Privacy Policy

Medley Medprep

Operated by Vynnberg Pty Ltd

ABN: 19 697 391 281

Last Updated: 2 October 2026 | Effective Date: 8 May 2026


1. About This Policy

Medley Medprep is an online ISAT preparation platform operated by Vynnberg Pty Ltd, registered in Victoria, Australia ("we", "us", or "our"). Our website is medleymedprep.com.

This policy explains how we collect, use, store, disclose, and protect personal information when you visit our website, use our learning and community features, purchase a subscription, or contact us. We handle personal information in accordance with applicable Australian privacy law, including the Privacy Act 1988 (Cth) and Australian Privacy Principles where they apply.

For privacy enquiries or complaints, use our Contact Us form, with "Privacy" in the message title.

2. Information You Choose to Provide

You can browse public pages without creating an account, although technical and usage information may still be collected as described below. Account, payment, and contact details are needed for the features that use them. If you do not provide required information, we may be unable to provide those features or respond to your request.

Optional profile details and community contributions are your choice. Please avoid including sensitive information, such as health information or identity documents, or other people's private details in profile fields, posts, messages, or screenshots unless necessary for your request and you have authority to share them.

3. Personal Information We Collect

The information collected depends on the features you use and which security features are enabled.

3.1 Accounts, Profiles, and Preferences

We collect your name, email address, account identifier, authentication information managed by Firebase Authentication, and account details such as your role, plan, creation date, sign-in activity, and account status. If you sign in with Google, we receive the account information provided through that sign-in, such as your name, email, and profile picture.

We also store profile information and preferences you provide, such as a preferred name, profile photo, optional physical address, time zone, and appearance settings. We may record whether you completed or skipped onboarding and which notifications you dismissed.

3.2 Learning, Practice, and Exam Activity

We collect answers, scores, question completion and timing information, practice and exam history, saved drafts, marked questions, schedules, and study progress. We use these records to save and restore sessions, show performance analytics, and manage access to free and paid learning features, including question allowances and promotion eligibility.

Some preferences, recent searches, study tasks, and draft progress are stored in your browser. Other records are stored with your account so they can be used across sessions or devices.

3.3 Profile Photos and Community

If you upload a profile photo, we process the image and store the resulting photo and its file reference. Our upload process resizes and re-encodes images and removes embedded metadata, such as camera metadata. This does not remove information visible in the image itself.

Community posts, replies, and interactions may be linked to your account, display name, profile photo, role badge, and posting times. Information you share there can be copied or shared by others. Uploaded images may also be accessible to someone who has their image link.

3.4 Payments, Subscriptions, and Promotions

Stripe processes payments through its checkout and billing services. We send relevant account and purchase information, such as your email, account identifier, and selected plan, to Stripe. Payment card information is provided to Stripe; our application database does not store full card numbers or card security codes.

We keep payment-related references and records needed to administer your purchase, such as Stripe customer and subscription identifiers, plan and payment status, access dates, cancellations, and promotion redemption details. We may also record when an administrator grants or changes account access. These records support billing enquiries, access management, and prevention of repeated promotional claims.

3.5 Contact Requests, Reports, and Attachments

Our contact form collects your email address, phone number, message title, and message. Enquiries are delivered through our email provider to our support inbox.

When you submit a question or website report, we collect your message, report category, relevant question or page details, submission time, and any screenshots you attach. Signed-in reports are associated with your account identifier and email address. We also keep the report's status and handling information.

The Platform may send automatic error reports containing diagnostic information, such as the affected page path, browser information, error details, and times. Some automatic reports can be submitted without signing in. Such reports may still involve technical request information and security checks; they are not necessarily anonymous.

3.6 Website Usage and Conversion Analytics

We record selected interactions with our own website, such as public page views, button clicks, preview completions, and the start or completion of signup. These events include a random browser-session identifier, public page path, interaction labels, and time. We also record the first public page visited in a browser session, the referring website's hostname, and campaign labels from links. We do not collect full referring URLs or search query text in these events. Session storage keeps this source information while you move between pages.

These event messages do not include your name or email address as event fields. When you sign in, we can link the session's source information to your account identifier and use it to measure account creation, completed free diagnostics, and payments confirmed by Stripe. Conversion records do not include your answers or scores. These records are not anonymous. This measurement is sent to our own service and helps us understand which content brings visitors who go on to use the learning platform.

