Privacy Policy
Effective Date: June 28, 2026
SmartCare ("the App," "we," "our," or "us") is a clinical learning platform designed for healthcare students and professionals. This Privacy Policy explains how we collect, use, store, and protect your information when you use the SmartCare application, website, and related services.
By creating an account or using the App, you agree to the practices described in this policy. If you do not agree, please do not use the App.
1 Information We Collect
1.1 Information You Provide to Us
- Account Registration: When you create an account, we collect your email address, a password (stored as a salted hash — we never store plain-text passwords), and optionally your full name and professional level (e.g., Paramedic, EMT, Physician).
- Google Sign-In: If you choose to sign in with Google, we receive the email address and name associated with your Google account. We do not receive or store your Google password.
1.2 Information Collected Automatically
- Usage Data: We log basic server-side audit records for security purposes, including login attempts, registration events, and administrative actions. These logs include a timestamp, the action performed, the email address involved, and the IP address of the request. Audit logs are retained for security monitoring and are not used for analytics or advertising.
- Local Storage: The App stores your study progress, quiz attempts, accuracy scores, theme preferences, and PWA install state locally in your browser using
localStorage. This data stays on your device and is not transmitted to our servers unless you voluntarily sync it.
1.3 Information from Third-Party Services
- Google OAuth: We use Google Sign-In as an optional authentication method. Google shares your email address and name with us solely for account creation and authentication. Google's privacy policy applies to the initial OAuth flow.
- Chart.js (CDN): The App loads the Chart.js library from a content delivery network (jsdelivr.net). Your browser may communicate with the CDN to fetch this library. No personal data is sent to the CDN as part of this request.
- Google Fonts: The App loads font files from Google Fonts (fonts.googleapis.com, fonts.gstatic.com). Your browser may share your IP address with Google as part of the font request. Google's privacy policy governs this interaction.
2 How We Use Your Information
- To create and maintain your account.
- To authenticate you when you sign in.
- To display your study progress and performance analytics (stored locally in your browser).
- To respond to support inquiries (contact email only).
- To monitor and maintain the security and integrity of the service (audit logs).
3 Data Storage and Retention
- User Accounts: Account information (email, hashed password, name, role) is stored in a database on our server. We retain this data for as long as your account is active. You may request deletion of your account at any time (see Section 7).
- Audit Logs: Server audit logs are retained for a period of up to 90 days for security analysis, after which they are automatically deleted.
- Local Storage Data: Study progress, quiz results, and preferences stored in your browser's localStorage remain on your device. You can clear this data at any time through your browser settings or by using the "Clear Cache" option within the App. This data is not accessible to us unless you explicitly share it.
4 Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties. We do not share your information with third parties except:
- Service Providers: We use Google OAuth for authentication. Google receives only the data necessary to complete the OAuth flow (no SmartCare-specific data is sent to Google beyond the OAuth token exchange).
- Legal Compliance: We may disclose information if required to do so by law or in response to valid legal process (e.g., a court order or subpoena).
5 Data Security
We implement industry-standard security measures to protect your information:
- Passwords are hashed using
werkzeug.security.generate_password_hash(PBKDF2-based). Plain-text passwords are never stored. - All API communication occurs over HTTPS (TLS) in production.
- CSRF protection is enforced on all state-changing API requests.
- Rate limiting is applied to authentication endpoints to mitigate brute-force attacks.
- Server audit logs track security-relevant events for incident response.
While we take these precautions, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
6 Children's Privacy
The App is intended for use by healthcare students and professionals aged 16 and older. We do not knowingly collect personal information from children under the age of 13 (or under the age of 16 in jurisdictions where that is the applicable threshold). If we become aware that a child has provided us with personal information without parental consent, we will delete that information promptly. If you believe a child has provided us with personal data, please contact us.
7 Your Rights and Choices
- Account Deletion: Delete your account and all associated data immediately, in-app, from the "Danger Zone" on the sign-in page's account panel (sign in, then look for "Delete my account"). You can also request deletion by contacting us at the email address below, which we will process within 30 days.
- Data Access: You may request a copy of the personal data we hold about your account.
- Local Data: You can manage or clear your local storage data at any time through your browser settings or the App's cache-clearing feature.
- Cookies: The App does not use tracking cookies. Session cookies may be used for authentication purposes when you are logged in. These are strictly necessary for the functioning of the App.
8 Third-Party Links
The App may contain links to external websites or resources (e.g., educational references). We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any external services you visit.
9 Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the effective date at the top of this policy and, where appropriate, by displaying a notice within the App. Your continued use of the App after changes take effect constitutes your acceptance of the revised policy.
10 Open Source License
SmartCare's source code is released under the MIT License — free for the clinical education community to study, adapt, and build on.
11 Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
SmartCareAttn: Privacy
Soliman Anas
Email: solimananas.dev@gmail.com
Website: https://solimananas.github.io/SmartCare/