Privacy
Your privacy, in plain English
Last updated: February 2026
What we collect
- Your name, email, and the role you pick on first visit.
- The school, program, or organisation you join (if any).
- What you study on Maldek/CHIN: modules viewed, quizzes taken, mastery scores, free-text reflections.
- Standard web telemetry — device type, browser, IP-derived region — used to keep the platform working.
What we never collect
We do not collect Protected Health Information (PHI). Maldek/CHIN is an educational platform. It does not handle real patient records, EHR data, insurance information, or anything you would need a HIPAA covered-entity relationship for. If you ever feel asked to enter PHI on the platform, stop, and email us — that's a bug, not a feature.
Why we use AI, and how
We use AI models (Anthropic, Google, OpenAI) to explain concepts, generate practice scenarios, and grade your reasoning. Every AI output is run through a "decision-support" filter that rewrites directive medical language into educational language. Every AI surface tells you the same thing: this is education, not medical advice — always follow up with your licensed healthcare provider for personal medical questions.
Your rights
- Right to access: download every record we hold about you at
/api/me/export. - Right to delete: erase your account and all linked records via the Account → Delete me action.
- Right to know: we will tell you who we share your data with (currently: our AI model providers, our hosting + database provider, and your school/employer if you joined via an institutional cohort).
- Right to opt out: of analytics, of marketing email, and of any optional research. Toggles live on your account page.
Children & students
If you are using Maldek/CHIN through a school, your school determines what data is shared with us and how long we keep it. For students under 18, we require a parent/guardian consent flow before any account is created — administered by the school.
Where your data lives
On secure cloud infrastructure in the United States. We do not intentionally transfer data internationally; if you contact us from outside the US, request routing is incidental.
Changes to this policy
We'll email you 14 days before any material change.
This document is a plain-English starting template. Always consult a licensed attorney for jurisdiction-specific advice. For questions, contact hello@maldek.health.
