Welcome to MedLabSolve — an MCQ practice platform built for medical laboratory science students and professionals under the NIMELSSA-LCU association. This Privacy Policy explains clearly and honestly what data we collect, how we use it, and the rights you have over it. We believe in transparency — no jargon, no fine print traps.
Who We Are
MedLabSolve is operated by NIMELSSA-LCU (Nigerian Medical Laboratory Science Students Association — Lead City University Chapter). We are the data controller responsible for the personal information collected through this platform.
Our platform is hosted on GitHub Pages and uses third-party backend services (including Google Firebase) to power authentication, data storage, and real-time features.
Data We Collect
We only collect data that is necessary to provide and improve the MedLabSolve experience. This includes:
- Display name / username
- Email address
- Password (encrypted)
- Chosen avatar / profile photo
- Quiz scores & attempts
- Daily streak data
- Difficulty & mode preferences
- Invite code & referral links
- Leaderboard ranking
- Device & browser type
- IP address (approximate)
- Time & frequency of app usage
How We Use Your Data
Your data is used strictly for the following purposes:
- Account creation & login
- Tracking quiz performance
- Displaying leaderboard rankings
- Maintaining daily streaks
- Sending in-app notifications
- Enabling challenge & invite features
- Improving quiz content quality
- Admin moderation & support
Data Sharing & Third Parties
We use trusted third-party services to power MedLabSolve. These services may process certain data on our behalf:
| Service | Purpose | Data Shared |
|---|---|---|
| Google Firebase | Authentication, database, storage | Email, name, scores, avatar |
| GitHub Pages | Website hosting | IP address (access logs) |
| Google Fonts | Typography rendering | IP address (CDN request) |
We do not share your personal data with any other external parties, government bodies, or commercial entities unless required by Nigerian law.
Data Storage & Security
Your data is stored securely on Google Firebase servers. We implement the following safeguards:
- HTTPS encryption in transit
- Firebase Auth for password hashing
- Firestore security rules
- Role-based admin access controls
- Regular security reviews
Cookies & Local Storage
MedLabSolve uses browser localStorage and session cookies to maintain your login state, save preferences (such as avatar choice, quiz mode, and "Remember Me" setting), and preserve your streak data between sessions.
We do not use advertising cookies, third-party trackers, or analytics pixels. Firebase may set its own functional cookies as part of its authentication service.
Your Rights (NDPR & NDPA 2023)
Under Nigeria's data protection laws, you have the following rights regarding your personal data:
| Right | What It Means | How to Exercise |
|---|---|---|
| Access | Request a copy of your data | Contact us via email |
| Correction | Fix inaccurate information | Settings page or email |
| Deletion | Request account & data removal | "Wipe My Progress" or email |
| Restriction | Limit how your data is used | Contact us via email |
| Portability | Receive your data in a usable format | Contact us via email |
| Objection | Object to certain uses of your data | Contact us via email |
We will respond to all verified requests within 30 days in accordance with the NDPA 2023.
Data Retention
We retain your personal data for as long as your account is active. If you delete your account or use the "Wipe My Progress" feature, your data will be permanently removed from our database within 14 days.
Anonymized, aggregated quiz performance data (with no personally identifiable information) may be retained indefinitely to help improve question quality and platform performance.
Children & Minors
MedLabSolve is designed for medical laboratory science students, most of whom are university-level adults. We do not knowingly collect data from children under the age of 13.
If you believe a minor has created an account without parental consent, please contact us immediately and we will delete the account promptly.
Contact & Data Requests
For any questions, concerns, or formal data requests related to this Privacy Policy, please contact our Data Privacy team. We are committed to responding to all verified enquiries within 30 business days in accordance with the Nigeria Data Protection Act 2023.