Privacy Policy
1. Scope of this policy
This Privacy Policy describes how PreMD (premd.org) (the "Service") collects, uses, stores, and protects information. It applies to the account workspace, the browser-only guest workspace, and the public pages of the site.
PreMD is an independent, non-commercial project, operated and maintained by an individual in the United States. It is free to use, is not funded by advertising, and is not affiliated with, sponsored by, or endorsed by the AAMC, AACOM, any medical school, or any test-preparation or admissions service.
Privacy questions, requests to access or delete your data, and reports of a suspected security incident should be sent to [email protected], which is monitored by the operator. Where these details change, this section and the revision date above will be updated.
Design commitments. The Service is built to require as little trust as possible. Your record remains yours: a complete export and a permanent deletion control are available to you directly in Settings, and neither requires contacting us. We do not sell or rent personal information, do not operate advertising or third-party behavioural tracking, and do not use your records to train generalised machine-learning models. Features that would require collecting more than the Service needs are disabled.
Community outcomes contribution is not available. The feature described in section 3 is switched off and collects nothing. No application-cycle facts are gathered, transmitted, or stored for community analytics. Section 3 is retained so that the design is documented in advance; if the feature is ever enabled, this policy will be updated and separate, unchecked consent will be requested before anything is sent.
2. Information we collect
Account information. When you create an account, we collect your email address and authentication credentials. If you sign in with Google, we receive your email address and basic profile information from Google in accordance with your Google account settings; we do not receive your Google password.
Private Student Records. The substance of the Service is a record you author yourself: coursework and grades, study plans and logs, practice scores, clinical and volunteer experiences, activity descriptions, essays and drafts, school lists, interview records, expenses, and similar material ("Student Records"). They power your private tools and are not automatically copied into community analytics.
Feedback, reviews, and community discussions. If you submit feedback or a review, we collect the content, selected category, and account identifier. If the separately gated discussion community is enabled and you join it, we also collect your pseudonymous handle, optional applicant-stage and perspective fields, your choice about displaying that context, adult and rules attestations, posts, responses, quoted excerpts, votes, blocks, reports, automated screening status, moderation status, and timestamps. Your authentication identifier remains server-side and is not returned on public discussion pages. Contributions that pass the narrow automated screen are public immediately; material containing obvious contact information, identifiers, spam patterns, threats, or confidential-interview language is held for review. A score-adjusted threshold of distinct reports may also withhold visible material for review. Do not submit names, contact details, patient information, confidential interview material, or anything else you do not intend to disclose publicly.
Secondary-prompt submissions and confirmations (optional). Your private secondary drafts remain Student Records. If the separately gated prompt library is enabled and you submit prompts for verification, we collect the school, cycle, exact prompt text, source category, an official source URL when provided, your account identifier, moderation status, and timestamps. If you attest that you personally received every prompt displayed in a current-cycle collection, we collect your account identifier, the collection, timestamp, and an optional private note for moderators; public users see only the total number of confirmations. A confirmation does not claim the displayed collection is exhaustive or grant republication rights. Remove applicant names, IDs, portal tokens, invitation links, and other personal details before submitting either form. Pending sets and confirmation notes are visible only to authorized reviewers. Public responses are shaped by an active reviewed rights record: exact wording, excerpts, links, history, and comparisons remain unavailable unless their individual permissions are true. School/cycle metadata and independently authored themes may remain available when authorized; your account identifier does not become public.
Google Calendar (optional). If you choose to sync your study plan to Google Calendar, Google issues the Service a short-lived permission limited to events on calendars you own. PreMD uses that permission in your browser only to create, update, and (when you expressly choose “Remove synced events”) delete the study-plan events PreMD placed on your primary calendar. The permission is requested only when you click the sync or removal button, is held only in the memory of that browser tab, and is never stored by us. IDs of events created by PreMD are retained on your device so removal can be retried; they are not uploaded to your PreMD account. We do not read, copy, or retain existing calendar contents, and no Student Records are sent to Google other than the study-task titles and times you asked to place on your calendar. You can revoke the permission at any time from your Google account's security settings, and you can use the calendar-file (.ics) export instead without connecting anything. PreMD's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalized AI or machine-learning models, do not transfer it to third parties, and do not use it for advertising.
