiling. Nothing here follows you to another website, and nothing is sold, shared or joined with an advertising profile.
Standard server logs, including an IP address, may be recorded by our hosting provider for security and abuse prevention. They are not used to build a profile of you and are kept only as long as they are useful for that purpose.
What the contact form collects
The contact form asks for four things: your name, your email address, the closest description of your role, and your message. Nothing else is requested and nothing else is recorded from the form.
We use it to reply to you. Submissions are held by Netlify, who host this website, so that an enquiry is not lost, and they are read only in order to answer you. The message body is not written to our application logs. Please do not include patient information in a message to us.
What the application collects
If you create a MedGrades account, the application holds the information it needs to be useful to you:
- Account details: your name, email address and stage of training.
- Case information you enter: text you type, audio you record, photographs of case sheets or reports you upload, and the structured record built from them.
- Learning activity: presentations generated, practice sessions completed, questions answered, and the weak areas identified from them.
- Subscription status: whether you are on a trial or a paid year. Payment itself is handled by Razorpay.
Payment card, UPI and net banking details are entered on Razorpay and are never seen or stored by MedGrades.
What you must never enter
MedGrades is a learning tool, not a medical record. It does not need to know which patient a case belongs to, and it is designed so that it never has to.
Do not enter any of the following into the application:
- Patient names, or the names of their relatives.
- Phone numbers or email addresses belonging to a patient.
- Home addresses or any other location that identifies a patient.
- Hospital registration numbers, unit record numbers, IP or OP numbers, or bed identifiers tied to a named patient.
- Government identifiers of any kind, including Aadhaar, PAN, ration card or insurance numbers.
- Photographs of faces, or of any image feature that identifies an individual.
Photograph the clinical content of a case sheet, not the header that names the patient. Everything MedGrades does clinically works from findings, not from identity.
Your institution’s rules on patient confidentiality continue to apply to you in full. This policy does not replace them and cannot loosen them.
How case data is stored and deleted
Case data is stored so that it is available to you across your devices and across the days of an admission. It is transmitted over encrypted connections and held in access-controlled storage.
- Your cases are yours. They are not shown to other students, to faculty or to your college.
- You can delete an individual case from within the application, and you can request deletion of your entire account by writing to us.
- Deletion removes the case from the application. Backups age out on their own schedule, so a deleted case may persist briefly in a backup before it is overwritten.
- Your case content is not sold, and it is not used to advertise anything to you.
Where processing is carried out by service providers, such as hosting, storage or the language models that generate presentations and questions, those providers act on our instructions and are bound by contract.
Your choices
You can ask what we hold about you, ask for it to be corrected, ask for your account and case data to be deleted, or withdraw from the service entirely. Write to hello@medgrades.in and say what you want done.
The scope of these rights, the timelines we must meet and the grievance route available to you all need to be set out precisely once this document has been through legal review.
Changes to this policy
If this policy changes materially, the updated date at the top of the page changes with it and account holders are told. Continuing to use MedGrades after a change means the updated policy applies to you.
Age
MedGrades is built for students already in the clinical years of an MBBS course, and an account is intended for a person aged eighteen or over. If you are under eighteen, do not create an account without a parent or guardian giving consent on your behalf, which the Digital Personal Data Protection Act, 2023 requires us to obtain and verify before processing your data.
If we learn that an account belongs to someone under eighteen without that consent, we close it and delete the data held under it. Tell us at privacy@medgrades.in if you believe this applies to an account.
Where the data sits
Case data is stored in Google Cloud Firestore in the asia-south1 region, which is Mumbai. Authentication is handled by Google Firebase Authentication. Payments are handled by Razorpay, an Indian payment aggregator authorised by the Reserve Bank of India, and MedGrades never receives your card, UPI or net banking details.
Preparing a case sends the text you supplied to a language model provider for processing. That text is processed to return your preparation and is not used to train a model. Because that provider operates outside India, this is a cross-border transfer, and it is one more reason the application asks you never to enter anything that identifies a patient.
Grievance officer and escalation
Under the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, the following person answers privacy questions, consent withdrawals, correction requests and deletion requests for MedGrades.
- Grievance officer: Somesh, Founder
- Operated by: Leads Meister LLP
- Address: Belagavi, Karnataka, India
- Email: privacy@medgrades.in
We acknowledge a request within seventy-two hours and resolve it within thirty days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India, which is the statutory authority under that Act. Nothing in this policy limits that right.
Something here unclear?
If any part of this policy does not answer the question you actually have, ask it. We would rather rewrite a paragraph than leave it ambiguous.
