Privacy Policy
Last updated 11 September 2026. Questions, or want your data? Email usmlepulse@gmail.com.
The short version
- We collect your name, email, and what you do while studying. Phone number only if you book a tutoring session.
- We never see your card number. Payments go to Kashier or Apple; we get back a confirmation and an expiry date.
- We do not use cookies and there is no advertising or tracking on this site.
- We do not sell your data, and we do not share it for anyone else's marketing.
- Every other company that touches your data is named in Who else sees it, all eight of them.
- You can delete your account, and everything with it, from Dashboard → Security.
Who we are
USMLE Pulse is an exam-preparation service operated from Egypt. For anything in this policy, a copy of your data, a correction, a deletion, or a complaint, write to usmlepulse@gmail.com and a person will answer.
We are the controller of the personal data described here.
What we collect
Your account
Your name, email address, and the country your connection appears to be in. A profile photo if you upload one. A phone number only if you book a tutoring session, because the tutor may need to reach you. We do not ask for your gender or your address.
Your date of birth, which we ask for once when you create an account. We use it for one purpose: to know that we are not keeping an account for a child, which is what the Children section below promises. It is not used for anything else, it is never shared, and it is never used for advertising. You can see it in your data export.
What you do while studying
Your study plan and the order you put your modules in, which tasks you have completed and when, your focus sessions, your streak, your garden, the questions you have answered, your own recall ratings, and your scores on any NBME forms you choose to log. This is the substance of the product: without it there is no plan and no progress screen.
Things you write
Anything you write inside the product is yours and is stored against your account only: your own edits to a card, and anything you draw or write by hand over a question or over the notes. These are private to you. Moderators can see the wording of the shared cards, which is the same for everybody; they cannot see what you have written in your own margins.
Study measurements
We record how long your focus sessions ran, which cards you reviewed and when, and how you rated your own recall, because that is what the study schedule and the progress screen are built from. There are no marks and no scores: the ratings are your own assessment of your recall, and every number we show from them is labelled as self-reported.
Payment
Whether you have an active subscription and when it expires, the amount and currency, and a reference number from whichever processor took the payment. For purchases made in the app we also store the transaction identifiers Apple gives us, so that a restored purchase can be matched to your account.
We never receive your card number, and we never store one. Card details are entered on the payment provider's own page, not ours.
Technical records
Three things, and they are the ones people are usually surprised by, so they are spelled out:
- Your IP address. Used to stop repeated failed sign-ins and abusive request volumes, and to work out which currency to show you. The currency lookup is cached against your address for a short period so the same request is not repeated on every page.
- Error reports. When something breaks in your browser we record what broke, where in our code it happened, which page you were on, which build you were running, and your browser and device type. This is how faults get found and fixed.
- Sign-in sessions. Which devices your account is signed in on, so that you can see them and end any you do not recognise.
The mobile app
If you install the app and turn notifications on, we register a notification token issued by Apple or Google for that installation, so a reminder can reach that device. You can turn notifications off in the app or in your phone's settings, and the token is removed when you sign out.
Messages
Messages you send to other students or to us are stored so that both sides can read them. If you report a conversation, the report and the messages it concerns are visible to our team so that we can act on it.
What stays on your device
Some things are kept on the phone or computer you are using rather than on our servers:
- Your sign-in session, held in the device's own secure store, the Keychain on iOS, the Android Keystore on Android, and not in ordinary browser storage.
- Work you did while offline, such as a card you graded or a focus session you finished with no connection, kept until it can be sent and then removed. It is stored against your account, so a second person signing in on the same device never sends it.
- Your preferences, including any wallpaper image you upload to the focus timer. That image is never uploaded to us.
Signing out clears the session. Clearing the app's or browser's data clears the rest.
Why we use it
- To give you the service you asked for: your plan, your notes, your progress, your subscription. This is the performance of our contract with you.
- To keep accounts safe, sign-in security, rate limiting, and finding faults. This is our legitimate interest in a service that works and is not abused, and yours in an account nobody else can take.
- To answer you when you write to us.
- To send study tips and product news, only if you have opted in, and only until you opt out. Every such email has an unsubscribe link.
We do not profile you for advertising, and nothing here is used to make an automated decision that affects you.
Who else sees it
We do not sell your data and we do not share it for anyone else's marketing. These are the companies that process some of it in order to run the service. This list is complete as of the date at the top.
| Who | What they get | Why |
|---|---|---|
| Supabase | Everything described above that is stored on our servers | They host our database, sign-in and file storage. They are our main processor. |
| Kashier | Your payment session, the amount, and an order reference | Card and local payments on the website. They take the card details directly; we do not see them. |
| Apple | The transaction identifiers for a purchase made in the app | To verify with Apple that a purchase is genuine, and to restore it on a new device. |
| Google (Firebase Cloud Messaging) | Your device's notification token | To deliver a push notification to that installation. Only if you turn notifications on. |
| Google (Sign-in) | Your email and name, if you choose to sign in with Google | To create or open your account without a separate password. |
| Zoom | Your name and the meeting time, if you book a mentorship or tutoring session | To create the meeting you are attending. |
| ipwho.is | Your IP address | To work out which country you are in, so the price is shown in the right currency. |
| Brevo | Your email address, your name, and the content of the email | They are the mail service that delivers our email to you. Used for account email and, if you opted in, study tips. |
What our internal tools do not send
We use AI assistants internally to help us find faults and understand how the product is being used. They are given counts and grouped error messages, not your records: the tool that reads usage asks the database for a number of rows and never for the rows themselves, and the tool that reads faults groups them by message and sends the message and the page it happened on, with no account attached. No name, email or study data is sent to an AI provider.
