Back to Practice Legal Document
Data Privacy & Security

Privacy Policy

Saudi Anesthesia Board QB Practice • Last Updated: August 2026

1 Information Collected

The Application is an active recall revision suite designed to minimize data collection while enabling real-time progress synchronization across devices.

  • Account Credentials: When signing in with Google OAuth, we receive your basic profile (name, email address, unique identifier `UID`). When registering with Email and Password, credentials and tokens are securely managed by Firebase Authentication. Passwords are encrypted and never accessible to the application.
  • Study & Performance Metrics: Selected question answers, accuracy scores, bookmarked question indices, and active modules are stored in your private cloud record (/users/{userId}).
  • Local Browser Storage: For guest users, all study data is stored exclusively in your browser's localStorage and never leaves your device.

2 How Your Data is Used

Collected data is used exclusively for core functionality:

  • Authenticating user sessions.
  • Synchronizing question progress and bookmarks across mobile and desktop devices.
  • Computing personal accuracy metrics and performance history.

Your data is strictly private and is never sold, rented, monetized, or used for commercial advertising.

3 Third-Party Infrastructure

  • Google Firebase & Google Cloud: Provides authentication infrastructure and Cloud Firestore hosting under Google's cloud security framework.
  • GitHub Pages (Microsoft): Serves the static website assets via HTTPS.
  • Content Delivery Networks: Tailwind CSS and Lucide Icons are delivered via public CDNs.

4 Data Security & Protection

User records in Cloud Firestore are protected by server-side security rules ensuring that only authenticated users can access their specific user ID (request.auth.uid == userId). All network communications are encrypted in transit via TLS 1.3.

5 Data Retention and Removal

Guest users can clear their data at any time by clearing their browser's cache and local storage. Authenticated users can request deletion of their cloud profile and synchronized records by contacting the administrator.