Browse the site

Privacy Policy

What Clinicoid collects, why it collects it, who else ever sees it, and how you get rid of it.

Last updated 15 September 2026 · Applies to the Clinicoid app and this website

The short version

  • We collect what the app needs to be your study account — who you are, what you have studied, and what you have paid for.
  • We do not sell your data, and there are no advertising or tracking companies in this app.
  • Your questions to Coid are sent to Google’s Gemini model through our own server so it can answer them. They are not used to train anybody’s model.
  • You can delete your account, and everything in it, from inside the app. It happens immediately and it cannot be undone.

The rest of this page is the same thing said carefully. It applies to the Clinicoid mobile app and to clinicoid.com.

Who we are

Clinicoid is a study app for medical students. In this policy, “Clinicoid”, “we” and “us” mean the team that operates the app and the clinicoid.com website. “You” means the person using it.

You can reach us about anything on this page at support@clinicoid.com, or from inside the app at Menu › Contact us.

What we collect

Everything below is collected because a specific part of the app needs it. Nothing is collected “just in case”.

Your account
Your email address, your name, your username, and your profile picture if you set one. If you sign in with Google, we receive your email address, your name and your Google profile picture from Google — nothing else, and no access to your Google account.
Your student identity
Your university, your academic year, your student ID number, your study group, and the photo of your university ID card that you take during sign-up. We use these to confirm you are a student on the course the app is built for, and to put you in the right year and group.
What you study
The questions you answer and what you answered, your marks and results, your bookmarks and mistakes, your flashcard reviews, the exams you sit, your study-time sessions and goals, and what you have downloaded for offline use.
Your conversations with Coid
The questions you ask Coid, the answers it gives, and which subject or page the answer was grounded in — so the chat is still there tomorrow. A temporary chat is the exception: it is never written down.
Messages and your social profile
The messages you send to other students and to support, any photos, files or voice notes you attach to them, who you are friends with, who you have blocked, and whether you are currently online.
Your device
The model and name of the phone, the operating system version, the app version, a random identifier we generate for the installation, and — if you allow notifications — a push token from Expo’s notification service. This is what lets you see “which devices am I signed in on” and sign one out.
Payments
What you bought, when, what it cost and your subscription state. Purchases in the iPhone app are made through the App Store, and purchases in the Android app through Google Play. We never see or store your card number: Apple or Google handles the payment and tells our server only that a purchase happened.
When something breaks
If a request to our servers fails, our server logs record that it failed, when, and from which account. There is no third-party crash-reporting or analytics service in this app.

Permissions the app asks for

Android asks you before any of these. Each one is requested at the moment it is needed, never at start-up, and saying no leaves the rest of the app working.

Camera
To photograph your university ID card during sign-up, and to take a picture to send in a chat. The camera is not used at any other time.
Microphone
To dictate a question to Coid instead of typing it, to talk to Coid in a voice chat, and to record a voice note in a chat. Speech is turned into text by your phone’s own speech-recognition service.
Photos and files
To attach a picture or a document you choose to a message, to set your profile picture, and to save a file you have downloaded. We only ever receive the file you picked.
Notifications
To tell you about a reply, a message, a study reminder you set, or an announcement from your year. You can turn categories off in Settings › Notifications, or all of them in Android’s settings.

Why we use it

  • To give you an account and keep you signed in on the devices you chose.
  • To show you the right material — your year, your module, your subjects — and to keep other years’ material out of it.
  • To record what you have studied, so your progress, mistakes and statistics are yours and survive a new phone.
  • To answer your questions with Coid, grounded in your own course material.
  • To deliver messages between you and other students, and between you and support.
  • To take payment, to give you what you paid for, and to keep the ledger straight.
  • To keep the service secure — to spot an account being shared or a subscription being resold, and to enforce the Terms of Use.
  • To reply when you write to us.

Where the law requires a legal basis, ours is the contract between us (giving you the service you signed up for), our legitimate interest in keeping the service working and secure, and your consent for the device permissions above — which you can withdraw at any time in Android’s settings.