3.7 IP Addresses and Shared-Account Abuse Signals

When IP abuse monitoring is enabled, our server processes the connection IP address associated with successful signed-in visits and completed free practice sessions. An IP address identifies a network connection and may be shared by a household, school, workplace, mobile network, or VPN. It does not reliably identify one person or their physical address.

Our monitoring records include:

  • A keyed hash of the IP address and a masked version of the address;
  • The associated account identifier, account creation time, and activity times;
  • The type of activity and completed free-practice question counts.

The keyed hash lets us identify accounts using the same connection without putting the full address in the shared-connection report. It remains linked to account activity and is not anonymous data. Separately, we store the most recently observed full IP address for an account in encrypted form, together with its observation time and expiry time.

Only authorised Super Admins can access the IP abuse reports and the latest full IP address shown in a user's account details. The information helps them review patterns that may indicate repeated-account or free-allowance abuse. A shared IP is a review signal, not proof of abuse, and does not by itself automatically block an account or reduce its allowance.

Super Admins can also view country-level counts of approximate recent student activity locations on the admin dashboard. Our server derives these counts from the latest retained IP observation using a local geolocation database; it does not send IP addresses to an external geolocation service. The map response contains counts and coverage information, without account identifiers, names, emails or IP addresses. It excludes observations older than 30 days and does not extend their retention. These approximate network locations may reflect VPNs, proxies or mobile networks and are not students’ declared residence or citizenship.

3.8 Other Security and Technical Records

Our servers and infrastructure providers may process IP addresses, browser and request information, timestamps, and operational logs to deliver and protect the service.

We use separate spam and submission controls for contact requests, reports, and uploads. These controls may use keyed hashes of network or email identifiers, submission fingerprints, request counts, and processing receipts to detect excessive or duplicate submissions. They can automatically limit or reject excessive requests. This is separate from the shared-account review signals described above.

We also receive browser security reports about blocked or unexpected resources and keep records of administrative actions, such as role and permission changes. Browser security reports are filtered to limit unnecessary detail; support and error reports may contain more diagnostic information.

4. How We Collect Information

We collect information directly when you enter it, submit content, or use Platform features; automatically through requests, browser storage, activity events, and diagnostics; and from service providers such as Firebase Authentication and Stripe when they provide account or payment updates.

5. How We Use Information

We use information to:

  • Create and secure accounts, remember preferences, and provide learning and community features;
  • Save progress, calculate results, show analytics, and administer access and question allowances;
  • Process subscriptions and promotions and resolve billing enquiries;
  • Respond to enquiries, investigate reports, and troubleshoot errors;
  • Understand website use and improve content, reliability, and the signup experience;
  • Detect suspicious account patterns, limit spam and repeated submissions, and investigate misuse;
  • Maintain administrative records and meet applicable legal obligations.

If we send optional promotional communications, you may ask us to stop them. Essential account, security, support, and billing communications may still be needed to provide the service.

6. Who Can Receive or Access Information

We do not sell personal information.

Authorised personnel can access information according to their roles and responsibilities. For example, administrators with report access can review ordinary support and question reports, including their attachments and associated account details. Access to IP abuse reports and full account IP addresses is restricted to Super Admins.

We use service providers to operate the Platform, including:

  • Google/Firebase for authentication, databases, and file storage;
  • Vercel for website hosting and delivery;
  • Tencent Cloud for our API server;
  • Stripe for payment processing and subscription management;
  • Email providers for delivery and storage of contact and support correspondence.

These providers process information needed for their services. Their own notices explain their handling practices: Firebase privacy and security, Vercel Privacy Notice, and Stripe Privacy Policy.

Information is also shared through community features as described in section 3.3. We may disclose information where required or authorised by law, or as part of a business transfer subject to applicable privacy protections.

7. Overseas Processing and Storage

Our services use infrastructure outside Australia. Our configured Firebase database is in Singapore, and our configured file storage is in the United States. Firebase Authentication also processes data in the United States, as described in Firebase's privacy information.

Our other providers, including Tencent Cloud, Vercel, Stripe, and email providers, may process information through their hosting, support, and subcontractor operations in other countries. A database or storage location does not mean all processing is confined to that country. Contact us if you need more information about overseas handling.

Where applicable, we take reasonable steps to meet Australian privacy requirements when disclosing personal information overseas, including considering provider safeguards and contractual arrangements.

8. Data Security

We use safeguards such as encrypted connections, authenticated access, role-based permissions, and restricted server access to security records. The latest full IP address held for abuse review is encrypted separately from ordinary profile information. A keyed IP hash helps match connections but does not make linked account records anonymous.

