MedCross Privacy Policy
Last updated: July 11, 2026 · Effective: June 26, 2026
Plain-English summary. MedCross is designed to be privacy-friendly. We do not operate a backend server — your game progress, coins, friends list, library, and email-account credentials all stay on your device. We display ads through Google AdMob, offer optional sign-in via Apple or with an email + password (device-local), and process in-app purchases through Apple. We do not sell personal information. The sections below explain each data flow and your rights in detail.
1. Who we are
MedCross ("MedCross", "we", "us", or "our") is operated by Yoav Toren, an individual developer, acting as the data controller for the personal information described in this policy.
Contact: yoavtoren@gmail.com
This policy applies to the MedCross mobile application available through the Apple App Store. It does not apply to third-party websites or services we link to.
2. Information we collect
2.1 Information stored only on your device
The following information is generated by your use of MedCross and stored locally on your device using iOS application storage. We do not transmit, copy, or synchronize this information to any server we operate.
- Game progress, completed levels, and unlocked medical terms
- Coin balance and a local record of in-app purchases
- Daily login streak counter and notification preferences
- Friends list, friend nicknames you choose, 6-digit player codes you have added, and your blocklist
- Achievements, XP, and gameplay statistics
- Promo code redemption history
- Onboarding completion state and your App Tracking Transparency response
- Profile display name, avatar selection, and nationality flag (if you choose to set one)
2.2 Sign-in options
MedCross offers three ways to use the app:
- Sign In with Apple. Authentication is handled entirely by Apple. Depending on the selections you make in Apple's prompt, Apple may share with us your Apple user identifier and, optionally, your name and email address. Anything Apple shares with us is stored only on your device.
- Email and password (device-local). You may create an email-based account. The email address and a cryptographically-hashed form of your password (PBKDF2-SHA256 with a unique salt and 10 000 iterations) are stored only on your device. The plaintext password is never stored, never transmitted, and never leaves your device. Because we do not operate a backend, an email account created on one device cannot be used to sign in on a different device, and we cannot reset a forgotten password — if you want cross-device access, use Sign In with Apple.
- Continue as Guest. No identifying information is associated with your data; a random local identifier is generated.
2.3 Information processed by advertising and purchase partners
When you view ads or make purchases inside the app, our third-party providers (Google AdMob and Apple) may collect information directly from your device under their own privacy policies. See Section 4 for details on what each provider collects.
2.4 Diagnostic information
If the app crashes, the iOS operating system may collect crash diagnostics that Apple makes available to us in aggregated, non-identifying form via App Store Connect. We do not use any third-party crash-reporting or analytics SDK. No personal information is included in the crash diagnostics we receive from Apple.
3. How we use information
We use the limited information described above only for the following purposes:
- Operating the app: tracking your game progress, coins, achievements, library, and preferences so that the app functions correctly.
- Authentication: recognizing you when you reopen the app (Sign In with Apple) so your data on the device is associated with the correct account.
- Notifications: scheduling local daily reminder notifications on your device if you opt in.
- In-app purchases: recording, restoring, and validating purchases you make through Apple.
- Advertising: displaying banner, interstitial, and rewarded ads through Google AdMob, which helps keep MedCross free. You control whether AdMob uses your device identifier for personalized ads through the iOS App Tracking Transparency prompt.
- Safety and abuse prevention: enforcing your local blocklist for the Friends feature and responding to user reports.
- Legal compliance: meeting our obligations under applicable law and responding to lawful requests.
4. Third-party services
We use a small number of third-party services that may receive information directly from your device. We do not control their data practices once information reaches them — please consult their privacy policies for full details.
4.1 Apple App Store & StoreKit (in-app purchases)
In-app purchases (coin packs, World Pass, and any subscription products) are processed by Apple via StoreKit. Apple handles all payment information — we do not see or store your payment details. We receive only a transaction receipt confirming the purchase. See Apple's Privacy Policy.
4.2 Sign In with Apple
If you choose to sign in with Apple, Apple handles authentication and may share your name and email with us based on the choices you make in Apple's prompt. See Apple's Privacy Policy.
4.3 Google AdMob (advertising)
We display banner, interstitial, and rewarded ads through Google AdMob (a service operated by Google LLC). AdMob may collect and process the following information directly from your device:
- Device identifiers, including the iOS Advertising Identifier (IDFA) where you have granted permission
- Approximate location inferred from your IP address
- Device characteristics (model, operating system version, language, time zone)
- Ad interaction data (impressions, clicks, view duration)
If you grant permission through the iOS App Tracking Transparency prompt, AdMob may use these identifiers to deliver personalized ads. If you deny permission, AdMob will deliver non-personalized ads. See Google's Privacy Policy and how Google uses information from partner apps.
4.4 Notifee (local notifications)
We use the Notifee library to schedule daily reminder notifications. These notifications are scheduled and delivered locally on your device. No notification tokens or device identifiers are transmitted to any server, and we do not use remote push notifications.