Coid, and what happens to what you type

Coid is a large language model. When you ask it something, your question — together with the course material it needs to answer, and enough of the current conversation to follow the thread — is sent from the app to our own server, and from our server to Google’s Gemini API. The answer comes back the same way.

  • Your chats are stored on your account so you can reopen them. A temporary chat is not stored at all.
  • Your conversations are not used to train Clinicoid’s models or anybody else’s. Google processes the request on our behalf under its API terms and does not use API content to improve its models.
  • We record how much AI you have used, so allowances and billing work. That is a count, not a copy.
  • Please do not type patient names, patient records, or anyone else’s medical information into Coid.

Who else ever sees it

A small number of companies run parts of the service for us. Each one only ever receives what that part needs, and none of them may use it for their own purposes.

Supabase
Hosts the database, the accounts and the sign-in system.
Cloudflare
Stores and delivers the large files — books, lecture videos, audio and the files you send in chats — and serves clinicoid.com.
Google (Gemini)
Generates Coid’s answers from what our server sends it.
Google (Sign-In and Play)
Signs you in if you choose Google, and takes payment for purchases made in the Android app.
Expo
Delivers push notifications to your device.
Vercel
Runs our server and the website.

Other students see only what you show them: your profile, whatever you have made visible in Settings › Privacy, and the messages you send them. Your answers, marks, mistakes and Coid chats are never shown to another student.

We will also hand over information if the law genuinely requires it — a valid court order, for example — and we will tell you if we are allowed to.

Where it is kept, and for how long

The service runs on servers outside your country, so your information is transferred and stored abroad. We keep it while your account exists, because that is what makes it your account.

  • Delete your account and your profile, your study record, your chats and your files go the moment you confirm. Nothing is queued, and there is no notice period during which we still hold it.
  • Copies inside routine encrypted backups age out within 90 days.
  • We keep the minimum record of a purchase that tax and accounting law requires, even after deletion. It is how much, when, and the payment provider’s reference — a transaction, not a profile.
  • We keep a note that an account was deleted, with the date and the reason if you gave one, so we can answer questions about it later. It carries no name, no email and nothing you wrote.
  • A message you already sent to somebody else stays in their conversation, in the same way an email you sent stays in the other person’s inbox.

What you can do

See and change it
Settings › Personal info holds your profile. Settings › Privacy controls who can find you, who can message you and who can send you a friend request. Settings › Devices shows every phone signed in to your account and signs any of them out.
Get a copy
Write to us and we will send you your data in a readable format.
Delete it
Settings › Personal info › Delete account. The app shows you exactly what is on the account, asks you to confirm, and then deletes it — immediately, and with no way for you or for us to undo it. Deleting your account does not cancel a subscription, because Apple or Google takes that payment: cancel it in the App Store or Google Play too, or it keeps renewing. The app reminds you of this and has a button that takes you there.
Delete it without the app
If you cannot open the app, write to support@clinicoid.com from the address on your account and ask for it to be deleted. We will check the request really comes from you, delete the account, and write back to confirm — normally within a few days and never longer than thirty. clinicoid.com/delete-account says the same thing in full.
Object, or complain
If you think we are handling your information wrongly, tell us first — we would rather fix it. You also have the right to complain to your local data-protection authority.

Children

Clinicoid is built for university medical students and is not directed at children. You must be at least 16 to have an account. If you are under 18, a parent or guardian must agree to the Terms of Use for you. If we learn that we hold an account belonging to a child under 16, we delete it.

Keeping it safe

Traffic between the app and our servers is encrypted. Access to the database is restricted per-account by the database itself, so one student’s account cannot read another’s. Files that are not meant to be public are served through short-lived signed links rather than open addresses. Passwords are stored hashed and we cannot read them.

No system is perfect. If a breach ever affects your information, we will tell you and the relevant authority as quickly as the law requires.

Changes to this policy

When we change this policy we update the date at the top, and the new version appears in the app and on clinicoid.com. If a change genuinely affects how your information is used, we will tell you in the app before it takes effect rather than hoping you re-read this page.

Contact

Questions, requests, or anything on this page: support@clinicoid.com. In the app: Menu › Contact us.