Legal
Privacy Policy
1. Who we are
MedMinds ("MedMinds", "we", "us", or "our") is an online test-preparation platform for students preparing for India's NEET-UG examination, operating at medminds.me. We provide NTA-pattern mock tests, a curated Question Bank, performance analytics, and a personal test planner.
For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), MedMinds is the Data Fiduciary responsible for the personal data described in this policy, and you are the Data Principal. Your data is processed and stored on servers located in India.
MedMinds is an independent preparation resource. We are not affiliated with, endorsed by, or connected to the National Testing Agency (NTA), the National Medical Commission, or any official NEET body.
2. Information we collect
- Account information: Your name and email address when you register with a password or sign in with Google.
- Verification data: One-time passcodes and password-reset codes we generate and send to your email to confirm it's really you. These are stored only in hashed form and expire quickly.
- Test and practice data: Your answers, scores, timing, and attempt history for each mock paper and Question Bank item you attempt.
- Planner data: Dates you mark in the Test Planner (stored in our database and, optionally, synced to your Google Calendar).
- Session & functional cookies: A login-session cookie (
neet.sid) that keeps you signed in for up to 7 days, plus a few small first-party cookies that remember display state (such as whether your account has Test Series access) so the interface renders correctly. None of these contain advertising or cross-site tracking identifiers. - Usage data: Standard server logs (IP address, browser type, pages requested, timestamps) generated automatically when you use the site. We do not use third-party analytics or advertising trackers.
3. How we use your information
We process your personal data on the basis of your consent and to provide the service you have asked for. Specifically, we use it to:
- Create, secure, and maintain your account.
- Send verification codes, password-reset links, and essential account notifications by email.
- Serve test papers and Question Bank items, and calculate your scores.
- Display your performance history and analytics on your Dashboard.
- Sync planned test dates to your Google Calendar — only if you choose to connect it.
- Keep your session active across page visits.
- Maintain platform reliability, prevent abuse, and diagnose errors (via server logs).
We do not sell, rent, or trade your personal information, and we do not use it for advertising or profiling.
4. Google Calendar integration
When you click "Connect Google Calendar", we request the https://www.googleapis.com/auth/calendar.events scope. This lets us:
- Create a calendar event on your behalf when you plan a test date in the Test Planner.
- Update that event (for example, marking it "Completed") when you submit a test on the planned date.
- Delete the event when you remove a planned date from the planner.
What we do NOT do with your Google Calendar data:
- We do not read, scan, or store any existing events from your Google Calendar.
- We do not use your Google Calendar data for advertising, profiling, or any purpose unrelated to test scheduling.
- We do not share, transfer, or sell your Google account or calendar data to any third party.
- We do not allow any human — including MedMinds staff — to read your Google Calendar data, unless you explicitly request support and give consent.
Your Google refresh token is stored solely to create, update, and delete the calendar events you requested. You may disconnect Google Calendar at any time from your Dashboard — this deletes the stored token from our servers immediately, so MedMinds can no longer access your calendar. To also remove MedMinds from the list of apps that can access your Google Account, visit your Google Account Permissions.
5. Data storage, security & location
Your data is stored in a database hosted on infrastructure located in India. We apply safeguards appropriate to a service of our size, including:
- Passwords and verification codes hashed with the industry-standard bcrypt algorithm — never stored in plain text.
- All data in transit encrypted over HTTPS.
- The login-session cookie (
neet.sid) set ashttpOnly,Secure(on HTTPS), andSameSite=Lax, with session-id rotation on every sign-in to guard against session-fixation. - Google OAuth tokens stored with access restricted to the MedMinds application only.
No online service can guarantee absolute security, but we work to protect your data and to promptly address any vulnerability we become aware of.
6. Third-party services & sub-processors
We keep our third-party footprint deliberately small. We rely on the following providers, each only for the purpose stated:
- Google OAuth 2.0 & Google Calendar — for optional sign-in and calendar sync. Governed by Google's Privacy Policy.
- Brevo (Sendinblue) — our transactional email provider, used to deliver verification codes, password-reset links, and account emails. Brevo receives your email address and the message content solely to deliver it. See Brevo's Privacy Policy.
- Gmail SMTP (Google) — a fallback path used to send the same account emails in the rare event our primary email provider is unavailable.
- DigitalOcean — our cloud hosting provider, whose India-region infrastructure stores our application and database.
- Google Fonts — for typography. Font files may be requested from Google's servers when you load a page.
We do not use Meta/Facebook Pixel, Google Analytics, or any advertising SDK.
7. Data retention
We keep your account and test data for as long as your account is active. Verification codes expire within minutes; server logs are retained only for a limited period for security and debugging. Google Calendar tokens are deleted immediately when you disconnect the integration. When you delete your account, we erase your personal data as described in Section 8, except where a limited amount must be retained to comply with law.
8. Your rights
As a Data Principal under the DPDP Act, and subject to its conditions, you may:
- Access a summary of the personal data we hold about you.
- Correct, complete, or update inaccurate data in your account.
- Erase your account and associated data.
- Withdraw consent at any time — for example, by disconnecting Google Calendar via your Dashboard or via Google Account Permissions, or by closing your account.
- Export your test history — contact us for a machine-readable (JSON) copy.
- Grievance redressal — raise any concern about how we handle your data (see Section 9).
Withdrawing consent for a feature does not affect the lawfulness of processing carried out before withdrawal, and some data may need to be retained to run the parts of your account you continue to use.
9. Grievance redressal
If you have a question, complaint, or request concerning your personal data, you may contact our Grievance Officer at privacy@medminds.me. We will acknowledge your request within a reasonable time and endeavour to resolve it within 30 days, in line with applicable Indian law.
10. Children's & students' privacy
MedMinds is intended for students aged 15 and above, reflecting the typical age of NEET aspirants. If you are under 18, you may use MedMinds only with the consent of a parent or legal guardian, as required by the DPDP Act. We do not knowingly create accounts for, or collect personal data from, children under 13. If you believe a child under 13 has provided us data, please contact us for immediate deletion.
11. Changes to this policy
We may update this Privacy Policy as our features and legal obligations evolve. When we make significant changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of MedMinds after an update takes effect constitutes acceptance of the revised policy.
Contact us
For privacy questions, data requests, or to reach our Grievance Officer:
privacy@medminds.me
Looking for the legal side of the agreement instead? Read the Terms of Service →