Privacy

Your email address, what you have bought, which devices you sign in from, and how far through each lesson you are. Nothing else, and no advertising, ever.

In effect from 28 September 2026.

Muhammed Aarham is registering as a sole proprietor in Hungary. The registration number, tax number and business address will appear here as soon as that is done, and before anything is sold. Until then, ask at hello@medwithaarham.com for anything you need in writing.

1.Who holds it

Muhammed Aarham, trading as Med with Aarham, decides what is collected here and is responsible for it. Write to him at hello@medwithaarham.com about anything on this page. He answers within 5 working days.

MYK Productions built the platform and can reach the data while fixing it, under a written agreement that forbids using it for anything else.

2.What is collected

Your email address
The account itself. There is no password, so the address is how you sign in and how you are told anything.
Your name
Shown on your dashboard and over the video you watch. You can change it, and it is guessed from your email address until you do.
Your university
Optional. Used to show you the right slide list. Leave it blank.
What you bought
The course, the amount, the currency, the payment reference and the date, kept because it is an accounting record.
The two boxes you ticked at checkout
Which consents you gave and the moment you gave them. Kept because they are what the refunds policy rests on, and a consent nobody recorded is a consent nobody can rely on, including you.
Your devices
A short number worked out from your browser and language settings, plus a readable label like "Chrome on Windows", plus when it was first and last seen. It enforces the 2 device limit.
Your progress
Where you got to in each lesson, whether you finished it, and how many minutes you studied on a given day. It is what makes resume work.
Your notes
Anything you type on the notes page, and which lesson it was against. Nobody else can read them, not even Aarham, and they are deleted with your account.
Sign in links
A one way hash of each link you use, so the same link cannot be used twice. The link itself is never stored.

The device number cannot be turned back into anything. It is a truncated one way hash: it tells the platform that this is the same browser as last time and nothing else about your machine.

3.What is not collected

  • No card numbers. Bank transfers go through your bank and card payments through the payment provider; neither hands the numbers to this platform.
  • No advertising, no tracking pixels, no analytics, no third party scripts.
  • No location, no contacts, no camera, no microphone.
  • No profile of you sold, shared or given to anyone for marketing.

4.Why it is allowed

Three reasons, and every item above is one of them.

  • To give you what you paid for. Your account, your enrolment, your progress. Without it there is no course to deliver.
  • Because the law requires it. Payment records are an accounting record and have to be kept.
  • To stop one payment becoming forty students. The device limit and the name over the video exist so a course made by one person is still worth making. That is a legitimate interest, and it is narrow: it watches devices, not people.

5.Who else sees it

Four companies, all serving from inside the EU. Your data does not leave the European Economic Area.

Cloudflare
Runs the website. Your IP address and the pages you request, briefly, to serve them.
Neon
Database, hosted in Frankfurt. Your account, your enrolments, your devices and your progress.
Bunny.net
Video delivery. Your IP address while a lesson plays, and which video was requested.
Resend
Sends the sign in email. Your email address and the message itself.

None of them may use any of it for their own purposes. Nothing is sold, and nothing is handed to anyone else unless a court orders it.

6.How long it is kept

Your account
Until you ask for it to be deleted, or two years after your last access period ends.
Progress, notes and devices
Deleted with the account.
Payment records
Eight years, which is what Hungary requires of anyone keeping accounts.
Used sign in links
Deleted once the link they refer to has expired.

7.What you can make him do

All of it by email, all free, all answered within 5 working days and in every case within a month.

  • Show you everything held about you, as a file.
  • Correct anything wrong.
  • Delete your account. Payment records survive it, because the law says they must.
  • Stop the device checks being applied to you, which in practice means closing the account, since the course cannot be delivered without them.
  • Take your data elsewhere in a machine readable form.

If he handles it badly you can complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), or to the supervisory authority in the EU country where you live.

8.Security, honestly stated

Sign in is by one time link, so there is no password to steal or reuse. The session cookie cannot be read by any script. Everything travels over HTTPS and the database sits behind credentials held only by the platform.

Nobody can promise a system is unbreakable, and a policy that does is lying. If something is breached and it puts you at risk, you will be told, and so will the regulator, within 72 hours of it being known.

9.Under 16

The courses are written for university students and the platform is not intended for anyone under 16. If you believe a child's data is here, say so and it will be removed.

10.Cookies

There is one, it keeps you signed in, and it does nothing else. The whole of it is on the cookie page, which is short because there is not much to say.

Anything here that is unclear, ask. hello@medwithaarham.com