Privacy Policy
Last updated 17 August 2026
This policy explains what GoLearnix collects when you use GoLearnix, why we collect it, who else can see it, and how you get it back or get it deleted. We have tried to write it in plain language and to describe what the product actually does rather than everything the law might permit us to do.
1. Who we are
GoLearnix is a practice and revision platform for MBBS students. The data controller is GoLearnix, PLACEHOLDER — registered address. For anything in this policy, including requests to access or delete your data, see Contact at the end of this page.
2. What we collect
Information you give us
- Account details. Your name, email address, and a password. Passwords are never stored in a readable form; we cannot see yours and cannot recover it for you, only help you set a new one.
- Study context. Your university, college, and the year or stage of your course. This determines which question banks and books you can access, so it is required rather than optional.
- Profile choices. The avatar you pick.
- Waitlist entries. If you join the pre-launch waitlist, we store your email address, the university you typed, your country, and your year of study. Nothing else, and no account is created.
Information created as you use the platform
- Practice activity. The questions you attempt, the options you select, whether you were correct, how long you spent, and the exams and sessions you create.
- Your work in the library. Highlights, underlines, and notes you make on book pages, and the text you selected when you made them. These are stored so your books look the way you left them.
- Bookmarks and saved questions.
- Account activity. A log of significant actions on your account, used for support and for spotting abuse.
Information collected automatically
- Sign-in records. Each time you sign in we record your IP address, basic information about the browser and device you used, and when the session started, was last active, and expires. This is what enforces the limit on how many devices can be signed in at once, and what lets you recognise a session you do not remember starting.
- Abuse-prevention counts. To stop password guessing and automated abuse we keep short-lived counts of recent requests associated with an IP address and, on sign-in and password-reset, an email address. These expire on their own and are not used for anything else.
What we do not collect
We do not run advertising or third-party analytics, we do not use tracking pixels, and we do not build advertising profiles. We do not ask for or store payment card details. We do not collect health information about you.
3. Cookies
GoLearnix sets one cookie, and only after you sign in:
| Type | Purpose | Lasts |
|---|---|---|
| Essential sign-in cookie | Keeps you signed in. It holds a random value and nothing else: no name, no email, nothing readable about you, and it cannot be read by scripts running in your browser. | Until you sign out, until the session goes idle, or until a fixed maximum age, whichever comes first. |
There are no advertising, analytics, or preference cookies, which is why you are not asked to accept a cookie banner. Blocking this cookie will prevent you signing in.
4. Why we use it
- To create your account, sign you in, and keep you signed in.
- To show you the right curriculum, since access is scoped to your university and year.
- To produce your performance analytics: which subjects, topics, and sub-topics you are strong or weak in, and how that compares with other students in aggregate.
- To save your highlights, notes, and bookmarks between sessions.
- To send you transactional email: password resets, account invitations, and, if you joined the waitlist, a message when we open.
- To keep the platform secure and available: enforcing device limits, rate limiting, and investigating abuse.
Where the law requires a legal basis, ours is performance of our contract with you for the first four, your consent for waitlist email, and our legitimate interest in a secure service for the last.
5. Who we share it with
We do not sell your data and we do not share it for anyone else's marketing. We use a small number of service providers who process data on our instructions:
| Category | What they handle |
|---|---|
| Cloud hosting and database providers | Run the platform and store its data. Between them they hold your account, practice, and library data, and see IP addresses as requests pass through. |
| Email delivery provider | Sends transactional email such as password resets and invitations. Receives your email address and the contents of that message. |
| Academic institution directory | Powers the university suggestions on the waitlist form. When you type into that field, what you type and the country you picked are sent to a third-party directory of universities to fetch matches. Your name, email address, and identity are never sent. |
We will name the specific providers behind each category on request, and we require each of them to process your data only on our instructions. Contact us for the current list.
We may also disclose information if we are legally required to, or where it is necessary to protect our rights, our users, or the security of the platform.
6. Your university
If your access comes through an institutional arrangement with your university or college, we may share aggregate usage and performance reporting with them. Where we do, we will say so at sign-up. We do not give your university your individual answers or your notes unless you ask us to.
7. How long we keep it
- Account and study data for as long as your account is open, and then until you ask us to delete it.
- Sessions until they expire or you sign out; expired rows are swept automatically.
- Rate-limit counters only for the length of their window.
- Waitlist entries until we launch and have contacted you, or until you ask to be removed, whichever is first.
8. How we protect it
- Passwords are stored using one-way encryption, never in readable form.
- Sign-in credentials are held in a form that cannot be reversed, so a stolen copy of our data contains nothing that could be used to sign in as you.
- Traffic between you and GoLearnix is encrypted.
- Sign-in, password-reset, and waitlist requests are throttled, and each account has a limit on how many devices can be signed in at once.
- Access to production data is restricted to the people who need it to operate and support the service.
No system is perfectly secure. If we ever discover a breach affecting your data, we will tell you and the relevant regulator as quickly as the law requires.
9. Your rights
Wherever you are, you can ask us to give you a copy of your data, correct it, delete it, or stop using it in a particular way. If you are in the UK or the EU you also have the rights granted by the UK GDPR and GDPR, including the right to object to processing and to complain to your local data protection authority.
Contact us using the details at the end of this page and we will respond within 30 days. Deleting your account removes your personal details and your work; anonymised, aggregate statistics that cannot identify you may remain in our reporting.
10. International transfers
GoLearnix is available worldwide and our providers operate internationally, so your data is likely to be stored and processed outside the country you live in. Where the law requires safeguards for that transfer, we put them in place with each provider. You can ask us where your data is currently held.
11. Children
GoLearnix is built for students in medical school and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
12. Changes
If we change this policy we will update the date at the top, and for anything significant we will tell you by email or in the app before it takes effect.
13. Contact
For questions, requests, or complaints about this policy, write to info@golearnix.com. See also our Terms of Service.