Privacy Policy
This policy explains what personal data MOALM collects when you use the platform, how we use and share it, the choices you have, and how we protect it. We wrote it to match how the platform actually works — including your documents, your learning data, and our use of third-party AI services.
Last updated: September 13, 2026
01Introduction
[LEGAL ENTITY NAME] ("MOALM", "we", "us", or "our") operates the MOALM adaptive medical-learning platform, including its website, web application, and related services (together, the "Platform"). This Privacy Policy explains what personal data we collect when you use the Platform, how we use and share it, the choices available to you, and how we protect it.
MOALM helps medical students and other learners turn their own study materials — lecture notes, slides, textbooks, and past exams — into concepts, practice questions, flashcards, review schedules, an AI tutor, and exam-focus insights. Because the Platform is built around your materials and your learning activity, we want you to understand clearly what data is involved.
This policy applies to all users of the Platform, whether you use it individually in your Personal Workspace or as a member of an Organization (for example, a university class or study group). If we ever offer a separate organization-level agreement, that agreement will govern the relationship between MOALM and the Organization, while this policy governs how we treat your personal data.
Your use of the Platform is also governed by our Terms & Conditions, available on the Platform at /terms. Please read both documents together.
02How MOALM Works — the Data Context
To explain our data practices, it helps to know what the Platform actually does with your materials:
- Document analysis. When you upload a document (PDF, DOCX, or PPTX), we extract its text, tables, and images (using optical character recognition where needed), divide it into sections, identify the concepts it covers, link those concepts to standard medical vocabularies (such as UMLS and MeSH) where possible, and connect the concepts into a knowledge graph.
- Study asset generation. From that analysis, the Platform generates practice questions, flashcards, and explanations, reusing existing validated content where it already exists.
- Personalized learning. As you study, the Platform records your answers, correctness, and timing, and uses them to estimate your mastery of each concept, detect knowledge gaps (including gaps in prerequisite concepts), schedule spaced reviews, and recommend what to study next.
- AI tutor. You can ask the tutor questions about your materials. The tutor answers using relevant passages retrieved from your documents.
- Exam Intelligence. If you upload past exams, the Platform analyzes their structure and historical patterns to estimate which topics deserve the most attention, and can build practice exams and study plans focused on those estimates.
Each of these activities involves processing data described in the next section.
03Information We Collect
Account information
When you create an account, we collect your name, email address, and password. Your password is stored only as a one-way hashed value — we cannot see it. You may also provide a mobile phone number during onboarding or in settings for account recovery and important updates. We also store account status information (such as whether your email has been verified and whether your account is active or suspended) and records of your workspace memberships.
Onboarding information (optional)
After signing up, the Platform may invite you to tell us your role (for example, student, teacher, professor, or parent), your study goal, and how you heard about MOALM. Providing this information is optional; we use it to personalize your experience and understand our learners.
User Content — documents and other materials you submit
The materials you upload or submit to the Platform ("User Content") are central to how MOALM works. User Content includes:
- Documents you upload, such as lecture notes, slides, textbooks, course packs, and previous exam papers (PDF, DOCX, PPTX);
- The content extracted from those documents, including text, images, page scans, and the sections ("chunks") we divide them into;
- Derived study assets generated from your documents, such as extracted concepts, concept relationships, questions, flashcards, and explanations;
- Questions, prompts, and messages you type into AI features (including the AI tutor and document chat); and
- Your AI tutor conversations, which are retained as transcripts so the tutor can maintain context within a session.
When you upload a document, you confirm that it belongs in a workspace you control. Documents uploaded while an Organization is your active workspace become part of that Organization’s shared library.
Learning Data
As you use the Platform, we generate and store "Learning Data" about your studying, including:
- Questions you answer, the answers you selected or wrote, whether they were correct, and how long you took;
- Exam attempts, your answers to each exam question, scores, and results;
- Review history and spaced-repetition scheduling state for the material you study;
- Estimated mastery levels and knowledge-gap assessments for the concepts you have studied, including diagnosed gaps in prerequisite concepts;
- Study sessions and study activity, such as what you studied, when, and for how long; and
- Post-exam check-ins where you choose to report how your real exam went, which we use to evaluate and improve the accuracy of Exam Intelligence.
