Privacy policy

Applies to the MedFiszki app (Android and iOS). Last updated: 12 August 2026.

In short. By default your studying never leaves the device. Cards, review progress, statistics and settings are stored locally. The app connects to the network to confirm a purchase of the full base — and, if you switch it on yourself, to synchronize your progress through your own Google account. There are no ads, no analytics, no profiling and no user accounts, and we run no server holding your data.

1. Who is responsible

The controller of personal data processed in connection with the app is Instaling sp. z o.o., a company registered in Poland. Privacy contact: instaling@instaling.pl.

2. What stays on the device

The following is kept in the app's local database. We have no access to it, we do not send it to any server of ours, and we cannot recover it if you delete it. Until you turn synchronization on (section 5), it does not leave the device at all:

  • flashcard content — both the bundled cards and any you add or import yourself,
  • review history and the FSRS scheduling state of every card,
  • study statistics: streaks, section mastery, hardest terms,
  • settings: interface language, known language, daily new-card limit, active directions, reminder time.

A backup is an ordinary file that you create yourself. It goes exactly where you save or send it — we never come into contact with it.

3. When the app uses the network

By default in two situations: when you buy access to the full base, and when you restore an earlier purchase (for example after changing phones). A third one appears only once you switch on Google Drive synchronization yourself (section 5). Otherwise the app works entirely offline, and a lack of connectivity never blocks studying — nor does a failed synchronization.

4. Purchase-related data

Purchases are handled by the store you downloaded the app from (Google Play or the App Store), and purchase status is verified on our behalf by RevenueCat, Inc. acting as our processor. The following data is involved:

Data Purpose
Purchase history and subscription status from the store (what was bought, when, until when it is valid) Unlocking the full base and checking whether a subscription is still active
An anonymous user identifier issued by RevenueCat and the store's purchase identifier Linking the purchase to the installation so that it can be restored on a new device
Diagnostic data sent with the request: app version, purchase SDK version, operating system, store country Handling the request correctly and diagnosing purchase failures

We do not pass this data on for marketing, do not combine it with your studying and do not build a profile from it. The app does not collect your name, e-mail address, phone number, location, contacts, advertising identifier or list of installed apps.

We never see your payment details — card number, billing address. Those are handled exclusively by the store.

5. Google Drive synchronization — optional

It is off by default. You turn it on yourself with a switch in the app's settings (or by accepting the offer the app makes once). Until you do, nothing described in this section happens.

Once enabled, the app signs you in with your Google account and asks for access to a single hidden folder that belongs to the app itself (the drive.appdata scope). This is not access to your Drive: the app cannot see, read or touch any other file of yours. The folder is invisible in the Drive interface and cannot be shared with anyone.

What we store in that folder:

  • review progress and the FSRS scheduling state of your cards,
  • flashcards, decks and sections you created or imported yourself,
  • study settings (daily limit, active directions, target retention, paused sections).

The key point: this data goes to your Google account, not to us. We run no server of our own, we have no access to that folder and we cannot see its contents. The account's e-mail address is used only to display "Signed in as…" inside the app and is never stored by us.

What does not go into the folder: the content of the bundled term base (it ships inside the app, so there is no reason to upload it) and any record of whether you have purchased access.

You can turn synchronization off or disconnect the account at any time in the app's settings. You delete the folder itself in your Google account settings: Security → Your connections to third-party apps and services → MedFiszki → remove access and app data. Processing is based on your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time — withdrawal does not affect the studying stored locally.

6. Legal basis and retention

Purchase data is processed under Article 6(1)(b) GDPR: it is necessary to perform the contract, that is to give you the content you paid for. We keep it for as long as the entitlement to the full base lasts, plus the period required by tax law and limitation periods for claims.

The entitlement itself is additionally cached locally on your device — that is what lets the app work offline instead of asking the store over and over.

7. Recipients

  • RevenueCat, Inc. (USA) — purchase verification, as a processor under a data processing agreement. Transfers outside the EEA rely on Standard Contractual Clauses. RevenueCat's privacy policy.
  • Google Ireland Ltd. / Apple Inc. — as store operators, for the transaction itself; there they act as separate controllers under their own terms.
  • Google — as the Drive provider, if you enable synchronization (section 5). The data then sits in your own account and is covered by Google's privacy policy; we are not a party to that storage.

We use no analytics or advertising tools whatsoever.

8. Notifications

Review reminders are generated locally by your device's operating system. We send no push notifications from a server and need no identifier for them.

9. Your rights

You have the right to access your data, rectify it, erase it, restrict or object to its processing, and to data portability. Write to instaling@instaling.pl — we respond within 30 days.

Deleting data. You delete your study data yourself by uninstalling the app or clearing its data in system settings. If you used synchronization, you delete the app's Drive folder in your Google account settings (section 5). We delete the purchase record held by RevenueCat on your request sent to the address above; note that afterwards the purchase can no longer be restored automatically — the transaction history then remains only in the store.

You may also lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warsaw) or with your local supervisory authority.

10. Children

The app is intended for people aged 16 and over — the material is aimed at medical students and healthcare workers. We do not direct it at children and do not knowingly collect their data.

11. Changes

If the scope of processing changes, we will update this page and the date at the top. Significant changes will additionally be announced in the app's release notes in the store.