Privacy
Study Navigator privacy policy
This policy covers the MediPrep Study Navigator ChatGPT app and MCP, Chrome extension, optional local macOS bridge, and their connections to MediPrep and learner-selected study providers.
Effective September 14, 2026
The short version
Study Navigator is a learner-controlled medical-education service. It does not sell personal data, serve advertising, build advertising profiles, or use private course, question-bank, Anki, Tutor, or ChatGPT content for MediPrep analytics, research, or model training.
Connecting the app, attaching a file, opening a page, or viewing a route is not permission for MediPrep to collect that content and is not a learning event. ChatGPT reads a learner-selected attachment within the learner's ChatGPT account. MediPrep receives only the bounded fields in an invoked tool request and never receives the attachment itself.
How the ChatGPT app and MCP work
The Study Navigator app connects ChatGPT to MediPrep's Model Context Protocol (MCP) endpoint. Depending on the learner's ChatGPT settings, ChatGPT may use the current conversation, attachments, or memory to decide whether to offer a MediPrep tool. That host-side context is controlled by OpenAI. MediPrep has no ambient access to the learner's chats, memories, files, browser, or other connected apps.
For a lecture breakdown, the MCP accepts only a short, institution-neutral medical concept phrase or bounded controlled concept identifiers. Its schemas exclude slide bodies, screenshots, OCR, speaker notes, filenames, local paths, course or school labels, learner identity, answers, performance, credentials, and proprietary resource bodies. Shared graph searches and results are request-scoped and are not durably persisted by MediPrep. Body-free operational logs may record only an outcome, latency, release hash, or error class—not the phrase, concept identifiers, result body, or attachment metadata.
To protect the public MCP from automated abuse, MediPrep derives one rotating daily HMAC digest from the network IP supplied by the hosting platform before authentication and, after successful authentication, a separate digest from the user ID. The service stores only the rate-limit namespace, daily digest, minute window, request count, and created or updated timestamps in a service-role-only security table. It stores no raw IP, user UUID, token, request body, tool arguments, answers, or performance. These counters are used only for rate limiting—not analytics, reporting, research, or training—and are deleted after 24 hours by a cleanup that runs each minute, subject to a temporary database or scheduler outage and the hosting provider's backup policy.
Some authenticated tools can read source-safe MediPrep course or planning projections, start a short-lived practice or study job, record an answer inside that expiring job, or prepare an external action. A preview is not a write. Calendar writes and personal-provider launches require the learner to request the corresponding apply or launch action; the tool cannot silently turn file access into permission to write or report learning activity.
Shared Context Graph and UWorld identifiers
The shared Context Graph is a public, versioned medical-concept routing release. It can return controlled concept metadata, reviewed Boards & Beyond routes, handoffs to current human-published MediPrep questions, public medical references, and reviewed numeric UWorld question identifiers or exact provider Topic Search labels mapped to controlled concepts. MediPrep presents numeric results as your learner-specific UWorld ID selection. The underlying release is shared, while the request-specific route is not stored as a per-learner graph or retained search.
A UWorld route contains only a released numeric question ID or reviewed exact topic identifier and label, controlled concept relationship, source and rights lineage, and a bounded provider action. It contains no UWorld stem, choices, answer, explanation, screenshot, private URL, credential, subscription state, history, or performance. The mapping does not provide UWorld access and is not a UWorld-issued license, partnership, or endorsement. The learner must have lawful access to the provider and remains subject to that provider's terms.
When the learner chooses the one-click UWorld handoff, a short-lived URL fragment carries only the selected numeric IDs or exact topic identifier and label, public graph action IDs, and release hashes into the signed-in MediPrep page in that browser. The fragment is cleared before the Companion acts and is not remotely stored by MediPrep. UWorld supplies the live topic question count, which MediPrep does not persist. ChatGPT handles the tool result under the learner's ChatGPT data settings. A device-local replay marker contains no question IDs, topic, or learner identity.
Learner-specific UWorld availability and every installed Anki or AnKing locator stay in the local Companion lane. The remote personal-route relay may hold only the MediPrep account and connected-device IDs, controlled concept and provider keys, graph authority, lifecycle status, bounded counts, timestamps, and opaque action UUIDs. Exact personal question, card, note, deck, tag, schedule, answer, credential, and performance data do not enter the MCP result or relay store.
Account, authentication, and connected services
- MediPrep account. Authenticated operations use the learner's MediPrep email, account identifier, authentication session, and the minimum owner scope needed to prevent one account or browser profile from reading another's records. Passwords are handled by MediPrep's authentication provider and are not stored in study records.
- Source-safe course and planning state. Authenticated tools may read or update controlled course, session, concept, planning, and calendar-projection fields already attached to the account. Private source bodies, filenames, paths, notes, exact teach-backs, and ambient chat history are not added to those projections.
- Google Calendar. If the learner connects Google and confirms a write, MediPrep uses the granted OAuth scope to manage the dedicated MediPrep planning action described in the preview. Google receives and retains the resulting calendar data under the learner's Google account and Google's terms.
