DGExams
Terms of UsePrivacy Policy
Back to DGExams

Privacy Policy

Last updated · 8 September 2026
Contents
  1. 01Who is responsible
  2. 02What we hold
  3. 03Why we hold it
  4. 04Who else processes it, and where
  5. 05Transfers outside the Kingdom
  6. 06Reuse of generated results between users
  7. 07Share links
  8. 08Trying it without an account
  9. 09How long we keep it
  10. 10Your rights
  11. 11Changes

DGExams is a study tool for medical exam preparation. This policy explains what personal data it holds about you, who else processes it, where that processing happens, and how to get a copy of your data or have it deleted.

01Who is responsible

DGExams is the controller of the personal data described here.

02What we hold

  • Your account — username, your password (stored only as a one-way cryptographic digest — not encrypted, because encryption can be reversed and this cannot), and an email address if you chose to verify one.
  • Your question bank — the material you upload or paste, the questions extracted from it, your own notes, and the file names it came from.
  • Your study record — which questions you answered, your exam attempts, flags and tags.
  • A usage log — one row per AI request: which feature, which model, how many tokens, how long it took and what it cost. It records no question content.
  • Your settings — theme, display and exam preferences.
  • Your own AI provider key, if you add one. It is encrypted before storage and is never shown back to you or to anyone else.

We do not ask for and do not want health information about you or anyone else. The medical content in your bank is study material, not patient data — please do not upload documents containing real patients' details.

03Why we hold it

To provide the service you asked for: to store your bank so it follows you between devices, to turn uploaded material into questions, to generate explanations, and to let you sign in and recover your account.

04Who else processes it, and where

DGExams is not self-contained. To do what it does, it sends data to the following processors, all of which operate outside the Kingdom of Saudi Arabia:

  • Anthropic (United States) — the text and page images of material you upload, so questions and explanations can be generated from it. We ask Anthropic to run this processing on United States infrastructure specifically, rather than wherever happens to be fastest.
  • Datalab (United States) — every PDF you upload is sent there whole, as a file, to be read. It is our primary text extractor rather than a fallback for scanned documents, so this happens on every upload, not only when a page resists reading.
  • Resend (United States) — your email address, your username in some messages, and a verification code, when you register, reset a password or change your address.
  • Railway (United States) — hosting for the application and its database. This is where your account and your bank are stored at rest.
  • Cloudflare — serves a PDF-reading script to your browser. It receives your IP address and browser details, and none of your content.

05Transfers outside the Kingdom

Everything above means your personal data is transferred outside Saudi Arabia. We do this to provide the service to you — you cannot get questions out of a PDF without the file reaching the system that reads it. We send the minimum needed for each purpose. We do not sell your data and we do not use it for advertising.

06Reuse of generated results between users

This one is unusual enough to spell out. To avoid paying twice for identical work, DGExams keeps a shared cache of results generated from submitted material. It is NOT matched on whole files: a match is a passage of text, or a single question carrying the same wording, options and answer. So if anyone else — including someone using the free trial without an account — submits text or a question matching yours, they may be served the output already generated from it.

The cache holds derived output, not your account, and it is not linked to you. Because of that it is also the one store we cannot search by user — so it is not reached by an account deletion.

07Share links

If you create a share link, the questions you selected are copied into a snapshot that anyone signed in with the link can import. Your private notes and your flag history are stripped before the copy is made; a note captured from the source file travels with the question. Snapshots are fixed at the moment you create them — revoking a link stops new imports, but cannot reach a copy someone already took.

08Trying it without an account

The guest trial stores your work in your browser for that session only, and no guest CONTENT is written to our database. Two things are: a counter that limits free AI usage, held against a random id in a cookie that outlives the session so closing the browser does not refill the allowance, and a row in the usage log above. Neither carries an identifier for you.

09How long we keep it

Your account and bank are kept until you delete them. Unverified signups, password reset codes and email-change codes expire within hours and are removed. Sign-in sessions expire and are removed.

10Your rights

  • Get a copy — Settings → export downloads your entire bank as a file.
  • Correct it — your bank, your notes, your email address and your password are editable in the app. The username is fixed once chosen.
  • Delete it — Settings → Danger deletes your account, erasing your bank, its backups, your shares, jobs, settings and sessions. Two things stay: the usage log rows above, kept but unlinked from you, and the shared cache, which has no owner to search by.

The export, correction and deletion controls above are in the app itself, so you do not need to ask us to use them.

If you are not satisfied with how your personal data is handled, you may complain to the Saudi Data & Artificial Intelligence Authority (SDAIA).

11Changes

If this policy changes materially, we will say so here and update the date at the top before the change takes effect.

Also readTerms of Use