CMD Med is desktop only for now — open it on a laptop or desktop to continue.

← cmdmed

Privacy Policy

Last updated: May 2026

cmdmed ("we", "us", or "our") operates https://cmdmed.co.uk. This page informs you of our policies regarding the collection, use, and disclosure of personal information when you use our service.

1. Information We Collect

We collect the following types of information:

  • Account information — your name and email address when you sign in with Google.
  • Usage data — pages visited, questions answered, study session progress, and scores.
  • Device data — browser type, operating system, and IP address for security and analytics.

2. How We Use Your Information

We use your information to:

  • Provide and maintain the cmdmed service
  • Track your study progress and personalise your experience
  • Send service-related communications (e.g. security alerts)
  • Monitor and improve the platform
  • Comply with legal obligations

We do not sell your personal data to third parties.

3. Authentication

We use Google OAuth via Supabase for authentication. When you sign in, Google shares your name and email address with us. We do not store your Google password. You can revoke access at any time via your Google account settings.

4. Data Storage

Your data is stored securely using Supabase, hosted on AWS infrastructure in the EU. We apply row-level security so that only you can access your personal study data.

5. Cookies

We use strictly necessary cookies to maintain your session. We do not use advertising or tracking cookies. By using cmdmed, you consent to this use of cookies.

6. Data Retention

We retain your data for as long as your account is active. You may request deletion of your account and associated data at any time by emailing hello@cmdmed.co.uk. We will action your request within 30 days.

7. Your Rights

Under applicable data protection law (including UK GDPR), you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict our processing of your data
  • Data portability

To exercise any of these rights, email hello@cmdmed.co.uk.

8. Third-Party Services

We use the following third-party services:

  • Supabase — database and authentication
  • Google OAuth — sign-in

Each service has its own privacy policy governing use of your data.

9. Children's Privacy

cmdmed is not directed at anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "last updated" date. Continued use of cmdmed after changes constitutes acceptance of the updated policy.

11. Contact

If you have any questions about this Privacy Policy, please contact us at hello@cmdmed.co.uk.