PanOph
Back to Home

Privacy Policy

Last updated: 4 June 2026

1

Introduction

PanOph ("we", "our", or "us") operates the PanOph mobile application, the website at panoph.com, and the PanOph Images contribution service at images.panoph.com (collectively, the "Service"). This Privacy Policy explains how we collect, use, and protect your information when you use our Service.

By creating an account or using the Service, you consent to the collection, use, and processing of your information as described in this Privacy Policy, in accordance with the Digital Personal Data Protection Act, 2023. If you do not agree with this policy, please do not use the Service.

2

Information We Collect

Account Information

When you sign in with Google, we receive your name, email address, profile picture, and account identifiers necessary for authentication from your Google account. We use your name and email to create and manage your PanOph account. Your profile picture is only displayed back to you (e.g. in the navigation bar) and is not used for any other purpose.

Usage Data

We collect information about how you use the Service, including scenarios attempted, scores, MCQ attempts, content votes, favourites, bookmarks, progress through learning modules, content viewed, search activity, and feature interactions. This data is used to track your learning progress, maintain access, personalize the Service, and improve the Service.

Device & Analytics Data

We use Firebase Analytics to collect usage statistics such as app opens, screen views, search queries, content interactions, scores, and feature engagement. Analytics events are linked to your user account to help us understand per-user engagement and improve the Service. Firebase Analytics may also automatically collect device information such as device model, operating system version, and app version. We do not use advertising identifiers for ad targeting and we do not track you across other apps or websites. We do not serve ads in the Service. We may also send account-linked analytics properties and events such as subscription tier, active bundle, collaborator status, pioneer status, pricing interactions, invite-code checks, checkout starts, payment result views, and subscription actions.

Billing and Subscription Data

If you purchase, manage, cancel, or receive access to a subscription or extension, we collect and process billing and access records such as selected plan, billing period, subscription status, subscription start and end dates, provider, provider customer or subscription identifiers, provider transaction identifiers, product identifiers, payment status, refund status, failure reason, payment method category, coupon or invite-code use, and related support records. Payment details are processed by our payment and app-store providers; PanOph does not store complete card numbers.

User-Submitted Content

If you voluntarily submit feedback, error reports, topic requests, or testimonials through the Service, we store that content along with your name and email address. This may include ratings, comments, report details, page IDs, section IDs, topic details, platform, and related status fields. Testimonials may be displayed within the Service with your name.

Image Contributor Program Information

If you use PanOph Images, we collect contributor profile details such as your name, email address, professional title, designation, degree, place of work, and optional contributor profile photo. We also collect uploaded image files, image titles, clinical context you provide, upload metadata, review status, rejection reasons, approved-image counts, and access grant records. This information is used to operate the image submission, review, contributor recognition, and access-grant process. Contributors are expected to deidentify submissions before upload. If an upload contains personal data, we process it only as needed for review, security, support, compliance, removal, or enforcement of the contributor terms.

Referral Data

If you arrive at PanOph via a referral link, we store a referral cookie on your device to attribute the referral. When you create an account, this referral code is permanently associated with your account. The cookie is used solely for referral attribution and expires after 90 days. Referral records may include the creator or referral code, referred account, content-view counts, qualified referral status, conversion status, and related creator dashboard or payout metrics.

Local Storage

We store your learning progress locally on your device using browser local storage and IndexedDB (web) and Hive (mobile) for offline access and faster load times. Firebase Authentication also uses IndexedDB to maintain your sign-in session. This data stays on your device unless you sign in, at which point your progress is synced to our servers.

3

How We Use Your Information

  • To provide and maintain the Service
  • To save and sync your learning progress across devices
  • To manage your account, subscription status, billing records, and access grants
  • To analyze usage patterns and improve the Service
  • To attribute referrals to content creators
  • To manage creator dashboards, referral performance, and payout-related records
  • To communicate important updates about the Service
  • To process payments, refunds, subscription changes, app-store entitlements, and billing support
  • To operate the PanOph Images submission, review, and approval workflow
  • To apply image-derived access grants and maintain access records
  • To detect misuse, verify submissions, and handle copyright, consent, or privacy concerns
  • To investigate account restrictions, enforce fair-use rules, resolve disputes, and maintain platform security
4

Data Sharing

We do not sell, trade, or rent your personal information to any third party. We do not share your personal data with third parties for their own marketing or advertising purposes.

Your data is shared only with the following service providers, solely for the purpose of operating the Service:

  • Google Firebase — authentication and analytics
  • Cloudflare — application backend, database, object storage, and content delivery
  • Google Sign-In — account authentication
  • Vercel — website hosting and content delivery (may process server access logs including IP addresses for security and performance purposes)
  • Razorpay — web payments, subscriptions, refunds, and payment status updates
  • RevenueCat — mobile subscription entitlement synchronization
  • Apple App Store and Google Play — mobile app purchases, subscriptions, renewals, cancellations, and billing status

These service providers process data on our behalf and are bound by their own privacy policies and data processing agreements.

