Privacy Policy
Effective and last updated: July 26, 2026
This Privacy Policy explains how PSITEQbank.org (the “Service”) collects, uses, stores, and discloses information when you visit the website, create an account, or use the question bank.
1. Information we process
Account and authentication information
If you create an account, Firebase Authentication processes your email address, account identifier, authentication provider, and information necessary to authenticate you. If you use Google sign-in, Google and Firebase process information needed to complete that sign-in.
Study and application data
The Service may store your question history, submitted and draft answers, accuracy history, study sessions, settings, eliminated choices, highlights, reset timestamps, legal-policy acknowledgment, and related synchronization timestamps.
Feedback and reports
If you vote on a question or report a problem, we store the question identifier, your vote or report, optional comments, account identifier, email address, and submission time so the issue can be reviewed and abuse can be prevented.
Aggregate statistics
The Service maintains question-level totals such as total answer attempts and correct answers. These aggregate totals do not contain an account identifier or email address.
Browser and hosting information
The application uses browser local storage to support guest use, faster loading, and temporary or synchronized study state. Firebase, Google, Netlify, and underlying network providers may process ordinary technical information such as IP address, device or browser information, request logs, authentication cookies or tokens, and security events according to their own policies.
2. Why we use information
- to authenticate users and secure accounts;
- to provide question-bank functions and synchronize progress across devices;
- to preserve user highlights, preferences, and answer history;
- to calculate aggregate question accuracy;
- to review feedback, correct content, and prevent misuse;
- to maintain security, diagnose failures, and operate the Service; and
- to comply with applicable legal obligations and enforce our Terms.
3. Service providers and disclosure
We use Firebase services for authentication and cloud data storage, Google as an optional authentication provider, and Netlify for website hosting and delivery. These providers process information on our behalf or as independent providers under their applicable terms and privacy practices.
We do not sell personal information. We may disclose information when reasonably necessary to operate the Service, comply with law, protect rights or safety, investigate abuse, address intellectual-property or examination-security concerns, or complete an organizational transfer subject to appropriate safeguards.
4. Cookies and local storage
Authentication services may use cookies, tokens, or similar technologies to keep you signed in and protect your account. The application uses local storage for study state, guest progress, highlights, and legal acknowledgment. Clearing browser data can remove guest information that has not been associated with a signed-in account.
5. Retention
Account-linked study data is generally retained while your account remains active or as needed to provide the Service. Feedback and reports may be retained while needed for content review, security, recordkeeping, or legal purposes. De-identified aggregate question statistics may remain after account deletion because they are not stored with your account identifier or email address.
6. Your choices and deletion
You may reset study progress without deleting your account. Signed-in users may also select “Delete account and cloud data” in the app. After identity confirmation, that function is designed to delete:
- the user profile and synchronized study state;
- per-question drafts, submitted choices, eliminated choices, and highlights;
- feedback votes and issue reports linked to the account; and
- the Firebase Authentication account.
Local application data for that account is cleared from the device completing deletion. Data already cleared from the browser, de-identified aggregate statistics, records required for security or legal compliance, and information held independently by service providers may not be recoverable or may be retained as legally permitted.
You may also request access, correction, or deletion by contacting mustafa.khan41@gmail.com. We may need to verify your identity. Rights vary by jurisdiction, and certain exceptions may apply.
7. Security and international processing
We use reasonable administrative and technical measures intended to protect information, but no internet transmission or storage system is completely secure. Service providers may process information in the United States and other countries where they operate.
8. Children
The Service is intended for medical education and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so it can be reviewed and deleted.
9. Changes to this Policy
We may update this Policy when the Service or applicable requirements change. The effective date above identifies the current version. Material changes may require renewed acknowledgment.
10. Contact
Privacy questions or requests may be sent to mustafa.khan41@gmail.com.