Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information.
Information We Collect
Account Information
When you create an account, we collect your name, email address, specialty information, medical training level, and institutional affiliations to provide personalized medical education content. We may also collect profile pictures and professional credentials you choose to share.
Educational Data
We collect detailed information about your study sessions, quiz performance, answer patterns, time spent on questions, study guide preferences, flashcard interactions, and Consult conversations to provide personalized learning recommendations and track your progress.
Payment Information
When you subscribe to our services, we collect billing information including name, billing address, and payment method details. Payment processing is handled securely by Stripe, and we do not store your complete credit card information.
Technical Information
We automatically collect device information including IP address, browser type and version, operating system, device identifiers, screen resolution, time zone settings, browser plug-in types and versions, and referring/exit pages for security, analytics, and platform optimization.
Communications
When you contact us through email, chat, or other communication channels, we collect and store your messages, including any attachments, to provide customer support and improve our services.
How We Use Your Information
Essential Platform Functions
- Provide and maintain our medical education platform and services
- Process user registration and account management
- Handle subscription billing and payment processing
- Deliver customer support and respond to inquiries
- Ensure platform security and prevent unauthorized access
Personalized Learning
- Personalize your learning experience with AI-powered recommendations
- Track study progress and identify knowledge gaps
- Generate customized study guides and flashcard sets
- Provide adaptive question difficulty based on performance
- Deliver specialty-specific content and board exam preparation
Communication and Updates
- Send important updates about your account and our services
- Deliver educational content and study reminders (with your consent)
- Notify you about new features and platform improvements
- Share relevant medical education content and resources
Analytics and Improvement
- Analyze platform usage patterns to improve user experience
- Conduct research to enhance educational effectiveness
- Develop new features and content based on user feedback
- Optimize platform performance and loading times
- Generate anonymized reports for educational research
Legal Basis for Processing (GDPR)
For users in the European Union, we process your personal data under the following legal bases:
- Contract: To provide our educational services and fulfill our terms of service
- Legitimate Interest: To improve our platform, ensure security, and provide customer support
- Consent: For marketing communications and optional data processing (which you can withdraw anytime)
- Legal Obligation: To comply with applicable laws and regulations
Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience and understand how you use our platform:
Essential Cookies
Required for basic platform functionality, including user authentication, security, and session management. These cannot be disabled.
Performance Cookies
Help us understand how you interact with our platform, allowing us to improve performance and user experience.
Functional Cookies
Remember your preferences, settings, and study progress to provide a personalized experience.
Analytics Cookies
Used to analyze platform usage patterns and generate anonymized usage statistics. You can opt out of these in your account settings.
Artificial Intelligence and Data Processing
Our platform uses artificial intelligence to enhance your learning experience:
- Consult: Your conversations are processed to provide accurate medical education responses and improve the AI system
- Personalized Recommendations: We analyze your study patterns to suggest relevant questions and topics
- Content Generation: AI helps create customized study guides and explanations based on your learning needs
- Performance Analysis: Machine learning algorithms identify knowledge gaps and optimize your study path
All AI processing is done in compliance with privacy regulations, and we implement appropriate safeguards to protect your data throughout these processes.
Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following specific circumstances:
Service Providers
We work with trusted third-party service providers who help us operate our platform, including providers for:
- Database and authentication services
- Payment processing and billing
- AI and machine learning functionality
- Web hosting and content delivery
- Cloud infrastructure and file storage
- Analytics and performance monitoring
- Customer support and communication tools
All service providers are bound by strict data processing agreements and confidentiality requirements. We carefully vet all third parties to ensure they meet our security and privacy standards.
Legal Requirements
- To comply with applicable laws, regulations, or legal processes
- To respond to lawful requests from government authorities
- To protect our rights, privacy, safety, or property and that of our users
- To investigate and prevent fraudulent, unauthorized, or illegal activities
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction, subject to the same privacy protections.
Anonymized Data
We may share aggregated, anonymized data for research purposes, educational studies, or to improve medical education generally. This data cannot be used to identify individual users.
Data Security and Protection
We implement comprehensive security measures to protect your personal information:
Technical Safeguards
- End-to-end encryption of data in transit using TLS 1.3
- AES-256 encryption of sensitive data at rest
- Multi-factor authentication for administrative access
- Regular automated security scanning and vulnerability assessments
- Secure API endpoints with rate limiting and authentication
Administrative Controls
- Role-based access controls limiting data access to authorized personnel
- Regular security training for all team members
- Background checks for employees with access to personal data
- Incident response procedures for security breaches
- Regular security audits by third-party security firms
Infrastructure Security
- Hosting on industry-certified cloud infrastructure with appropriate compliance certifications
- Network security controls including firewalls and intrusion detection systems
- Regular encrypted data backups with secure off-site storage
- Disaster recovery procedures with geographic redundancy
- Continuous monitoring and threat detection systems
While we implement strong security measures, no method of transmission or storage is 100% secure. We continuously monitor and improve our security practices to protect your information.
