LEGAL INFORMATION
MedStudent OS — Privacy Policy
Effective Date: 1 September 2026 • Last Updated: 6 September 2026
This Privacy Policy explains how MedStudent OS handles personal information when you use our website, start or manage a trial or subscription, verify your access, contact us for support, submit feedback, request a refund, or otherwise interact directly with the MedStudent OS business.
MedStudent OS is operated by Ryan Chan trading as MedStudent OS, a sole trader in England, United Kingdom. Business Address: [ADDRESS]. Contact Email: Ryan.medstudentos@gmail.com. For personal information collected directly in connection with operating MedStudent OS, Ryan Chan trading as MedStudent OS is the data controller under applicable UK data-protection law. MedStudent OS is an AI Life Coach + Personal Cheerleader for adult Medical Students and is delivered using third-party services including ChatGPT by OpenAI, Stripe, AuthFlow, Framer and Google.
This Privacy Policy applies when you visit medstudentos.co.uk; start or manage a MedStudent OS free trial or subscription; verify access; use the MedStudent OS website; contact us for troubleshooting or support; submit feedback; request a refund; communicate directly with Ryan Chan; or otherwise interact directly with the MedStudent OS business. Your use of ChatGPT itself is governed separately by OpenAI’s own terms, privacy practices and Data Controls.
A. Trial, Subscription and Customer Information
When you start or manage a MedStudent OS trial or subscription, Ryan Chan may be able to see information provided through Stripe and/or AuthFlow. This can include your name and email address; trial and subscription status; subscription start and renewal dates; whether a subscription is active, trialling, cancelled, ending or expired; payment success or failure; cancellation, refund, dispute or chargeback information; and associated customer and subscription metadata. Payments are processed through Stripe. MedStudent OS does not directly collect or store complete debit or credit card details. Stripe Privacy Policy: stripe.com/gb/privacy.
B. Access Verification Information
MedStudent OS uses AuthFlow to verify whether the email address you provide is associated with an eligible free trial or subscription. The checkout email may be sent through the MedStudent OS GPT Action to AuthFlow so access status can be checked. AuthFlow may return whether an account is in a free trial, actively subscribed, expired, not associated with a subscription, or otherwise eligible or ineligible. Ryan Chan may also have access to aggregated or account-level AuthFlow analytics including authentication attempts, unique users, outcomes and subscription status. AuthFlow Privacy Policy: authflow-ai.com/privacy.
Ryan Chan cannot view your individual MedStudent OS conversations simply because he created MedStudent OS.
MedStudent OS runs as a Custom GPT within ChatGPT. OpenAI states that GPT builders cannot view individual conversations that users have with their GPTs. Ryan does not receive a dashboard containing your Step 1 answers, Honest Thoughts discussion, Graduation Vision, personal goals, emotional conversations, ongoing Life Coaching discussions, or other private content you share with Uncle Ryan inside ChatGPT. Your ChatGPT conversation is processed by OpenAI under your ChatGPT account and OpenAI’s applicable privacy practices. For users in the United Kingdom and Europe, see the OpenAI Europe Privacy Policy at openai.com/policies/eu-privacy-policy/. Eligible consumer ChatGPT users can also use OpenAI Data Controls to manage whether new conversations help improve OpenAI’s models.
Although Ryan cannot view your private ChatGPT conversation as the GPT builder, MedStudent OS uses an external Action for access verification. When you provide the checkout email needed for AuthFlow verification, the relevant information required for that verification may be sent from ChatGPT to AuthFlow. OpenAI explains that when a GPT uses external APIs or apps, relevant parts of a user’s input may be sent to that external service. MedStudent OS uses this functionality specifically for subscription and access verification. Avoid entering unnecessary personal information when providing your access-verification email.
If you contact MedStudent OS through a troubleshooting form, feedback form or email, we may collect information you voluntarily provide, including your name, email address, subscription email, what went wrong, feedback, where you reached within MedStudent OS, device or browser details, screenshots, and any other information in your message. MedStudent OS intends to use Framer Native Forms for support and feedback submissions. Submissions are sent to Ryan.medstudentos@gmail.com and may also be processed through Google/Gmail. Framer Privacy Statement: framer.com/legal/privacy-statement. Google Privacy Policy: policies.google.com/privacy?hl=en-GB.
MedStudent OS does not need identifiable patient information to troubleshoot the product or provide feedback. Do not submit patient names, dates of birth, addresses, NHS or hospital numbers, patient contact details, identifiable photographs, passwords, complete payment-card details, security credentials, or unnecessary sensitive health or personal information. If submitting a screenshot, crop, blur or redact unnecessary private information first. Avoid copying an entire private coaching conversation into a support request unless a limited excerpt is specifically required.