5. Legal basis for processing (EEA / UK)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information under the following legal bases as set out in Article 6 of the GDPR (and equivalent provisions of the UK GDPR):
- Performance of a contract (Art. 6(1)(b)): processing necessary to provide the MedCross app to you and to operate features such as game progress, authentication, and in-app purchases.
- Consent (Art. 6(1)(a)): processing that requires your explicit consent, including (i) sending you local reminder notifications, (ii) allowing AdMob to use your device identifier for personalized advertising through the App Tracking Transparency prompt, and (iii) confirming you are at least 13 years of age.
- Legitimate interests (Art. 6(1)(f)): displaying non-personalized advertising to support the free app, preventing abuse of the Friends feature through blocklists, and responding to user reports. Where we rely on legitimate interests, we have balanced them against your fundamental rights.
- Legal obligation (Art. 6(1)(c)): meeting our legal obligations, including responding to lawful requests by public authorities.
You may withdraw any consent at any time without affecting the lawfulness of processing already carried out. To withdraw consent to personalized ads, change your App Tracking Transparency setting in iOS Settings → Privacy & Security → Tracking. To withdraw consent to notifications, disable notifications in iOS Settings.
6. Your rights (GDPR / UK GDPR)
If you are in the EEA, UK, or Switzerland, you have the following rights regarding your personal information:
- Right of access (Art. 15): you may request a copy of the personal information we hold about you. Because we do not operate a backend, most information is held only on your device and you can access it directly in the app.
- Right to rectification (Art. 16): you may correct inaccurate information directly within the app, including your display name, avatar, nationality, and friend nicknames.
- Right to erasure / "right to be forgotten" (Art. 17): you may delete your account through the in-app "Delete Account" function in Profile → Settings. Deleting the app from your device also removes all locally-stored MedCross data.
- Right to restriction of processing (Art. 18): you may stop the app's processing of your data by signing out, denying tracking permission, or deleting the app.
- Right to data portability (Art. 20): because your data is stored on your device, you can back it up through iCloud or device backups under your own control. To request a copy in a portable format, contact us.
- Right to object (Art. 21): you may object to processing based on our legitimate interests at any time.
- Right not to be subject to automated decision-making (Art. 22): we do not use your personal information for automated decision-making with legal or similarly significant effects.
- Right to lodge a complaint: you may file a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu. In the UK, contact the Information Commissioner's Office at ico.org.uk.
To exercise any of these rights, email us at yoavtoren@gmail.com. We will respond within 30 days as required by the GDPR.
7. California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), gives you specific rights regarding your personal information.
7.1 Categories of personal information collected
In the 12 months prior to the effective date of this policy, we (and our advertising partner Google AdMob) may have collected the following categories of personal information as defined by the CCPA:
- Identifiers — Apple user identifier (if you Sign In with Apple), device-level identifiers, IDFA (subject to your ATT response)
- Internet or other electronic network activity — in-app interaction data, ad impressions and clicks, app usage events
- Geolocation data — approximate location inferred from IP address by Google AdMob (we do not access precise location)
- Commercial information — record of in-app purchases
- Inferences — Google AdMob may draw advertising inferences from interaction data where you have granted ATT permission
7.2 Sources, purposes, and recipients
We collect this information directly from your device through your interaction with the app, and through the Google AdMob SDK embedded in the app. We use the information for the operational and advertising purposes described in Section 3. Recipients are the third-party service providers described in Section 4.
7.3 Do Not Sell or Share My Personal Information
We do not sell personal information in the traditional sense of the word. However, the use of Google AdMob for personalized advertising may be considered "sharing" personal information for "cross-context behavioral advertising" under the CCPA.
To opt out, deny the App Tracking Transparency prompt the first time MedCross asks, or change your selection at any time in iOS Settings → Privacy & Security → Tracking → MedCross. When ATT is denied, AdMob serves only non-personalized ads and does not access your IDFA.
7.4 Your California rights
- Right to know: request what personal information we have collected.
- Right to delete: request deletion of your personal information. You can do this directly in-app via Profile → Delete Account, or by emailing us.
- Right to correct: request correction of inaccurate information.
- Right to opt out of sale or sharing: see Section 7.3 above.
- Right to limit the use of sensitive personal information: we do not collect sensitive personal information as defined by the CCPA.
- Right to non-discrimination: we will not deny you service, charge you a different price, or provide you a different level of quality of service for exercising any of these rights.
To exercise any of these rights, email yoavtoren@gmail.com. We may verify your identity by asking you to confirm details only the account holder would know (such as your 6-digit MedCross profile code).
8. Other countries — global privacy rights
MedCross is distributed worldwide. Wherever you live, we extend the same baseline privacy rights to you: access, correction, deletion, objection, and withdrawal of consent. This includes, without limitation, rights under Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act 1988, Israel's Privacy Protection Law, Japan's APPI, South Korea's PIPA, and any other national, state, or provincial privacy law that applies to you.
