Privacy Policy
Last Updated: 2026-05-04
1. Introduction
Toussaint Ventures LLC ("we," "us," or "our") operate this site, a medical education platform that includes question banks, practice tools, quizzes, and related features for healthcare learners. The Service may be supported in part by advertising. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service. We are committed to protecting your privacy and complying with applicable data protection laws, including the GDPR (for users in the European Economic Area) and the CCPA (for California residents).
Data Controller: Toussaint Ventures LLC. For privacy inquiries, use the Contact us link in the Service.
2. Information We Collect
2.1 Information You Provide
- Account information: Email address, display name (optional), password (stored in hashed form)
- Communication preferences: Your choices regarding cookies and analytics
- Feedback: If you contact us or submit feedback, we collect the content you provide
2.2 Information Collected Automatically
- Usage data: Questions answered, responses selected, correctness, timestamps, session identifiers
- Technical data: IP address (for security and rate limiting), browser type, device information
- Session data: Session cookies for authentication, cookie consent preferences
2.3 Advertising and measurement partners
If we show advertisements, we may work with advertisers, ad networks, and measurement vendors. They may receive or process limited technical data from your device or browser (such as device or browser characteristics, approximate location derived from IP where allowed, and ad interaction events) to deliver, cap frequency, or measure ads. We configure partners to limit use of personal identifiers to what is needed for those purposes. We do not sell your email address or account profile to advertisers as a list for their own marketing.
You can manage optional cookies and similar technologies through our Cookie preferences page (where available) and your browser settings.
2.4 Information from Third Parties
We do not currently receive personal information from third parties for marketing purposes unrelated to Service operations. If that changes, we will update this policy.
2.5 Optional weekly leaderboard
If you opt in via your account Profile, we process your count of questions answered in the current UTC calendar week (Monday 00:00 through Sunday 23:59:59, same week boundaries for everyone) and an optional leaderboard display label (a name you choose, or a short pseudonymous label if you leave it blank). Your email address is not shown on the leaderboard. Other learners who have also opted in may see your weekly count and that label on the weekly leaderboard. We may retain a pseudonymous top-three snapshot for past weeks so learners can revisit or share a read-only summary link; that snapshot does not include your email. You can opt out at any time in Profile; opting out stops new visibility to other learners on the board.
3. Legal Basis for Processing (GDPR)
If you are in the European Economic Area, we process your personal data on the following bases:
- Contract: To provide the Service (account creation, progress tracking, quizzes)
- Legitimate interests: Security, fraud prevention, service improvement, analytics (where not overridden by your rights); where permitted, contextual or limited personalization of advertisements and measurement necessary to operate a free-supported Service
- Consent: For optional analytics cookies, certain advertising cookies or similar technologies where required, and other processing where we ask for your consent
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service
- Authenticate you and manage your account
- Track and display your learning progress
- Personalize question recommendations and quiz sessions
- Offer an optional weekly leaderboard among learners who opt in (counts and labels only; email not shown)
- Send verification emails and account-related notifications
- Respond to your inquiries and support requests
- Enforce our Terms, prevent fraud, and protect the Service
- Comply with legal obligations
- Conduct analytics (with your consent where required) to improve the Service
- Deliver and measure advertising when we offer a free-supported Service (consistent with our policies and your choices)
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your information:
- Service providers: With vendors who help us operate the Service (e.g., hosting, email delivery). These providers are contractually obligated to protect your data and use it only for the purposes we specify
- Advertising and measurement vendors: Subject to contractual safeguards and regional requirements, vendors that place or measure advertisements may receive limited technical or pseudonymous information as described in Section 2.3
- Other learners (optional weekly leaderboard): If you opt in, other learners who have also opted in may see your weekly question count and your chosen leaderboard display label or a pseudonymous label, as described in your Profile settings. Your email is not displayed on the leaderboard
- Legal requirements: When required by law, court order, or governmental authority, or to protect our rights, safety, or property
- With your consent: In other circumstances where you have given explicit consent
International transfers: Our infrastructure may be hosted in the United States or other countries. If you are outside the U.S., your data may be transferred to and processed in the U.S. We rely on appropriate safeguards (e.g., Standard Contractual Clauses) where required by law.
6. Data Retention
- Account and usage data: Retained until you request deletion or 24 months after your last activity
- Consent records: Retained for compliance and audit purposes; may be retained after account deletion when required by law
- Security and audit logs: Retained as needed for security and legal compliance
You may request deletion of your data at any time through your account settings.
7. Your Rights
7.1 General Rights
- Access: You may request a copy of the personal data we hold about you
- Correction: You may update your profile information in account settings
- Deletion: You may request deletion of your account and associated data
- Export: You may request a portable copy of your data (e.g., via the "Export my data" feature in account settings)
7.2 GDPR Rights (EEA Users)
In addition to the above, if you are in the European Economic Area you have the right to:
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Data portability (receive your data in a structured, machine-readable format)
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority in your country
7.3 CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of your personal information
- Opt out of the "sale" of your personal information (we do not sell personal information)
- Non-discrimination for exercising your privacy rights
To exercise your rights, use the Contact us link or account settings (export/delete).
8. Cookies and Similar Technologies
We use cookies and similar technologies for:
- Essential cookies: Session management, authentication, security—required for the Service to function
- Preferences: Cookie consent and user preferences
- Analytics (optional): If you consent, we may use analytics cookies to understand how the Service is used
You can manage cookie preferences at any time via our Cookie preferences page. Where we introduce advertising-supported experiences, cookie and similar disclosures may supplement this Policy.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (HTTPS), secure password hashing, and access controls. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
10. Children's Privacy
The Service is not intended for individuals under 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected such information, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy and updating the "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
12. Contact Us
For privacy inquiries, to exercise your rights, or to report a data concern, use the Contact us link within the Service (when logged in).
For GDPR-related inquiries, you may also contact your local data protection supervisory authority.