Data Retention and Deletion
We retain your personal information only as long as necessary to fulfill the purposes outlined in this policy:
- Account Data: Retained for the duration of your account plus 7 years for legal compliance
- Educational Progress: Kept while your account is active and for 2 years after account closure
- Payment Information: Billing records retained for 7 years as required by tax regulations
- Consult Conversations: Retained for 1 year to improve service quality, then anonymized
- Technical Logs: Automatically deleted after 90 days unless required for security investigations
- Marketing Data: Deleted within 30 days of consent withdrawal
When you delete your account, we will permanently delete your personal data within 30 days, except where retention is required by law. Some anonymized usage data may be retained for research and platform improvement.
International Data Transfers
Subspecialty operates globally, and your data may be transferred to and processed in countries other than your residence. We ensure adequate protection through:
- Adequacy Decisions: Transfers to countries with EU adequacy decisions where applicable
- Standard Contractual Clauses: EU-approved data transfer contracts with third-party processors
- US-EU Data Privacy Framework: Compliance with approved transfer mechanisms
- Additional Safeguards: Technical and organizational measures to protect data in transit
Primary data processing occurs in the United States with infrastructure provided by certified cloud providers that meet industry security standards. EU users have the right to obtain information about specific data transfer safeguards by contacting us.
Children's Privacy
Subspecialty is designed for medical professionals and students aged 18 and older. We do not knowingly collect personal information from children under 18.
If you believe we have inadvertently collected information from someone under 18, please contact us immediately at privacy@subspecialty.com, and we will delete such information promptly.
Medical students under 18 should have parental consent before using our platform and should use the platform under appropriate adult supervision.
Your Privacy Rights
Depending on your location, you have various rights regarding your personal information:
Universal Rights
- Access: Request a copy of the personal information we hold about you
- Correction: Update or correct inaccurate or incomplete information
- Deletion: Request deletion of your account and associated personal data
- Data Portability: Export your data in a machine-readable format
- Communication Preferences: Opt out of marketing and non-essential communications
Additional EU/UK Rights (GDPR)
- Restriction: Request limitation of processing in certain circumstances
- Objection: Object to processing based on legitimate interests or direct marketing
- Consent Withdrawal: Withdraw consent for data processing at any time
- Complaint: File a complaint with your local data protection authority
- No Automated Decision-Making: Opt out of automated profiling that significantly affects you
California Rights (CCPA/CPRA)
- Know: Right to know what personal information is collected and how it's used
- Delete: Right to request deletion of personal information
- Opt-Out: Right to opt out of the sale of personal information (we don't sell data)
- Non-Discrimination: Right not to receive discriminatory treatment for exercising rights
- Correct: Right to correct inaccurate personal information
To exercise any of these rights, contact us at privacy@subspecialty.com. We will respond to your request within the timeframe required by applicable law (typically within 30 days).
Policy Updates and Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
- Notification: We will notify you of material changes via email or prominent platform notice
- Advance Notice: Significant changes will be communicated at least 30 days before taking effect
- Continued Use: Continued use of our platform after changes indicates acceptance of the updated policy
- Opt-Out: If you disagree with changes, you may delete your account before they take effect
We encourage you to review this Privacy Policy periodically. The "Last Updated" date at the bottom indicates when the policy was last revised.
Contact Information
If you have questions about this Privacy Policy, how we handle your personal information, or wish to exercise your privacy rights, please contact us through any of the following methods:
Privacy Inquiries
Email: privacy@subspecialty.com
Subject Line: Privacy Policy Inquiry
Response Time: Within 2 business days
Data Protection Officer
Email: dpo@subspecialty.com
For: GDPR-related requests and concerns
Response Time: Within 30 days as required by GDPR
General Support
Email: support@subspecialty.com
For: Account and platform questions
Hours: Monday-Friday, 9 AM - 6 PM EST
Postal Address
Subspecialty Inc.
Privacy Department
123 Medical Education Blvd
Suite 456
Boston, MA 02101
United States
When Contacting Us
To help us respond to your inquiry efficiently, please include your account email address and a detailed description of your question or request. For data subject rights requests, we may need to verify your identity before processing your request.
Privacy Policy Version: 2.0
Last Updated: January 2, 2026
Effective Date: January 2, 2026