The MedStudent OS website is hosted using Framer and currently uses Framer’s built-in website analytics. Framer states that its built-in analytics do not rely on cookies, do not create persistent identifiers, provide privacy-focused website metrics, and do not collect or store information that identifies an individual visitor for analytics purposes. MedStudent OS does not currently use Google Analytics, Meta Pixel or comparable third-party advertising trackers. If this changes, this Privacy Policy will be updated and any legally required consent mechanism will be introduced.
MedStudent OS may process personal information to start and administer trials; administer paid subscriptions; verify access; manage billing, cancellations and refunds; respond to support requests; review feedback; improve the product; detect misuse, fraud or subscription circumvention; manage complaints, disputes and chargebacks; and keep legally required business, accounting and tax records. The typical UK GDPR lawful bases are performance of a contract, legitimate interests, and legal obligations. Where legitimate interests are relied upon, they involve operating, securing, supporting and improving MedStudent OS in a proportionate way users would reasonably expect.
MedStudent OS relies on OpenAI / ChatGPT to host the Custom GPT and conversational experience; Stripe to process payments, trials, subscriptions, billing, cancellations and refunds; AuthFlow to verify access and subscription eligibility; Framer to host the website, provide analytics and handle native support and feedback forms; and Google / Gmail to receive and store support and feedback correspondence. Their official privacy policies are linked at the end of this document. MedStudent OS does not sell personal information to advertisers and does not currently operate an email-marketing newsletter or marketing mailing list. Transactional emails may still be sent by Stripe or another provider involved in administering a subscription.
Where users submit personal information through a Framer form created by MedStudent OS, Ryan Chan trading as MedStudent OS determines why that information is collected and how it is used. Framer explains that, where it processes a customer’s end-user personal data on the customer’s behalf, the customer acts as controller and Framer acts as processor. MedStudent OS intends to use Framer forms only for legitimate support and product-feedback purposes.
Support requests, troubleshooting submissions, feedback and related correspondence will normally be retained for up to 24 months from the relevant interaction, and may be deleted sooner where no longer required. Information may be retained longer for an ongoing complaint, fraud prevention, legal dispute, financial or accounting obligation, regulatory requirement or another legal obligation. Payment, transaction, refund, cancellation and accounting records may be retained as required to administer subscriptions, comply with tax and accounting obligations, resolve disputes, demonstrate transactions or comply with applicable law. Stripe, AuthFlow, Framer, OpenAI and Google may separately retain information under their own policies.
Some external providers used to operate MedStudent OS may process or store personal information outside the United Kingdom, including internationally operating providers such as OpenAI, Stripe, AuthFlow, Framer and Google. Where applicable, those providers are responsible for using legally recognised safeguards for international transfers according to their respective obligations and policies. Their current privacy practices are linked in Section 10 and at the end of this document.
Depending on circumstances and applicable UK data-protection law, you may have rights to request access, correction, deletion, restriction of processing, objection to processing, portability of certain information, withdrawal of consent where it applies, and to make a complaint. Not every right applies in every situation. To exercise a right relating to information controlled directly by MedStudent OS, contact Ryan.medstudentos@gmail.com. Where a request relates specifically to ChatGPT/OpenAI, Stripe, AuthFlow, Framer or Google as an independent controller, you may also need to contact that provider directly.
If you have concerns about how MedStudent OS handles personal information, contact Ryan.medstudentos@gmail.com so we have an opportunity to understand and resolve the issue. You also have the right to raise a concern with the United Kingdom’s data-protection regulator, the Information Commissioner’s Office (ICO).
MedStudent OS is intended for users aged 18 years or older. You should not start a MedStudent OS free trial, purchase a subscription or submit personal information to MedStudent OS if you are under 18.
MedStudent OS does not currently use customer email addresses for promotional email marketing. Your email may be used where reasonably necessary for subscription administration, authentication, billing, cancellation, refunds, support, troubleshooting, feedback, security or legally required communication. If optional email marketing is introduced in the future, any consent or opt-out mechanisms required by law will be introduced separately.
Submitting private feedback does not automatically give MedStudent OS permission to publish your name, photograph, personal story, private conversation, testimonial, screenshot or identifying information. If Ryan would like to use identifiable feedback publicly, separate permission will be requested. You are free to refuse.
MedStudent OS uses established third-party providers for payments, website hosting, authentication and email. Reasonable steps will be taken to protect personal information controlled directly by MedStudent OS. However, no online service or transmission method can guarantee absolute security. You are responsible for protecting your ChatGPT account, email account, payment accounts and passwords. Never send MedStudent OS passwords, authentication codes or complete payment-card information.
MedStudent OS is an evolving product. This Privacy Policy may be updated where the product changes, a new provider is introduced, existing providers change, new functionality is introduced, data practices change, or applicable legal requirements change. The latest version will be published on medstudentos.co.uk with its current Last Updated date. Material changes will be communicated where reasonably required.
For privacy enquiries or requests: Ryan Chan trading as MedStudent OS. Business Address: [ADDRESS]. England, United Kingdom. Email: Ryan.medstudentos@gmail.com.
Privacy Policies of Services Used by MedStudent OS