AI interaction and usage records
We keep technical records of AI feature usage tied to your account and workspace — for example, which AI features you used, the models and providers involved, token counts, and the associated processing cost. These records help us enforce usage limits, operate the Platform efficiently, and monitor for abuse. If you use the voice tutor, your voice audio is streamed to our speech-model provider to power the conversation, as described in Section 5.
Technical and log data
We collect limited technical data necessary to operate and secure the Platform, including authentication tokens, rate-limiting records, and security logs. Certain logs — such as records of administrative actions and password-reset requests — include IP addresses and browser/device identifiers. We do not use third-party advertising or analytics trackers on the Platform.
Billing records
If you purchase a paid feature, we create and keep records of your orders — the product purchased, the amount and currency, payment status, the payment processor’s transaction references, and any refund history. We do not store your full card number or card security code; payment details are handled by our payment processor (see Section 10).
04How We Use Your Information
We use personal data to operate, maintain, and improve the Platform, specifically to:
- Create and administer your account, Personal Workspace, and Organization memberships;
- Process and analyze the documents you upload, and generate the study assets you request (concepts, questions, flashcards, explanations);
- Power AI features, including the AI tutor, document chat, adaptive learning, and Exam Intelligence;
- Personalize your learning experience, as described in Section 6;
- Track your progress, calculate mastery, schedule reviews, and generate progress analytics for you;
- Send transactional emails, such as email-verification codes, password-reset links, security notices, processing-status updates, and access-activation and expiry notices (see Section 16);
- Process payments, maintain billing records, and enforce the entitlements and usage limits attached to free and paid features;
- Detect, prevent, and address abuse, security incidents, and violations of our Terms & Conditions; and
- Understand how the Platform is used so we can improve its quality, reliability, and efficiency.
Legal bases we rely on
Depending on where you live, data-protection laws may require us to identify a legal basis for processing. In general: we process personal data to perform our contract with you (providing the Platform you signed up for); to comply with legal obligations; on the basis of your consent where you have given it (for example, optional onboarding information you choose to provide); and for our legitimate interests in operating, securing, and improving the Platform — such as keeping usage records, preventing abuse, and analyzing aggregate usage patterns — always balanced against your rights.
05AI Processing and Third-Party AI Providers
MOALM uses a combination of our own processing infrastructure and third-party artificial-intelligence services to deliver its features. This section explains what leaves our infrastructure and who processes it.
- Large language models. To analyze documents, extract concepts, generate questions and explanations, and power the AI tutor, portions of your User Content and your questions are sent to third-party large-language-model providers. This can include the text of your uploaded documents (or extracted sections of them), the questions and options being generated or reviewed, your typed questions, and relevant passages retrieved from your documents to answer them.
- Embedding services. To support search and semantic matching, we convert text from your documents into mathematical representations ("embeddings") using specialized embedding services. The embeddings themselves are stored in our database; the text used to create them is processed by the embedding provider.
- Medical entity linking. Extracted concept names (not full documents) may be sent to our medical-vocabulary linking service to identify standard identifiers such as UMLS and MeSH codes.
- Optical character recognition. Pages that contain scanned images rather than text are processed by our OCR service to extract their content.
- Voice tutor. If you use the voice tutor, your audio is streamed from your device directly to our speech-model provider (Google) to conduct the conversation. Voice sessions are subject to daily usage limits.
These providers process data on our behalf for the purpose of delivering the Services. The specific providers we use may change as we update our infrastructure; the current categories of providers are described above and, where applicable, in Section 13 (international transfers).
Important — AI provider training. Whether a third-party AI provider may use submitted content to train or improve its own models is determined by that provider’s terms of service and the configuration of our account with them. We do not make any representation that your content is excluded from provider training processes unless and until we confirm and document that configuration.
We do not use your uploaded documents, tutor conversations, or Learning Data to train our own foundation models.
