Privacy Policy
Welcome to AZ Learn (referred to herein as "AZ Learn", "we", "our", or "the Platform"). We operate a specialized medical education learning management system (LMS) designed for medical students, healthcare trainees, and clinical instructors.
This Privacy Policy explains how personal information, device telemetry, and educational records are collected, stored, processed, and protected when using the AZ Learn native applications (Android APK, iOS/iPadOS Client, Windows Desktop Client) and associated web portals.
Key Summary: We collect only the minimum personal data required to administer clinical courses. We never sell user data, never display third-party advertisements, and never track students across external websites or services.
1. Information We Collect
When creating an account and accessing course curricula, we collect the following categories of data:
- Account & Identity Data: Full name, verified mobile phone number, email address, and cryptographically hashed passwords (SHA-256). We never store plaintext passwords.
- Academic & Enrollment Records: Course subscriptions, scratch card redemption history, quiz attempt submissions, and flashcard recall confidence intervals.
- Hardware Device Identifiers (DRM & Anti-Piracy): To enforce single-student licensing and prevent commercial credential redistribution, our applications record:
- Android Devices: The 64-bit hardware-level
ANDROID_ID(16-character hexadecimal identifier). - iOS & iPadOS Devices: Cryptographically salted device identifier (
identifierForVendorUUID) bound to the active student session. - Windows PC Devices: Hardware component fingerprint derived from motherboard and CPU serial hashes.
- Operating System Information: OS platform (e.g., Android, iOS, Windows) and device model name (e.g., "iPad Air", "Samsung Galaxy Tab").
- Android Devices: The 64-bit hardware-level
- Security & Access Logs: DRM key request timestamps and network IP addresses recorded in ephemeral Cloudflare logs strictly for rate-limiting (maximum 30 key requests/minute) and anomaly defense.
2. How We Use Hardware Identifiers
Hardware device identifiers are collected strictly for Digital Rights Management (DRM) and license enforcement:
- Dual-Device Slot System: Each enrolled student is authorized to bind exactly one (1) Mobile device and one (1) Personal Computer. Hardware identifiers ensure that video decryption keys are only delivered to the student's authorized devices.
- Anti-Account Sharing: Hardware identifiers prevent unauthorized simultaneous access from unauthorized third parties.
- No Location or Fingerprinting Tracking: We do not collect GPS location data, advertising IDs (e.g., Google GAID, Apple IDFA), browsing history, or background app activities.
3. In-Memory Video Decryption & Screen Security
To safeguard clinical intellectual property and copyrighted medical lectures:
- All video lecture chunks are encrypted with AES-128 and decrypted strictly in volatile RAM memory. Decryption keys are never stored on persistent flash storage or SD cards.
- On Android, the app enforces
FLAG_SECUREat the OS window manager level, preventing screen mirroring, screenshots, and screen recording apps from capturing lecture content. - On iOS and iPadOS, the application applies native
ScreenSecurityManagerhardware shields (UITextField.isSecureTextEntrycanvas isolation andUIScreen.capturedDidChangeNotificationblanking). - On Windows, the application calls Win32
SetWindowDisplayAffinityto block recording by OBS, Discord, and desktop screen capture tools.
4. Data Storage, Security & Cloudflare Architecture
All user accounts and authentication states are maintained on Cloudflare Serverless Edge Infrastructure (Cloudflare D1 SQLite database and Cloudflare Workers). Data is encrypted in transit using Transport Layer Security (TLS 1.3) and encrypted at rest within Cloudflare's secure global datacenters.
5. Third-Party Data Sharing
AZ Learn strictly prohibits the sale, rental, or marketing use of student information. We disclose information only to the following essential infrastructure providers:
- Cloudflare Inc.: For global edge routing, serverless API execution, database storage, and CDN media delivery.
- Resend API: For dispatching one-time transactional password reset codes (OTP) to the student's verified email.
6. Account & Data Deletion
In compliance with international data privacy regulations, students retain the right to request permanent deletion of their account and associated device bindings:
- You may submit an account deletion request by emailing support@medhub-academy.stream from your registered email address.
- Upon verification, your account record, device bindings, quiz histories, and enrollment records will be permanently purged from our database within thirty (30) business days.
7. Contact Information
For privacy inquiries, hardware slot resets, or compliance requests, please reach out to our administrative team:
- Email: support@medhub-academy.stream
- Academy Portal: https://azlearn-portal.pages.dev
- Operating Entity: AZ Learn Educational Systems