Privacy Policy
Last updated: June 2026
1. Who We Are
SA Note is operated by SA Note, a company based in the United Arab Emirates ("SA Note", "we", "our", or "us"). We are the data controller responsible for your personal data. Our full registered company details are available on request.
SA Note is an educational platform for medical students and professionals. This Policy explains what data we collect, why, who we share it with, how long we keep it, and the rights you have. For any privacy question or request, contact contact@sa-note.com.
2. Personal Data We Collect
| Category | Examples |
|---|---|
| Account & identity | Name, email, password (stored hashed), Google ID if you use Google sign-in |
| Profile & education | University, profession, class/year, graduation year, upcoming exam date |
| Subscription & billing | Plan, billing status, Stripe customer ID. We do not store full card numbers — Stripe handles payments. |
| Learning activity | Mock-exam attempts and scores, question attempts, bookmarks, progress, spaced-repetition data |
| User-generated content | Notes, comments, group-study chat messages, uploaded files |
| Technical & usage | Device/browser info, IP address, pages visited, features used, analytics events |
| Marketing preferences | Whether you have opted in or out of marketing emails |
We do not intentionally collect special-category (sensitive) data. Please do not enter patient-identifiable clinical data into notes or chats.
3. How and Why We Use Your Data
| Purpose | Legal basis |
|---|---|
| Create and manage your account; provide the platform | Performance of a contract |
| Process subscriptions, billing and refunds | Performance of a contract |
| Personalised study feedback, incl. AI exam debriefs | Contract / legitimate interests |
| Moderate group-study chat for safety | Legitimate interests |
| Service and transactional emails | Contract / legitimate interests |
| Marketing emails and product updates | Consent (withdraw anytime) |
| Analytics to improve the platform | Consent (via cookie banner) |
| Security, fraud and abuse prevention | Legitimate interests / legal obligation |
| Comply with legal, tax and regulatory duties | Legal obligation |
4. Artificial Intelligence (AI) Processing
Some features use third-party AI services (currently Anthropic's Claude) to generate personalised mock-exam debriefs (using your scores, domain performance and any short reflections) and to moderate group-study chat for harassment or abuse.
This data is processed only to deliver these features and is not used to train the provider's models under our service terms. AI output may be inaccurate and must not be relied upon as medical advice — see our Disclaimer.
5. Cookies and Analytics
We use essential cookies (to run the site and keep you signed in) and, with your consent, analytics cookies (currently Mixpanel). Analytics do not run until you accept them in our cookie banner. See our Cookie Policy.
6. Who We Share Your Data With
We do not sell your personal data. We share it only with service providers ("subprocessors") who help us run SA Note under contracts that require them to protect it — including Stripe, Brevo, Amazon SES, Anthropic, Mixpanel, Google, Amazon Web Services, Bunny.net, Meilisearch and Upstash. The full current list is at /subprocessors. We may also disclose data where required by law or in connection with a business transfer.
7. International Data Transfers
We operate from the UAE and our providers operate globally, so your data may be transferred outside your country, including outside the EEA and UK. Where we transfer data from the EEA or UK we rely on appropriate safeguards such as Standard Contractual Clauses or transfers to adequate countries. Request details at contact@sa-note.com.
8. How Long We Keep Your Data
- Account & profile: life of your account, then deleted/anonymised within 30 days of closure.
- Learning activity & content: life of your account.
- Billing & tax records: as required by tax law (typically 5–7 years).
- Chat moderation logs: up to 12 months.
- Analytics: typically up to 14 months.
- Backups: purged on our routine backup-rotation cycle.
9. Your Rights
Depending on where you live, you may have the right to:
- Access a copy of your data
- Correct inaccurate data
- Delete your account and data
- Restrict or object to certain processing, including marketing
- Receive your data in a portable format
- Withdraw consent at any time
You can export your data and delete your account directly in Account → Privacy, and manage marketing in your account settings. For anything else email contact@sa-note.com; we respond within the time required by law. You may also complain to your data-protection authority.
10. Region-Specific Information
EEA & UK: If you are in the EEA or UK, you can contact us about any data-protection matter at contact@sa-note.com. UK users may complain to the Information Commissioner's Office.
United Arab Emirates: We process personal data in accordance with applicable UAE data protection law.
California (CCPA/CPRA): California residents may know, delete, correct and opt out of the sale/sharing of personal information. We do not sell or share personal information as defined under California law. Use the in-app controls or contact contact@sa-note.com.
11. Children
SA Note is intended for users aged 16 and over. We do not knowingly collect data from children under 16 without appropriate consent.
12. Security
We use encryption in transit, hashed passwords, access controls and reputable infrastructure providers. If a breach affects your rights, we will notify you and the relevant authority as required by law.
13. Changes to This Policy
We may update this Policy and will post the new version here with an updated date. For material changes we will notify you by email or in-app.
14. Contact Us
SA Note — Privacy & general enquiries: contact@sa-note.com.