PanOph administrators and reviewers may access contributor profile details, uploaded images, clinical context, contributor profile photos, review decisions, and rejection reasons where needed to review submissions, manage access grants, address support requests, and enforce the Image Collaborator Program terms.

Authorized PanOph administrators, reviewers, and support personnel may access account, subscription, billing-related, contributor, referral, feedback, report, restriction, and payment-related records only where needed to operate the Service, provide support, review submissions, prevent misuse, resolve disputes, maintain security, and comply with legal or operational requirements.

If a PanOph Images submission is approved, the approved image and selected contributor recognition may be displayed or used in PanOph educational content, academic content, platform content, and educational or platform-related promotional material, including social media, in accordance with the Image Collaborator Program terms.

5

Data Storage & Security

Your app data (learning progress, scores, favourites, and subscription status) is stored securely through our application backend using managed cloud database and storage infrastructure. All data transmission is encrypted using TLS, and stored data is encrypted at rest by our infrastructure providers.

Your authentication data (name, email, profile picture, and sign-in metadata) is processed by Google Firebase Authentication, which is a global service operated by Google with servers that may be located outside India. This is limited to the information required to verify your identity and maintain your sign-in session. Analytics data is processed by Google Firebase Analytics, which may also use servers outside India. Our hosting and backend providers may also process requests through global edge infrastructure, which means server logs including IP addresses may be processed outside India.

Billing and subscription records may be processed by Razorpay, RevenueCat, Apple App Store, Google Play, and our backend infrastructure. These records may include provider identifiers, subscription state, entitlement state, transaction references, refund status, billing issue status, and limited payment metadata required to provide access, reconcile payments, prevent fraud, handle support, and maintain financial and audit records.

PanOph Images submissions, contributor profile details, review decisions, rejection reasons, contributor profile photos, and access-grant records are stored using managed backend, database, and object-storage infrastructure. Uploaded images remain private during review and are accessible only to authorized systems, administrators, and reviewers unless and until PanOph approves them for educational platform use under the Image Collaborator Program terms.

6

Data Retention

We retain your account and progress data for as long as your account is active. If you request deletion of your account, we will delete your personal data from our application database within 30 days of receiving your request. We will also reset your user identifier in our analytics systems so that future data is no longer linked to your identity. Analytics data that has been aggregated or anonymised and cannot reasonably be used to identify you may be retained.

For PanOph Images, submitted content files may be retained, archived, removed, or deleted according to the Image Collaborator Program terms. We may retain submission metadata, review decisions, rejection reasons, access-grant records, compliance records, and audit records where required for security, legal compliance, dispute handling, fraud prevention, program operations, or enforcement of contributor terms, even if image files are deleted.

Billing, subscription, refund, referral, creator, support, restriction, feedback, report, and audit records may be retained where required or permitted for tax, accounting, legal compliance, fraud prevention, dispute handling, security, service operation, creator attribution, or enforcement of our terms.

7

Account Deletion

You can request deletion of your account and associated personal data by emailing us at support@panoph.com with the subject line "Account Deletion Request".

Upon receiving your request, we will delete your personal data from our database within 30 days, except where retention is required or permitted for legal, security, audit, dispute, fraud-prevention, service-operation, or contributor-program reasons. Data stored locally on your device can be removed by uninstalling the app or clearing the app's data.

Deleting your account or requesting removal of a submitted image does not automatically revoke licenses already granted for approved PanOph Images content, except where required by applicable law or agreed by PanOph.

8

Your Rights

Under the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000, you have the right to:

  • Access and request a copy of the personal data we hold about you
  • Request correction of inaccurate or incomplete data
  • Request deletion of your data and account
  • Withdraw consent for data processing
  • Nominate another person to exercise these rights on your behalf
  • Lodge a complaint with the Data Protection Board of India

You may withdraw consent by requesting deletion of your account. Withdrawal of consent may result in deletion of your account and personal data, and you may no longer be able to use the Service. Data-rights requests do not automatically revoke licenses already granted for approved PanOph Images content, except where required by applicable law or agreed by PanOph. To exercise any of these rights, contact us at the email address below or reach out to our Grievance Officer.

9

Age Restriction

The Service is intended for medical professionals and students and is not directed at individuals under the age of 18. Use of the Service is not permitted for anyone under 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected personal data from a person under 18, we will delete that data promptly unless retention is legally required.

10

Data Breach Notification

In the event of a personal data breach that is likely to cause harm, we will notify the Data Protection Board of India and affected users as required under the Digital Personal Data Protection Act, 2023.

11

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date.

12

Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts in New Delhi, India.

13

Grievance Officer

In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the Grievance Officer for the purpose of this Privacy Policy is:

Dr. Rahul Arya

Co-founder, PanOph

Email: support@panoph.com

We will acknowledge your complaint promptly and aim to resolve it within 30 days of receipt.

14

Contact Us

If you have any questions about this Privacy Policy, please contact us at:

support@panoph.com