Because virtually all MedCross data is stored only on your own device and never reaches any server we operate, you can exercise most of these rights instantly and directly: edit your profile in the app, deny or revoke ad tracking in iOS Settings, or erase everything via Profile → Settings → Delete Account (or by deleting the app). For anything else, email yoavtoren@gmail.com and we will respond within 30 days, or sooner where your local law requires. Where your local law grants you rights beyond those described elsewhere in this policy, those rights apply to you in addition to, not instead of, the rights above.
9. App Tracking Transparency
iOS requires apps to obtain your permission before tracking you across other companies' apps and websites. MedCross presents the App Tracking Transparency prompt the first time you complete onboarding. Your response is stored on your device by iOS.
- If you allow tracking: Google AdMob may access your IDFA and use it to deliver personalized ads.
- If you deny tracking: Google AdMob will not access your IDFA, and ads will be non-personalized.
You can change this choice at any time in iOS Settings → Privacy & Security → Tracking → MedCross.
10. Children's privacy & age requirement
MedCross is intended for users aged 13 and older. During onboarding, you are required to confirm you are at least 13 years of age before continuing.
We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has provided information through MedCross, please contact us at yoavtoren@gmail.com and we will promptly delete the information.
MedCross does not include in-app chat, direct messaging, or other features that allow children to communicate with strangers.
11. Data retention & deletion
Because your MedCross data is stored on your device:
- It remains on your device until you delete the app, sign out, delete your account in-app, or reset your data.
- iCloud or local device backups (if you have them enabled) may retain copies until those backups are deleted or expire.
- You may permanently delete your account at any time via Profile → Settings → Delete Account. This clears all locally-stored MedCross data and revokes the Sign In with Apple authorization for MedCross.
Third-party providers (Apple, Google) retain transaction records and advertising data under their own retention policies.
12. Data security
We take reasonable technical and organizational measures to protect your information against unauthorized access, disclosure, alteration, and destruction:
- All data we control is stored in iOS application storage, which is sandboxed by iOS so other apps cannot read it.
- The app does not transmit data over plaintext HTTP. All network communications use TLS / HTTPS (App Transport Security is enforced).
- We do not operate a backend server, which eliminates entire categories of server-side risk (database breach, credential stuffing against our infrastructure, etc.).
- We do not store plaintext passwords. For Sign In with Apple, authentication is delegated entirely to Apple. For email accounts, the password is hashed on-device using PBKDF2-SHA256 with a unique 128-bit salt and 10 000 iterations before storage; only the hash and salt are persisted.
- We do not collect, store, or transmit payment information — all payments are handled by Apple.
No security measure is perfect. If we become aware of a security incident affecting your personal information, we will notify you and the relevant authorities as required by applicable law (see Section 14).
13. International data transfers
We do not transfer your data internationally because we do not collect data on our own servers. However, our third-party providers may process your information in countries outside your country of residence:
- Apple processes Sign In with Apple and StoreKit transactions across its global infrastructure.
- Google AdMob processes advertising data in the United States and other countries.
These providers maintain appropriate data-transfer safeguards (such as Standard Contractual Clauses) for transfers from the EEA, UK, and Switzerland.
14. Data breach notification
If we become aware of an unauthorized acquisition or disclosure of personal information that we control, we will notify affected users and the relevant supervisory authorities without undue delay, and within 72 hours where required by the GDPR (Article 33).
15. Friends feature, reporting & blocking
The Friends feature allows you to add other MedCross players to your friends list using a 6-digit player code that you must obtain from the other person directly. There is no in-app contact discovery, no address-book access, no search by name or email, and no chat or messaging.
Friend additions, including any nickname you choose for a friend, are stored only on your device. The other person does not see the nickname you have chosen for them.
If you encounter a player who you believe is engaging in abusive behavior, you can long-press the friend card in the Friends list to access two options:
- Report this user: opens an email draft to yoavtoren@gmail.com pre-filled with the player's code so we can investigate.
- Block this user: removes the player from your friends list and prevents you from adding them again on this device.
We review reports promptly and may take action including warning the reported player, restricting features, or, if we add a backend in the future, removing them from matchmaking.
16. Information we do NOT collect
- We do not operate a cloud backend or store your data on our servers.
- We do not collect or transmit your real-world (precise) location.
- We do not access your contacts, photos, microphone, or camera.
- We do not include in-app chat, direct messaging, or other user-generated content broadcasting.
- We do not sell personal information for monetary consideration.
- We do not use first-party analytics or third-party analytics SDKs (no Firebase Analytics, Mixpanel, Amplitude, Segment, etc.).
- We do not use third-party crash reporting SDKs (no Sentry, Bugsnag, Crashlytics, etc.).
- We do not use social-network sign-in beyond Apple (no Facebook, Google, or Twitter Sign In).
17. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. For material changes, we will notify users through the app or by other reasonable means before the change takes effect. Continued use of MedCross after the effective date of a revised policy constitutes acceptance of the revised policy.
Questions about this policy, requests to exercise your rights, or other privacy concerns? Contact us at:
Email: yoavtoren@gmail.com
Operator: Yoav Toren
Subject line for privacy requests: "MedCross Privacy Request"
We will respond within 30 days of receiving a verifiable request, or as required by applicable law.