Interview practice recordings (optional). Camera and microphone media is processed in your browser and is not uploaded by the current Service. A recording is not retained until you choose to save it to private browser storage on that device. Practice metadata and reflections become part of your private Student Records. You can replay, download, or delete a saved recording from Practice history; clearing browser storage can remove recordings you have not downloaded. If an older release previously stored a recording in your private account, the current Service keeps retrieval and deletion available but does not create new cloud recordings.
AI Assistant (optional). The default on-device model processes a minimized record summary and chat locally. If you separately choose and authorize a named bring-your-own-key provider, this browser sends your messages, the prior messages in that open chat, and an exact previewed minimized summary directly to that provider. The summary excludes names, email, recommender identifiers, course titles, essays, notes, organizations, and financial entries. Your API key and provider-specific consent stay in this browser and are not synchronized to PreMD.
Basic service and security data. Supabase and Cloudflare necessarily process request times, IP addresses, browser/device signals, and security events to deliver the Service and prevent abuse. When configured, Cloudflare Turnstile runs on authentication forms and evaluates browser signals to issue a short-lived anti-bot token. No behavioral or performance analytics beacon is enabled. Any future analytics proposal requires documented privacy review, a policy update, and a matching security-policy change before activation. Infrastructure logs and backups are separate from the contribution preview.
What we do not collect. We do not collect advertising identifiers, run third-party advertising, marketing, session-replay, or cross-site behavioral trackers, or sell or rent personal information.
3. Optional community outcomes contribution
Adults may separately choose to contribute a minimized copy of selected application-cycle facts to produce community-level admissions information. This feature is off by default, is not required for any private feature or to view released results, and is not part of signup consent.
Before upload, PreMD displays the exact eligible snapshot: random snapshot ID, contract and consent versions, matriculation cycle, canonical school/program code, program type, half-month milestone periods, outcome, matriculation and cycle-complete indicators, state of legal residence at state level, and optional first-time/reapplicant status. Broad cGPA, science-GPA, and official-MCAT bands require one separate unchecked choice. Five broad per-cycle experience-hour bands (clinical experience, physician shadowing, non-clinical service, research, and leadership) require another separate unchecked choice. Exact hours, activity dates, titles, descriptions, employers, and organizations never enter that minimized snapshot. Names, email, account ID, essays, notes, recommendation writers, exact addresses or ZIP codes, exact dates, exact grades or scores, and the private record as a whole are excluded.
The authenticated service separately processes the account ID and an account-to-random-cycle-key mapping to prevent duplicate cycles and honor correction, withdrawal, and deletion. This is pseudonymization, not a promise of anonymity. Public pages receive only delayed, fixed aggregate releases that pass contributor, parent, numerator, complement, complementary-suppression, and independent-review controls, never applicant rows or an unrestricted query interface. See the Community Outcomes Methodology.
4. How information is used
- To provide the Service: storing, displaying, and synchronizing your Student Records across your devices.
- To operate accounts: authentication, security notices, and service communications.
- To improve the Service: reading feedback and bug reports you choose to send.
- To publish reviews you submit, only after moderation and only with the display name you provide.
- To privately queue and verify cycle-specific secondary prompts you intentionally submit, and to publish only the wording, excerpts, themes, comparisons, history, and source links permitted by a separately reviewed rights record.
- If you separately opt in, to validate minimized outcome facts, prevent duplicates, honor lifecycle controls, and prepare disclosure-reviewed aggregate releases.
We do not sell Student Records or contributions, use them for advertising, provide applicant-level data to schools or recruiters, or use community data to make admissions decisions or individual “chance” predictions.
5. Storage, retention, and security
Student Records are stored with Supabase, our database and authentication provider, in an access-controlled database. Row-level security policies are enforced at the database layer so that each account can read and write only its own records. Data is transmitted over encrypted connections (HTTPS/TLS). A copy of your most recent records may also be cached in your own browser's local storage to allow the Service to load quickly and operate offline.
No method of storage or transmission is perfectly secure; we cannot guarantee absolute security, but we apply reasonable administrative and technical safeguards appropriate to the nature of the data.