06Personalization and Your Learner Model
MOALM builds a model of your learning in order to personalize your experience. Your learner model is constructed from your Learning Data and is used to:
- Estimate your mastery of each concept you have studied;
- Detect knowledge gaps, including "root-cause" gaps in prerequisite concepts that may be holding back your performance on more advanced topics;
- Schedule spaced-repetition reviews at the times you are most likely to benefit from them;
- Recommend what to study next and in what order;
- Adapt the difficulty and selection of practice questions to your level; and
- Build exam-focused study plans that prioritize topics by both their estimated exam importance and your current mastery.
These estimates are probabilistic and imperfect. They are study aids, not evaluations of you as a person or predictions of your academic future. You can always choose what to study regardless of what the Platform recommends.
Your learner model is scoped to you. Within any given workspace, your Learning Data is associated with your account, and other members of an Organization cannot see it (see Section 8).
07Content Sharing Across Workspaces
To keep the Platform efficient and its question bank high-quality, certain derived study content may be shared beyond the workspace in which it was originally generated. Specifically:
- Validated shared content. Concepts, concept relationships, questions, and flashcards that have passed our quality and grounding checks may be marked as shared across the Platform and made available to users in other workspaces and Organizations.
- Reuse of equivalent processing. If a document you upload is identical or semantically equivalent to one that has already been processed (by you or by another user), the Platform may reuse the previously generated derived content — for example, questions and concepts — rather than processing the document again.
In these cases, what may be shared is the derived study content (questions, concepts, relationships, flashcards), not your account information, your Learning Data, or the uploaded file itself. Your uploaded files remain stored within the workspace they were uploaded to, and your Learning Data is never shared across workspaces.
This reuse is one of the ways MOALM keeps costs and prices down while building a better shared knowledge base over time.
08Organizations and Administrator Access
Every user has a Personal Workspace, which is created automatically, is private to you, and cannot be discovered by others. You may also join one or more Organizations (shared workspaces) using an invitation or join code provided by the Organization.
What Organization membership means for your data
- Documents uploaded to an Organization are shared with its members. When an Organization is your active workspace, documents you upload become part of that Organization’s library and can be viewed by its members.
- Organization administrators manage the Organization’s learning content — for example, learning modules, exams, and Exam Intelligence analyses. They can also view aggregate AI usage and cost data for the Organization, attributed to anonymized user identifiers (not names or email addresses).
- Your individual Learning Data is not visible to Organization administrators. In the current version of the Platform, administrators cannot see your answers, scores, mastery levels, progress, study sessions, or tutor conversations.
- Joining is your choice. If your university or study group operates an Organization on MOALM, decide for yourself which materials you upload there, and remember that Organization documents are visible to its members.
The Platform evolves. If we introduce features that allow Organization administrators to see member learning data, we will update this policy and provide appropriate notice and controls before doing so.
MOALM personnel
Our system administrators can access account, content, technical, and billing data as necessary to operate, support, secure, and troubleshoot the Platform — for example, to investigate reported issues, retry failed processing, or address suspected abuse. Administrative access is restricted to authorized personnel, and administrative actions are recorded in audit logs.
10Payment Processing
Payments on the Platform are processed by Kashier, our third-party payment processor. When you make a purchase:
- You are redirected to a checkout page hosted by Kashier (or presented with an InstaPay QR code, where available);
- Your payment details (such as card or wallet information) are entered on and handled by Kashier — they are transmitted to Kashier and not stored by MOALM; and
- We receive and store only the information needed to maintain your order history and provide your purchase — for example, the product, amount, currency, payment status, the processor’s transaction references, the payment method type, and refund history.
Kashier’s own terms and privacy policy apply to the payment pages and the processing of your payment details.
11Data Retention
We retain your personal data for as long as your account is active, and afterwards for as long as needed for the purposes described in this policy — for example, to maintain the content you generated, to keep billing and transaction records for accounting purposes, to prevent abuse, and to comply with legal obligations.
- Billing records are retained as financial records and are not deleted when content is removed.