We take reasonable technical and organisational steps to protect information against loss, misuse, and unauthorised access or disclosure. No system can guarantee absolute security. You can help by protecting your sign-in details and avoiding sensitive content in screenshots or public contributions.

9. Cookies, Local Storage, and Similar Technologies

We and our integrated providers use browser storage and related technologies for authentication and Platform features. Local storage may hold preferences, recent activity, draft progress, and indicators used to avoid duplicate activity records. Session storage also holds the random identifier and event markers used for our website usage measurement described in section 3.6.

We do not currently provide a dedicated in-app cookie preference centre. You can manage cookies and site storage through your browser. Blocking or clearing storage may sign you out, reset preferences, or remove unsynchronised drafts. Clearing browser storage does not delete information already stored on our servers, and blocking storage does not necessarily prevent technical requests or usage events from being sent.

10. Retention and Account Deletion

Retention depends on the information and why it is needed. We consider service delivery, security investigations, billing and dispute handling, and applicable legal requirements when deciding how long to keep records. We delete or de-identify information when it is no longer needed, subject to applicable retention obligations.

  • IP abuse records: Raw activity records expire 30 days after the recorded activity. The encrypted latest IP address expires 30 days after its latest observation. Expired raw records are excluded from new detections, account IP displays and country-level dashboard counts; automated database deletion can occur later. When activity triggers a warning, we save a separate report with masked connection information, associated account identifiers, counts and activity times. These report summaries remain available for manual administrator review after the detection window and raw-record expiry; marking a report resolved retains it in report history. They do not contain the full IP address. Report summaries and review state have separate retention from raw monitoring records and providers' operational logs.
  • Submission controls: Most request counters and processing receipts are scheduled for expiry around seven days after their counting window or submission day ends. Receipts needed for unfinished image cleanup can remain until cleanup completes, followed by a further expiry period. These short retention periods do not apply to the contents of reports or support emails.
  • Account and learning records: These are generally held while your account is active so that you can use your profile, progress, and history. Account deletion removes your authentication account, profile and associated account records, any legacy leaderboard entry, and linked sign-in and exam-score records.
  • Uploaded images: Replacement and account-deletion processes schedule managed profile photos for cleanup. Cleanup can take time and may be retried. Report attachments follow the report's retention; putting a report in the administrator recycle bin does not permanently erase it.
  • Other records: Support correspondence, reports, community contributions, payment and promotion records, usage analytics, and security or administrative records have separate retention needs. Ending a browser session or deleting an account does not automatically remove all of these records.

An account-deletion report records information such as the account identifier, email address, previous plan and role, and deletion time to document the request and support follow-up. IP observations associated with a deleted account remain subject to their normal expiry. Billing records may be retained by us or Stripe where needed for transactions, disputes, or legal obligations.

Copies held in provider backups or recovery systems may remain until those systems' retention cycles complete. If you want other information removed, including a report or community contribution, contact us so we can assess the request and explain any information that must be retained.

11. Your Choices, Requests, and Complaints

You can update available profile settings and request account deletion through the Platform. You may also ask us for access to personal information we hold about you, correction of inaccurate information, deletion where permitted, or an end to optional marketing communications.

Use our Contact Us form, with "Privacy" in the title, and describe your request or complaint. We may need to verify your identity before providing or changing account information. Please do not send passwords, full payment card details, or identity documents unless we specifically arrange an appropriate verification process with you.

We will assess and respond within a reasonable time and any timeframe required by applicable law. If we cannot fulfil a request, we will explain the reason, subject to legal restrictions, and available complaint options.

If a privacy complaint remains unresolved after you contact us, you may contact the Office of the Australian Information Commissioner (OAIC), where it has jurisdiction. See the OAIC privacy complaints page or call 1300 363 992 for its current process.

12. Children and Minors

Our services are used by students, including people under 18. We recommend that parents or guardians review this policy with minors, particularly the information about public profiles, posts, photos, and screenshots. If you believe a minor's personal information has been provided or handled inappropriately, contact us using the form above.

13. Third-Party Services and Links

External websites and services, including payment and sign-in services, have their own privacy practices. Review their notices when using them. This policy describes our handling of information and does not replace those providers' policies.

14. Changes to This Policy

We may update this policy as our services, providers, or legal obligations change. The latest version will appear on this page with an updated "Last Updated" date. We will provide any additional notice required by applicable law.

15. Governing Law

This policy is governed by the laws of Victoria, Australia and applicable Commonwealth law, without limiting privacy rights that apply to you under applicable law.