UPDATED 24 SEPTEMBER 2026
Android Privacy Policy
How your account, study activity, purchases and advertising information are handled. Acknowledgement is not consent to advertising.
Who is responsible
MediByte for Android is provided by SOLVAR YAZILIM VE BILISIM DANISMANLIK LIMITED SIRKETI, trading as SOLVAR YAZILIM VE DANIŞMANLIK. Address: B D:20, NO:4-1 ATATURK MAHALLESI, NERGIS 1 SOKAK, BUYUKCEKMECE, Istanbul (Europe) 34536, Türkiye. Contact admin@solvarcompany.com for privacy and account requests. This notice covers the Android app and the MediByte account-support website; other platforms may offer different features.
Account information
Email registration sends your email address, password and optional name directly to Google Firebase Authentication. The app does not save your password; it keeps sign-in tokens in encrypted Android storage protected by Android Keystore. Guest sign-in creates a Firebase anonymous account and a server identifier. It is not anonymous browsing. You can use device-only study features without creating an account. Account identifiers are also used to authenticate account-deletion requests and check any complimentary access explicitly granted by MediByte. Such access is verified with the server, can be revoked and does not create a paid subscription.
Study records on your device
Exam preferences, goals, calendar entries, lesson progress, practice answers, recall cards, bookmarks and simulated-case notes are stored on your Android device. Signing in does not upload or synchronize all those records. They remain separate from the cloud account and are shared by the app installation unless the feature explicitly identifies an account scope. Clearing the app's storage in Android Settings removes local records, credentials and caches. Signing out alone does not erase them. If you use the same cloud account on another MediByte platform, that platform may have associated cloud study data, such as calendar sessions.
Downloads and technical information
Lessons, recordings, artwork and question banks are downloaded from Google Firebase-hosted services. Requests disclose IP addresses and request metadata to the service provider. Downloaded media may be cached locally. Firebase Authentication, hosting and security services process technical information needed to operate, troubleshoot and protect those services. We do not include identifiable patient records in the provided fictional cases.
Google Play purchases and verification
Google Play processes Android subscriptions and payment-card details. MediByte receives purchase tokens, product and subscription status and sends purchase evidence to its verification service. The service checks and acknowledges purchases with Google Play. It stores token hashes, entitlement status and security records rather than raw purchase tokens or payment-card details. Firebase App Check and Google Play Integrity process app, device and integrity signals to prevent abuse. Entitlement checks are tied to the Google Play purchase; signing into MediByte does not automatically transfer an Apple subscription to Android. Subscription cancellation is managed separately in Google Play.
Advertising and privacy choices
Free access may include Google AdMob banners and optional rewarded ads. Google Mobile Ads and its consent service can collect and share IP addresses, approximate location inferred from IP, device or account identifiers, app/ad interactions, diagnostics and performance information for advertising, measurement and fraud prevention. This includes app-set identifiers and, where available under platform settings, advertising identifiers. MediByte does not send account email, learner notes, practice answers or patient information as ad targeting fields. Consent choices are presented where required. Use Advertising privacy choices in the app when available, and Android's advertising settings, to review applicable choices. Refusing optional personalized-ad consent does not purchase Plus. Verified Plus access suppresses new MediByte ad requests; it does not erase information already processed by providers.
Microphone and voluntary sharing
OSCE dictation uses optional on-device speech recognition on supported Android devices, after a disclosure and microphone permission. Audio is not saved as a recording or sent to a MediByte server by this feature. Recognition is cancelled when the feature is left; typed input remains available. The app does not silently fall back to cloud recognition when on-device recognition is unavailable. If you choose a system share action, the text you choose is passed to the destination app you select. Avoid putting patient identities, real clinical records or confidential information into any text field.
Why information is processed
Account information delivers the account services you request. Technical information provides content, security and troubleshooting. Purchase evidence determines paid access and prevents fraud. Advertising information supports free access, ad measurement and fraud prevention, subject to the choices and legal requirements that apply. Where data-protection law requires a legal basis, requested services rely on the applicable service/contract basis; necessary security relies on legitimate interests subject to your rights; legal obligations apply where actually required; optional processing requiring consent relies on a separate consent choice. Reading or acknowledging this notice is not consent to personalized advertising, marketing or every use of personal data.
Retention and security
Local records remain until you remove them, clear app storage or uninstall; operating-system and provider storage have their own lifecycles. Cloud account information remains while the account exists and is removed as part of account-deletion handling, subject to any necessary legal or security exception. Deletion requests retain account identity and processing details while being handled. After automated erasure is verified, the raw account identity is removed from the receipt; a hashed identifier, request reference, timestamps and limited completion evidence are scheduled for deletion after 90 days. Provider expiry processing can take additional time. Requests requiring individual review remain pending until they are handled. Purchase-token hashes and revocation/security records are retained as needed to verify entitlements, prevent reuse of revoked purchases and handle disputes; they are not a raw payment-card database. Any applicable retention exception is explained during request handling. Service-provider logs are governed by provider settings and terms. Data in transit uses HTTPS/TLS. Android account tokens are encrypted; server request and purchase ledgers are not publicly writable. These measures do not eliminate every security risk.
Request account and data deletion
Open Account → Account & data deletion in the app, or visit https://medibyte-account.web.app/delete-account/ without reinstalling. You can submit a request authenticated to your account, including a guest account while still signed in. If you cannot sign in, contact admin@solvarcompany.com. We verify ownership before handling deletion of the account and associated cloud profile/study data. The request receipt confirms intake, not completed erasure. For supported accounts, the service disables sign-in and revokes refresh sessions, waits at least 65 minutes for existing access tokens to expire, then removes mapped cloud records and the sign-in account. Accounts with older or unmapped shared data require individual review to avoid removing another person's information. Necessary retention exceptions will be explained. Deleting an account does not cancel a Google Play or Apple subscription. Device-only records are separate: clear MediByte's storage in Android Settings. Never send your password or payment-card details in a support message.
Your rights and contact
Depending on applicable law, you may request access, information about purposes and recipients, correction, erasure, restriction, portability or objection to processing, and withdraw consent for future consent-based processing. Withdrawal does not undo processing already lawfully performed. Under Türkiye's KVKK Article 11, rights include asking whether data is processed, obtaining processing information, requesting correction or erasure when legal conditions apply, requesting notification to recipients, objecting to adverse results from exclusively automated analysis, and seeking compensation for unlawful processing. You may contact the relevant supervisory authority, including the Turkish Personal Data Protection Authority or your local data-protection authority. Send requests to admin@solvarcompany.com; proportionate identity verification may be necessary. Statutory response periods and remedies apply.
Intended audience and updates
MediByte is intended for adult medical learners, not children. It is an educational product, not a patient record, diagnostic service or substitute for professional clinical judgment. Contact us if you believe a child has supplied personal information. Changes to data handling will be reflected in this notice; separate permission or consent will be requested where required.
Your notice acknowledgement
After a successful account operation, the app saves the notice version, acknowledgement time, language and platform with the local account session. This is a local acknowledgement receipt, not a central consent certificate. It does not turn on advertising, tracking or marketing. You can reopen this notice without changing your choices.
Useful links
Account deletion request · Contact privacy support · Google Privacy Policy · Firebase privacy information · Google partner-site data use