- Chrome and local study tools. The extension may keep account-scoped Canvas locators, private course text, UWorld execution bindings, Anki locators, local permissions, and bounded action receipts in that Chrome profile. They remain device-local unless the learner separately confirms a named send to a selected recipient.
Learner-requested captures and Anki drafts
The local extension also offers separate capture actions beyond shared UWorld routes. When you request an Anki draft from a supported answer review, it reads the current question text, correct answer, explanation, and optional educational objective. The minimum text needed to draft the card goes through the local bridge to your connected ChatGPT workspace. The formatted explanation and instructional images can be included in the card you approve in Anki; those images and formatted HTML are not part of this text-only AI request. Opening a UWorld page alone does not authorize this capture or send.
You can separately capture supported UWorld question history and performance reports, review the result, and save it in your account-scoped history on this device. These actions can handle question identifiers, topics, outcomes, counts, and capture times. Capturing or saving progress does not authorize AI analysis; requesting analysis is a separate action with its own disclosed input.
Screen and video study actions use the browser's explicit sharing picker. Captured images selected for an AI task go through the local bridge to your connected ChatGPT workspace. Manual card drafts require review and a confirmed Anki add. Optional video autopilot requires a separate session activation naming the destination deck and card limit; it can send subsequent slide images and add unreviewed AI drafts during that bounded session. Stop or end sharing to stop new work. An add already being committed may finish.
MediPrep does not remotely store these private captures or drafts. Temporary local image files are cleaned up when the AI operation ends; a forced process or computer shutdown can leave local files requiring cleanup. Saved cards and media remain in your Anki collection and may sync under your existing Anki settings. Local cleanup does not delete content retained by your AI provider; its account settings and terms govern that processing. Use only sources you are authorized to process, and do not share patient information or unrelated private content.
Storage, retention, and deletion
- Shared Context Graph requests and results have no MediPrep body persistence. Memory-only practice and study jobs expire within 30 minutes.
- Personal-route requests and launches expire after two minutes; completed body-free availability results expire no later than ten minutes and become unavailable immediately at expiry.
- A learner-started local page capture may retain only its source-safe receipt for at most 30 days. A linked answer episode expires after two hours by default and no later than 24 hours, always before the capture.
- Account-scoped source-safe course and planning projections remain until the learner replaces or revokes the connection or deletes the MediPrep account, unless a shorter contract shown in the product applies. Device-local Navigator records remain until removed in the product, cleared from the browser or Anki profile, or the extension/add-on is uninstalled.
Learners can disconnect the ChatGPT app, sign out of MediPrep, disconnect Google or a local Companion, remove course connections and local sources, clear extension or Anki data, and request account deletion through support. Disconnecting stops new MediPrep access but does not itself delete an existing ChatGPT conversation, a third-party account, or an already-created calendar event; those must be deleted with the provider that holds them. Expired relay rows may remain until the next scheduled cleanup but cannot be used after expiry.
Third-party providers and sharing
OpenAI operates ChatGPT and may retain the upload, conversation, tool request, and tool response under the learner's selected account, workspace, plan, settings, and OpenAI terms. MediPrep does not control that provider retention and does not call the ChatGPT transcript device-local. Google processes an explicitly confirmed Calendar action. Vercel hosts the public app and MCP endpoint, and Supabase provides authentication and account-scoped service storage. Like other web infrastructure, those processors may receive normal network and request metadata such as an IP address, user agent, or authorization header to deliver and secure the request under their agreements. MediPrep's app tables do not copy raw IP addresses or bearer tokens into study or rate-limit records.
Canvas, UWorld, Boards & Beyond, Anki, AnKing, Chrome, Google, OpenAI, ChatGPT, and Codex are third-party products or marks. Their access, availability, subscriptions, content, privacy practices, and terms are controlled by their owners. MediPrep is independent of those providers and does not share learner data with data brokers, advertising networks, institutional dashboards, researchers, or model-training datasets.
Chrome permissions and local Companion
- Side panel shows the Navigator next to the learner's current study page.
- Active tab, tabs, and scripting identify and connect only supported MediPrep, Canvas, and UWorld pages for a learner-started action.
- Storage keeps account-scoped settings, local course records, permissions, and bounded action receipts on the device.
- Native messaging connects to the separately installed and notarized MediPrep local macOS bridge.
- Site access is limited to MediPrep production origins, Canvas
instructure.comcourses, UWorld, local AnkiConnect, and MediPrep's authentication service.
Security, education use, and policy changes
MediPrep uses allowlisted origins, strict account boundaries, least-privilege local transports, bounded schemas, short-lived capabilities, and fail-closed validation. No security measure eliminates every risk; learners should keep ChatGPT, Chrome, Anki, Study Navigator, and the local bridge current and should never send credentials, question bodies, patient information, or other unnecessary private content in a support request.
Study Navigator is intended for adult and higher-education learners and is not directed to children under 13. Public direct-to-learner use is not a FERPA certification. A school-directed deployment or institution- controlled education-record flow requires the institution's separate authority, access, retention, and privacy review. Material policy changes will update the effective date and the relevant listing or in-product notice.