Draft for legal review

M&M General Surgery

Privacy Policy

This website draft explains the product’s current data practices in plain language. It is not a replacement for the versioned Privacy Policy published inside the application.

Scope and status

This draft covers the public M&M website and the M&M learner application. The operative in-app policy is the version presented during account registration and stored with the user’s consent record.

This public website uses no analytics, advertising trackers, third-party fonts or embedded social media. It does not set marketing cookies.

Information the product handles

M&M handles only the information needed to provide accounts, learning features, security and subscription access.

  • Account information such as email address, password hash, verification status and consent version.
  • Learning information such as reading position, bookmarks, highlights, practice attempts and recalled answers.
  • Subscription and entitlement records, including verified Apple transaction identifiers when Apple purchases become active.
  • Operational records needed for authentication, security, service reliability and an append-only review trail.

How information is used

Information is used to sign users in, deliver published content, save study activity, resolve access, protect accounts, provide support and keep required product records.

M&M does not sell personal information and does not use study activity for advertising.

Service providers and location

The service uses infrastructure providers to host the website, API and database. Email delivery is handled through the configured transactional email provider. Apple will process App Store purchases under Apple’s own terms when the listing is active.

Providers receive only the information required for their part of the service. Their own policies and legal obligations also apply.

Retention and account deletion

M&M keeps information for as long as needed for the service, security, legal obligations and the integrity of its review history. Retention periods should be confirmed by counsel before this draft is published as an operative policy.

The application provides an account-deletion path. Personal profile and study data are destroyed or pseudonymised according to the product’s erasure rules. Some audit, consent and transaction records may remain when they must preserve an accurate historical record.

Security

M&M uses access controls, server-side authorization, protected sessions, encrypted transport and restricted operational access. No online service can promise absolute security.

Your choices and rights

Depending on applicable law, users may ask to access, correct or delete personal information, or raise a concern about its use. Requests are reviewed against the identity, safety and record-keeping requirements that apply to the account.

Contact and changes

Privacy questions can be sent to dr.moalismail@gmail.com. Material policy changes are published as a new version rather than silently changing the version a user previously accepted.