Raw pseudonymized outcome facts expire after the cycle plus twelve months, with a ninety-day processing minimum and an absolute thirty-month cap from ingestion. The identity mapping exists only while facts remain. Payload-free snapshot review evidence and consent/withdrawal evidence may be retained for up to six years for accountability, unless the user invokes contribution-record or account deletion. Draft release identity links expire within seven days and are deleted immediately after publication. Fixed aggregates contain no applicant rows and may remain published or quarantined for audit. Provider backups and infrastructure logs follow their documented schedules.
Unpublished secondary-prompt submissions and prompt-set confirmations are deleted with the submitting account. A separately rights-reviewed public prompt record may remain after account deletion only for its recorded permitted uses; the submitter link is removed and the confirmation total is recalculated. A visible correction or takedown control is available in the library, and you may also report an incorrect, private, outdated, or rights-sensitive record to [email protected].
A structured prompt copy stored by an older community-discussion release is removed from the ordinary community record and held in a restricted quarantine for rights, retention, correction, or takedown review. It is not returned by community APIs or ordinary moderation tools and is deleted if its parent post is deleted. The operator must complete the documented owner/counsel retention review before keeping, restoring, or otherwise using quarantined wording.
6. Sharing and disclosure
We do not sell, rent, or trade personal information. Necessary providers include Supabase for database/authentication, any enabled discussion or prompt-library content, and retrieval or deletion of private interview recordings created by an older release; Cloudflare for hosting, content delivery, and optional Turnstile security; Google if you choose Google sign-in or Calendar sync; and the specific AI provider only if you explicitly authorize BYOK. New interview recordings are not sent to Supabase. Calendar events and external-AI requests are governed by the recipient's terms. Community outcome pages disclose only reviewed aggregate releases; separately enabled discussion pages disclose visible pseudonymous contributions, while prompt-library pages disclose only the text, independently authored themes, metadata, and source links allowed by an active reviewed rights record.
7. Browser storage and operational measurement
The Service uses local/session storage for authentication, offline record caching, preferences, same-tab guest handoff, and device-local AI keys/consent. If you explicitly save an interview recording, IndexedDB stores it on that device until you delete it or clear the site's browser data. No analytics beacon is enabled, and we do not use advertising or cross-site tracking cookies.
8. Your rights: access, correction, export, withdrawal, deletion
Your records belong to you. From Settings you can, at any time and without asking us:
- Export your complete record as a structured file, and individual records (coursework, scores, experiences, school lists, essays, and more) in spreadsheet form;
- Reset your private workspace locally and in the synchronized profile without changing separately controlled outcomes consent;
- Correct or replace a contributed snapshot, withdraw to delete active raw facts and mapping, or delete contribution records including retained consent/review/log evidence;
- Delete your account in-product after recent authentication, removing the account, private profile, any legacy private-account recording, authored feedback/reviews, community profile and contributions, unpublished prompt submissions, retained outcomes records, and app-owned browser data. Reviewed public prompt sets may remain without the submitter link.
Withdrawal affects future processing and releases. A fixed aggregate already downloaded, cached, quoted, or published is not retroactively recomputed because it contains no applicant row; PreMD may terminally quarantine it. For a request you cannot complete in the app, contact [email protected].
9. Children's privacy
PreMD is for adults aged 18 and older. A user must affirm that they are 18 or older before a new account is created, before an existing or OAuth account opens its private record, and before guest mode begins. The confirmation is retained with account metadata, or for the current guest browser session; PreMD deliberately does not collect a birth date, because a date of birth is more personal information than the age check requires.
We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created a record, contact us at the address in section 11 and we will delete the account and its records. This is a deliberate choice: PreMD holds detailed academic records, and restricting the Service to adults removes an entire category of risk for its users rather than managing it.
10. Changes to this policy
We may revise this policy as the Service or law evolves. Material changes receive a new revision date and, where appropriate, in-product notice. A material outcomes-purpose, field, or recipient change requires a new versioned affirmative consent before another upload.
11. Contact
Privacy questions, requests to access or delete your data, and reports of a suspected security incident go to [email protected], monitored by the maintainer identified in section 1. Most access and deletion requests need no correspondence at all: Settings has a full export of your record and a delete control for your workspace and account, and both take effect immediately.