Privacy
Last updated 2026-08-20 · Verelect, info@verelect.com
What Verelect is
Verelect is a study tool for UK medical students. You upload lecture slides; it produces structured notes and an Anki deck, checks the clinical numbers in them against current UK guidance, and can publish the notes to your Notion.
What we collect, and why
- Account: your university email address, your password stored only as a one-way bcrypt hash (never the password itself), your institution, and whether your email is verified. Used to run your account and choose the guideline stack for your institution.
- Uploaded lecture files: read once for their text and speaker notes and deleted the moment that reading is complete — before any checking starts, whether the run then succeeds or fails. No slide image is ever copied out of the file. What remains afterwards is Verelect's own generated study material: a note and cards written from understanding, with diagrams we draw ourselves. We hold no copy of your slides.
- Generated outputs: your notes, cards, deck and guideline findings are stored so you can download them again. They belong to your account.
- Lecture signature: a one-way signature of the lecture's text (not the slides, and not reversible into them) is kept with the generated outputs so an identical lecture is not reprocessed. It is not linked to any user.
- Entitlement ledger: an append-only record of your free lecture, each run, and any refund, with a reason — this is how billing questions get answered.
- Payment: handled entirely by Stripe. Verelect never receives, stores or handles card numbers. We keep your Stripe customer and subscription identifiers and the subscription status.
- Notion: if you connect Notion, we store the OAuth access token encrypted at rest, the workspace name, and the page you chose. You can disconnect at any time; that revokes the token at Notion and deletes it here.
- Processing logs: per-run logs of which step ran and what the guideline check found. No card data, no passwords.
Who sees your data
- Anthropic (the AI provider) receives the lecture's text during the checking step, with web search enabled so guidelines can be checked. It does not receive your name or email.
- Stripe handles payment. Notion receives the notes you choose to publish. Our email provider receives the address and content of verification and reset emails.
- We do not sell data and do not use it for advertising.
Cookies
One session cookie (httpOnly, SameSite) keeps you logged in. One local preference remembers light or dark theme. No tracking cookies.
Deleting your account
Settings → Delete account removes: your user record (email, password hash, institution, Stripe identifiers), all sessions, the Notion token (revoked first), your run directories and the job records that point at them, and anonymises your ledger rows so they can no longer be linked to you. Stored lecture outputs and lecture signatures are not linked to any user and remain so that identical lectures need not be reprocessed.
Retention summary
- Uploaded lecture files: deleted the moment they have been read — in every case, including failures. Only derived text used to retry a failed run is kept, and that for at most 24 hours.
- Generated notes and decks: until you delete them or your account.
- Lecture signatures and stored outputs: kept; re-verified against guidance after 90 days or at the academic-year boundary.
- Notion token: until you disconnect or delete your account.
Your rights
You can download everything we hold for you (notes, decks, findings are downloadable from the app), choose your health board where your school has more than one, change your password, disconnect Notion, and delete your account — all from Settings. For anything else, email info@verelect.com.