Privacy Policy
com.medatlas.app (Android) and com.medatlas.ios (iOS/iPadOS) apps, to the desktop application for Windows and macOS, and to the web/PWA version.In short: Epistemis works 100 % offline and without an account; in that mode your data never leaves your device. If you decide to create an account to sync across devices, we store your email address and your study progress in Google Firebase, encrypted in transit and accessible only by you. We show no advertising, use no trackers and never sell or share your data. You can export or delete everything whenever you want.
This is an English translation of the Spanish original. If the two ever diverge, the Spanish version prevails.
Contents
1. Data controller
The controller for Epistemis (“the app”, “we”) is its independent developer, reachable at soporte@somatryx.com. Epistemis is an educational project intended for the study and revision of Medicine by students and health professionals.
2. Two modes of use
a) Local mode (default) no account · offline
On installing the app you can use it without registering. Everything you generate — topics read, favourites, notes, highlights, revision cards, quiz results, streaks, settings — is stored solely in your device's local storage (localStorage / IndexedDB). That information is not transmitted to any server and is not accessible to us or to third parties.
b) Account mode (optional) cloud sync
If you want your progress synced across several devices, you can voluntarily create an account. Only then is any data processed off the device, as detailed below. This feature is entirely optional: you can ignore it and go on using Epistemis without limit.
3. Data processed
| Category | When | Detail |
|---|---|---|
| Study data | Always (local); in the cloud only with an account | Topics read, favourites, notes and highlights you write, revision cards, decks, progress, results and streak. Notes and cards may contain whatever text you enter. |
| Clio conversations | Always local; in the cloud only if you enable “Sync Clio conversations” | Questions and answers saved in your history. This sync is off by default and requires separate consent. When you turn it off, chats remain on the device and the copy in your Firestore document is removed. Attached images are not saved in history and are never synced. |
| Email address | Only with an account | Needed to authenticate you and to recover access. |
| Account identifier (UID) | Only with an account | Anonymous identifier generated by Firebase to associate your data with your account. |
| Google data | Only if you choose “Continue with Google” | The name and email of your Google account, provided by Google sign-in to create your account. |
| Minimal technical metadata | Only with an account | Timestamp of the last sync. Firebase may log connection IP addresses as part of its authentication service (see its policy). |
| Purchase data | Only if you buy a subscription | The receipt issued by the store and the status of your subscription (active or not), plus technical data about the device and the app version. Never your card details: those are handled by the store and never reach us. See point 5. |
| Mock-exam score (cohort) | Only if you turn on “Compare me with the cohort” in Settings; off by default | Only the rounded percentage correct, the number of questions and which exam it belongs to (MIR / USMLE). It is added to a global histogram of 20 counters, which contains no identifier of yours, no timestamp, and nothing that could reveal the score is yours. Your percentile is computed by your own device from that histogram; we never know it. Your account is used only to prevent bulk submissions, via a daily counter stored separately with no cross-reference to the histogram. |
We do not collect: location, contacts, advertising identifiers or browsing data outside the app. We perform no remote usage analytics and no profiling (no Crashlytics, no Sentry, and no trackers). The app may keep local learning counters —for example, numbers of searches, searches with no results, and correct answers— to show your progress. They never store your search text, remain on your device, can be disabled in Settings, and are included when you export your data. The only aggregate information that can be sent is the score histogram described above, and only if you turn it on. The microphone and photos/camera are used only if you activate them inside Clio (voice dictation and image interpretation); in that case, that content is sent in order to generate your answer according to the Clio mode you use (see point 5) and we do not store it.
Smart search (including the natural-language kind) runs entirely on your device: what you type into the search box is not transmitted to any server.
4. Purposes and legal basis
- Providing the study service (saving your progress on the device): legitimate interest / performance of the requested functionality.
- Cloud syncing and accounts: your consent, given when voluntarily creating the account. You can withdraw it by signing out or deleting the account.
- Syncing Clio conversations: your separate, explicit consent, given in Settings. It is off by default and can be withdrawn at any time without disabling sync for the rest of your progress.
