Privacy Policy
Last updated: July 13, 2026
This policy explains what data SRMED collects when you use our website (srmed.ai) or our mobile app, why we collect it, and what your rights are.
The short version: You don't need an account to use SRMED, and we don't know who you are. We collect anonymous usage statistics, error reports, and — on the website only — masked session replays so we can improve the product, and nothing else. We show no ads, we sell no data, we do not track you across other apps or websites, and your IP address is never stored with your analytics data. Analytics data is stored in the European Union.
1. Who we are
SRMED is a news service operated by Mohammed Alnamkani ("SRMED", "we"), the data controller. For anything related to your privacy, contact support@srmed.ai.
2. What we collect and why
We collect the minimum needed to understand whether the product works and to fix it when it breaks. None of it is tied to your identity.
| Data | Why |
|---|---|
| Anonymous usage events — screens you view, articles you open and how far you read, episodes you play and how far you listen, shares, reactions | Understand which content and features are useful, improve the product |
| Error and diagnostic reports — error messages, diagnostic logs, browser or device type, operating system, app version | Detect and fix crashes and bugs |
| Feedback you choose to send — free-text answers to in-product surveys | Read and act on your feedback |
| Push notification token — a device token issued by Apple or Google (only if you enable notifications, once the feature is available) | Deliver the notifications you asked for |
| Server and network logs — IP address and user agent in short-lived infrastructure logs | Keep the service secure and operational |
We process all of this under our legitimate interest in operating and improving SRMED, except feedback and push notifications, which happen only with your consent. Usage events and error reports are recorded against a randomly generated identifier created on your device — it cannot be connected to your name, email, or any real-world identity.
3. What we do NOT do
- No accounts. You cannot register, log in, or be profiled as a person.
- No advertising. We show no ads and embed no advertising SDKs.
- No sale of data. We do not sell, rent, or trade any data, to anyone.
- No cross-app or cross-site tracking. We never access advertising identifiers (such as Apple's IDFA). Under Apple's App Tracking Transparency definition, SRMED does not track you.
- No identity linking. We do not use our analytics system to identify individual users or link usage events to any personal identity.
- No stored IP addresses in analytics. Your IP address is discarded at ingestion — it is not stored with your events.
- No location collection. We never access your device's location. Our analytics derives an approximate location (country and city) from your IP address before the address is discarded.
4. In the mobile app
- No cookies. The random anonymous identifier is stored locally on your device.
- No session recording, ever. The app never records your screen, gestures, or interactions.
- You are in control. Turn off "Share analytics" in the app's Settings and nothing is sent from that moment — the local identifier is reset. Deleting the app removes it entirely. Opting out does not degrade the app in any way.
5. On the website
- One first-party cookie. It holds the random anonymous identifier, so we can tell returning visits apart from new ones. No third-party or advertising cookies. Local storage holds functional preferences (language, theme), and our infrastructure provider may set strictly necessary security cookies.
- Session replay. To diagnose problems, we record how the site's pages are used (clicks, scrolling, what was on screen) under the same random identifier; anything you type is masked before it leaves your browser, and recordings are deleted after at most 90 days.
- You are in control. Delete or block cookies for srmed.ai at any time; the site works fine without them.
6. Who processes data for us
We rely on a small number of service providers ("processors") for tasks we cannot do ourselves. They handle data only on our instructions, under data processing agreements:
| Provider | What they receive |
|---|---|
| An analytics and error-tracking service | Anonymous usage events, error reports, survey responses — stored in the European Union |
| A content-delivery and security network | Request metadata (IP address, user agent) in short-lived logs, as part of serving the website |
| A cloud hosting provider | Request metadata in operational logs, as part of running our backend |
| Apple (APNs) and Google (FCM), via a push-delivery service (only once push notifications ship, and only if you enable them) | Your push token and notification content |
If you want to know exactly which providers we use, email us and we will tell you. We may also disclose data if required by law; given that our data is anonymous, there is very little to disclose.
Links to other websites: SRMED articles link to their original news sources. Once you leave srmed.ai, that website's own privacy policy applies.
7. Where your data lives
Analytics and error data is stored in the European Union. The website is delivered through a global edge network and our backend runs in the United States; transfers outside the EU/EEA are covered by an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses.
8. How long we keep data
| Data | Retention |
|---|---|
| Anonymous usage events, error reports, and survey feedback | Up to 7 years (our analytics provider's plan maximum), or until you request deletion |
| Session replays (website only) | Up to 90 days |
| Diagnostic logs | 14 days |
| Infrastructure request logs | Days to a few weeks |
| Push tokens | For as long as you keep notifications enabled |
9. Your rights
You have the right to access, correct, delete, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. You can also lodge a complaint with your local data protection authority.
Because our data is anonymous, we cannot tell which events are yours. To have your analytics data deleted, send us the random identifier from your device (in the app: Settings → Privacy; on the web: the value of our analytics cookie) and we will delete everything recorded against it.
10. Children
SRMED is not directed at children under 13, and since we collect no identity data, we cannot knowingly collect anything about a child; if you believe a child's data has reached us, contact us and we will delete it.
11. Changes to this policy
Changes are posted on this page with an updated date above; material changes are announced in the app and on the website before they take effect.
