Privacy policy
Updated 2 September 2026
Astra QB is a medical question-bank app for students, operated by Pythowner ("we", "us"). This policy explains what the app collects, why, and what you can do about it. It applies to the Astra QB mobile app and the services behind it.
What we collect
Account
- At signup: your email address, your password (stored only as a hash, never in plain text) and your full name.
- Optional profile details you may add later: a username, phone number, gender, date of birth, governorate and a profile photo.
- A code is emailed to you to confirm the address. Confirmation does not lock you out of the app.
Devices
For each device you sign in on we keep a hashed device fingerprint, the platform (iOS or Android), the device model name and, if you allow notifications, a push notification token. This is what enforces the per-account device limit and lets you sign a device out from Settings.
Study activity
Your practice sessions, answers, time spent, flags, highlights, notes, results and the statistics derived from them. This is the product: it is what powers your history, review and analytics screens.
Security
- Question content shown to you carries a per-account watermark identifier. It is a random number tied to your account, not your name or email.
- The app detects screenshots and screen recording on question screens and reports the event, with the session and question it happened in, to our staff. On Android the screen is blanked instead. There is no automatic penalty: a person reviews these events before any action is taken.
- We keep access logs (sign-ins, token refreshes, device changes, content served) with IP address and app version for abuse prevention.
Telegram (optional)
If you connect Telegram from Settings, we store your Telegram user id and handle. It is used to deliver password reset codes and for support through the Astra bot. You can disconnect at any time from Settings; the bot then stops recognising your account.
Crash reports
If the app crashes, a report containing the error, the app version and device model may be sent to Sentry so we can fix it. Reports do not include your study content.
What we do not do
- No advertising and no advertising identifiers.
- No sale or rental of personal data.
- No tracking of you across other apps or websites.
- No location, contacts or microphone access. The camera and photo library are used only if you choose to set a profile picture.
Services we rely on
| Service | What it handles |
|---|---|
| Firebase Cloud Messaging (Google) | Delivering push notifications to your device. |
| Cloudflare R2 | Storing files, including your profile photo and question media. |
| Sentry | Crash reports. |
| Telegram | Only if you link your account: reset codes and support messages. |
Each of these processes data on our behalf to run the service. We do not give them anything beyond what the function needs.
Why we process it
To provide the service you signed up for (your account, your access and your study history); to keep the service and its content secure, which is a legitimate interest given that the questions are licensed material; to send you notifications you have allowed; and to meet legal and accounting obligations for purchases.
How long we keep it
- Account and study data: until you delete your account.
- Security and access logs: kept after deletion in de-identified form (the link to your account is removed; the watermark number stays so that content leaked before deletion can still be traced).
- Purchase records: activation and payment records are kept as accounting requires, without your name or contact details once the account is deleted.
Your choices and rights
- See and edit your profile from Settings in the app.
- Sign out devices you no longer use from Settings.
- Turn notifications off in your phone's settings.
- Delete your account from Settings, or by email. See Delete your account for exactly what is removed and what is kept.
- Ask us for a copy or correction of your data by writing to [email protected] from the address on your account.
Children
Astra QB is made for medical students and is not directed at children under 16. We do not knowingly collect data from them; if you believe a child has created an account, contact us and we will remove it.
Changes
If we change this policy we update the date at the top and, for material changes, tell you in the app. Continued use after a change means you accept the updated policy.
Contact
Pythowner, operator of Astra QB. Email [email protected].