- Security and abuse prevention for the authentication service: legitimate interest.
- Managing your subscription (validating the store receipt and giving you the access you paid for): performance of the contract you enter into on purchasing it. With no purchase there is no processing.
- Comparing your score with the cohort: your consent, given by turning the switch on in Settings and withdrawable by turning it off. It is off by default and, while it is, nothing is sent.
We do not use your data for advertising and do not subject it to automated decisions with legal effects.
5. Providers and third parties
For the optional account and syncing feature we use Google Firebase (Google Ireland Ltd. / Google LLC) as a processor:
- Firebase Authentication — handles registration and sign-in (email/password and Google).
- Cloud Firestore — stores your personal progress document and, only if you enable the dedicated switch, your Clio conversation history. If you use Clio included, it also stores a monthly usage counter (number of queries, without their content); all accessible only by your account (see “Security”).
- Cloud Functions — only if you use Clio included: a relay that forwards your query to the AI provider using the key Epistemis pays for (see “Clio · AI tutor”).
- Firebase Hosting — serves this privacy policy page.
- Firebase Cloud Messaging — only if you enable app notices: handles sending notifications and uses a device identifier (token) in order to deliver them.
History and relay are separate processing activities. The server that generates an answer does not log the content of the query or response. Separately, the app keeps history on your device and only adds it to your private Firestore document if you enable “Sync Clio conversations”, which is off by default. You can disable it to remove the cloud copy without deleting the local copy.
Processing by Google is governed by its Firebase Privacy and Security Policy and the Google Privacy Policy.
Clio · AI tutor
Clio is the artificial-intelligence tutoring feature. It is dormant until you use it and works in two modes; in both, your content is processed only when you send a query:
- Clio included (when signed in, paid for by Epistemis): your question — together with the relevant fragment of the app's content and, if you provide it, dictated text or the image you select — is sent to a Epistemis-owned server (a Firebase Cloud Functions function) that acts as a relay: it forwards the query to a language-model provider to generate the answer and returns it to you. Depending on the task, the provider may be Google (Gemini), DeepSeek, Anthropic (Claude) or OpenAI (ChatGPT). We do not store the content of your queries or the answers: the server keeps only a monthly usage counter tied to your account (number of queries, without their content) in order to apply the free quota. Processing by each provider is governed by its own privacy policy.
- Clio with your own key (optional): if you prefer not to go through the Epistemis server, you can enter your own key for Anthropic (Claude), OpenAI (ChatGPT) or Google (Gemini). In that case the query is sent straight from your device to the provider you choose, without passing through our servers, and your key is stored on your device only and is not shared with us.
PDFs and the Evidence space. If you open an article or PDF inside the Evidence space, text extraction happens entirely on your device: the file is not uploaded to any Epistemis server or third party, and the sources you record are stored like the rest of your data. Only what you decide to send to Clio in a question leaves your device, and in that case the above applies. Reproducible PubMed queries open in your browser against the NLM service, using the search terms you composed.
If you do not use Clio, none of these connections is made.
Purchases and subscriptions
Epistemis charges nothing today, so none of this is happening yet; it is described in advance because the mechanism already ships inside the app.
If you buy a subscription on mobile, payment is processed entirely by the store (Google Play or the App Store). Your payment details, billing name and address never reach Epistemis: the store only tells us whether the subscription is active.
If you buy it from a computer or browser, payment is processed by Lemon Squeezy (Lemon Squeezy LLC, United States), acting as merchant of record and, as regards your billing data, as its own controller rather than as our processor: they are the ones charging you and issuing the invoice. On their payment screen you provide them directly with your email address, your billing name and country and your card details. Epistemis never sees or stores your card details.
We send them only your account identifier (UID), inside the purchase link, so the payment can be matched to your account and access enabled; and we receive back, via a signed notification, the subscription status (active, cancelled, expired), its renewal date, the product purchased and a customer identifier. We do not store your billing email or any card data, not even the last four digits. See the Lemon Squeezy privacy policy.