- Derived study content that has been validated and shared across the Platform may be retained even after the original document or uploader account is no longer active, because it no longer identifies you.
- Short-lived technical data — such as authentication tokens, verification codes, and cached processing results — expires automatically within minutes to days.
To request deletion of your account or specific data, see Section 15.
12Data Security
We use a range of technical and organizational measures to protect the Platform, including:
- Password protection. Passwords are stored only as salted one-way hashes.
- Authenticated, token-based access. Sessions use expiring access tokens; resetting your password signs out your active sessions.
- Workspace isolation. Every request is evaluated against your active workspace and membership. Documents and content in one workspace or Organization are not accessible from another, and this isolation is enforced on every API request, not only in the interface.
- Role-based access control. What users and administrators can do is restricted by role.
- Audit logging. Administrative actions are logged with the acting account, timestamp, and network information.
- Rate limiting and abuse controls. Authentication, verification, and other sensitive endpoints are rate-limited to resist automated attacks.
- Verification of payment notifications. Payment webhooks are cryptographically verified before being processed.
No system is perfectly secure. If we ever become aware of a security incident affecting your personal data, we will take steps to contain it and will notify affected users and regulators where required by law.
13International Data Transfers
We operate from Egypt, and the services we rely on — including AI, embedding, payment, hosting, and email providers — may process data in other countries. When your data is transferred across borders, we rely on the arrangements described in this policy and on the safeguards agreed with those providers.
14Your Privacy Rights
Depending on where you live, you may have rights over your personal data, including the right to:
- Know what personal data we hold about you and receive a copy of it;
- Ask us to correct inaccurate or incomplete personal data;
- Ask us to delete your personal data;
- Object to or restrict certain processing;
- Withdraw consent you have given to optional processing (for example, onboarding information), without affecting the lawfulness of processing that came before; and
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, contact us at info@moalmai.com using the email address associated with your account. We will respond within a reasonable period and may need to verify your identity before acting on your request. Please note that some in-product self-service options (such as editing your profile or deleting your account directly from the interface) are limited in the current version of the Platform; in those cases we will handle your request through support.
Where we cannot fulfill a request — for example, because the data must be retained to comply with a legal obligation — we will explain why.
15Account and Data Deletion Requests
The current version of the Platform does not offer a self-service option to delete your account or your uploaded documents. If you want your account, documents, or other personal data removed, contact us at info@moalmai.com and we will process your request in accordance with this policy and applicable law.
When you leave or are removed from an Organization, your membership ends but the content you uploaded to that Organization remains part of the Organization’s library, and your Learning Data within that Organization is retained in your history. If you have questions about the data held in an Organization you left, contact us.
16Email Communications
We currently send only transactional emails that are necessary to operate your account and the Platform:
- Email-verification codes;
- Password-reset links and password-change security notices;
- Document-processing status updates (for example, when analysis is ready or processing failed);
- Exam assembly notices;
- Purchase-related notices (when a paid feature is activated or expires); and
- Service and security messages.
We do not currently send marketing emails. Because the messages above are essential to operating your account, they cannot be opted out of. If we introduce optional product or marketing emails in the future, we will provide a way to opt out, and we will update this policy.
18Minors
MOALM is designed for medical students and other learners in higher education, and is not directed at children. You must be at least 17 years old (or the age of digital consent in your jurisdiction, if higher) to create an account. If we learn that we have collected personal data from a child below the applicable age, we will delete it. If you believe a minor is using the Platform inappropriately, contact us at info@moalmai.com.
19Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Platform, our data practices, or the law. We will post the updated policy on this page and revise the "Last updated" date at the top. If a change materially affects how we use your personal data, we will notify you before it takes effect — for example, by email or by a prominent notice in the Platform.
Your continued use of the Platform after a change takes effect means you accept the updated policy.
20Contact Us
If you have questions about this Privacy Policy or how we handle your personal data, contact us:
- Operator: [LEGAL ENTITY NAME]
- Address: [REGISTERED ADDRESS]
- Privacy contact: info@moalmai.com
Your use of the platform is also governed by our Terms & Conditions →