Our own marketing accounts
We connect to Meta for statistics about our own Instagram and Facebook pages. That connection carries our page's data, not yours.
Where your data goes
We are in Egypt, and the companies above are mostly in the United States and Europe, so your data is processed outside your country and outside ours. Each of them is a company we have a contract with for that purpose. If you are in the EEA or the UK and want to know which safeguard applies to a particular one, write to us and we will tell you.
How long we keep it
Written plainly, because a vague answer here is usually a way of avoiding one.
- Your account and study data, for as long as your account exists. Deleting your account deletes them; see below. Your date of birth is part of this: it lives exactly as long as the account and goes when the account goes.
- Payment records, kept after an account is deleted, for as long as tax and accounting law requires us to be able to show that a payment happened. These are the transaction, the amount and the date, not anything about your studying.
- Messages, for as long as either side of the conversation has an account. A report is kept with the messages it concerns.
- Error reports: kept for 30 days, then deleted automatically. They carry the fault, the page it happened on and your browser type, and no name or email.
- Rate-limit and currency lookups, minutes and hours respectively, and neither writes your address down. The rate limiter counts recent requests against a one-way hash of your address and forgets each one as its window passes. The currency lookup stores a two-letter country code against a hash of your address and stops trusting it after 12 hours.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it, and you can withdraw consent for emails at any time. Write to usmlepulse@gmail.com. We will answer within 30 days, and we will not charge you for it.
Deleting your data
Two ways. Open Dashboard → Security and delete your account yourself, or email usmlepulse@gmail.com from the address on your account with the subject “Data deletion request”. If you email, we confirm within 7 days and complete the deletion within 30 days.
Deleting removes your profile, study progress, checklists, saved notes, anything you wrote or drew over a question or over the notes, your focus session history, your notification tokens and device sessions, your email subscription record, and any Instagram data linked to your account. We keep only what the law requires us to keep, payment records are retained for tax and accounting purposes, and those are held by our payment provider, not by us.
Deletion is permanent. Study progress and saved work cannot be restored afterwards.
Getting a copy
Open Dashboard → Security and choose Download my data. It gives you a single file containing everything described on this page that we hold about your account. If you would rather we sent it to you, ask by email and we will.
Complaining
If you are in the EEA or the UK you may complain to your national data protection authority. We would rather you told us first, so that we can fix it.
Watermarking of study material
Pages containing paid study material carry a watermark identifying the account that opened them. It is deliberately faint so that it does not interfere with reading, but it is present in any screenshot or recording of those pages.
Its only purpose is to identify the source if paid material is redistributed. It records the account identity and the time the page was viewed. It does not track what you read, how long you read it, or anything you do elsewhere.
Sharing paid material outside your account is a breach of the Terms, and the watermark is how we identify where a leaked copy came from.
Cookies
We do not use cookies. Not for analytics, not for advertising, not for anything, which is why you have never been shown a cookie banner here.
We do use your browser's own local storage to keep you signed in and to remember your preferences: your theme, which module you were last working on, an unsent draft. That stays on your device, is readable only by this site, and is cleared when you sign out or clear your browser data.
Children
USMLE Pulse is built for medical students and graduates preparing for a licensing examination. It is not directed at children, and we do not knowingly keep an account for anyone under 16.
We ask for your date of birth when you create an account, and we refuse the account if the date you give is below that age. If you had an account before we started asking, we ask you once the next time you sign in.
We do not verify it. We have no way to, and we would rather say so than imply a check we do not carry out. What asking gives us is narrower and still worth having: the question is put before anyone can open an account, the answer is recorded, and you cannot quietly change it afterwards. “We do not knowingly keep an account” is then a statement about something we actually asked, rather than about something we never looked at.
If you believe a child has created an account, write to usmlepulse@gmail.com and we will delete it and everything with it.
How we protect it
Specifically, rather than in general terms:
- The site and the app talk to our servers over HTTPS only.
- Passwords are handled by our sign-in provider and are never stored by us in a form we could read.
- The database enforces, row by row, that an account can only read its own data. That rule is in the database itself, not only in the app, so a fault in the app cannot hand your records to somebody else.
- Keys and credentials are held outside the public web directory, so they cannot be requested over the internet.
- Security notices: a new sign-in, a password change, cannot be switched off, because the first thing somebody who takes an account does is switch them off.
No service can promise it will never be breached, and we are not going to. If a breach affects you, we will tell you.
Changes
If we change this policy we will change the date at the top. If a change materially affects what we collect or who receives it, we will tell you in the product or by email rather than relying on you to re-read this page.
See also the Terms of Service, the Medical Disclaimer and the Refund Policy.