To validate the receipt for purchases made in the mobile stores we use RevenueCat, Inc. (United States) as a processor. What is sent to it is:
- Your account identifier (UID) if you are signed in — so that your subscription follows you across devices — or an anonymous identifier generated on the device if you use the app without an account.
- The purchase receipt issued by the store, plus technical data about the device and the app version.
Nothing about your study activity is sent: no topics, no notes, no cards, no quiz results, no Clio queries. See RevenueCat's privacy policy.
In addition, an in-house Cloud Functions function checks that status and returns a signed access grant to the device; it stores only the subscription status associated with your account, not the receipt and no payment data.
If you never buy anything, this section does not affect you: with no purchase there is no receipt to validate.
Presentation resources (no personal data): the typefaces are bundled inside the app (they are not requested from external servers). When online, some guides containing formulas may load the MathJax mathematical typesetting library from a public content delivery network, solely to display the equations; offline, the app renders them itself. These requests include no personal data and no identifiers of yours, and the app remains fully functional offline.
The atlas images (radiology, histology, anatomy, etc.) are bundled inside the app and come from openly licensed sources; their origin and licence are cited within the app itself (“Sources and trust” section).
6. International transfers
If you use the account, your data is stored on Google Cloud infrastructure, which may be located on servers in the United States or other regions. Google implements recognised transfer mechanisms (such as the EU Standard Contractual Clauses). By creating the account, you consent to this transfer. In local mode there is no transfer at all.
If you buy a subscription, receipt validation is carried out by RevenueCat, Inc. from the United States, covered by the EU Standard Contractual Clauses. For web purchases, payment is processed by Lemon Squeezy LLC, also from the United States and as its own controller for the billing data you give them on their payment screen. Both transfers are necessary to perform the subscription contract and are limited to the data described in point 5; with no purchase they do not occur.
7. Retention and deletion
- Local data: stays on your device until you erase it. You can remove it completely from Settings → Erase everything, or by uninstalling the app.
- Cloud data: kept for as long as your account exists. From Account and syncing you can delete your account and all its cloud data permanently (this erases your Firestore document and your authentication record).
- Portability: from Settings → Export data you can download all your information in a JSON file, and re-import it whenever you want.
8. Your rights
You have the right to access, rectify, erase and port your data, as well as to withdraw your consent and object to processing. Most of these rights you exercise directly from the app (export, edit, delete account). For any other request or complaint, write to us at soporte@somatryx.com. If you live in the EEA/United Kingdom, you may also complain to your data protection authority.
9. Security
- All communication with the cloud uses encryption in transit (HTTPS/TLS).
- Your Firestore document is protected by security rules that only allow access from your own authenticated account: no other user can read or modify your data, or enumerate the user list.
- We do not store your password: it is managed by Firebase Authentication using industry standards.
- We do not sell, rent or transfer your data to third parties for commercial purposes.
No system is infallible; in the event of a security incident affecting you, we will take reasonable measures and inform you where appropriate.
10. Minors
Epistemis is aimed at students and health professionals. It is not directed at children under 13 and we do not knowingly collect their data. If you believe a minor has provided us with data, contact us so we can delete it.
11. Cookies and tracking
The app uses no advertising cookies and no trackers. It uses local technical storage (localStorage/IndexedDB) that is essential to save your progress and preferences on the device. There is no third-party analytics and there are no tracking pixels.
12. Medical notice
Epistemis is educational and revision material. Its content — including guides, calculators, doses, algorithms and image atlases — is for training purposes and does not constitute medical advice, nor does it replace formal training, current clinical guidelines or the judgement of a health professional. Always verify clinical decisions against up-to-date sources and with professional judgement. Use of the information is the user's responsibility.
13. Changes to this policy
We may update this policy to reflect changes in the app or in regulations. We will publish the version in force on this same page and update the date at the top. Substantial changes will be communicated inside the app where reasonable.
14. Contact
For any privacy question or to exercise your rights: soporte@somatryx.com