Privacy Policy
How AnesCORE collects, uses and protects your data.
Last updated: 31 May 2026
AnesCORE ("we", "us") is operated by Lazart Studios SRL (Cluj-Napoca, Romania). This page explains what we collect, why, and the rights you have under EU GDPR (Regulation 2016/679) and Romanian Law 190/2018.
1. Data controller
The data controller is Lazart Studios SRL, with registered office at Str. Porțelanului 2, Sc. A, Et. 2, Ap. 14, 400058 Cluj-Napoca, Cluj County, Romania, registered with the Trade Registry under No. J2023002472129, Sole Registration Code (CUI) 48281539. For any privacy question or to exercise your rights, write to contact@anescore.com.
2. What we collect
Account data (name, email, password hash, hospital, city, country, target paper, target exam date, profile picture). Activity data (lessons viewed, questions answered, flashcard reviews, mock attempts, timestamps). AI Assistant data: when you use the assistant, the questions you ask and the answers it returns are stored so we can monitor quality and improve our lessons. Technical data (IP address, browser, device type, basic page analytics). Payment and invoicing data is processed by Stripe (card payments) and Oblio (e-invoicing); we never store your card details.
3. Why we process it
To provide the platform (legitimate interest / contract): authentication, progress tracking, content delivery, readiness score. To improve content (legitimate interest): aggregated, anonymised question performance data informs which lessons need rewriting. To bill you (contract): subscription management via Stripe. To communicate (legitimate interest): transactional email — invitations, password resets, account notices. We do not run ad networks and do not profile users for marketing.
4. Legal bases (GDPR Art. 6)
Performance of contract for account, billing and content delivery. Legitimate interest for security, analytics and product improvement. Consent for non-essential cookies and marketing communications, which you may withdraw at any time via the cookie banner or your settings.
5. Marketing communications
Separately from transactional email, we send optional engagement messages — newsletters, platform news and updates, and study reminders (including inactivity nudges). These are sent only if you opt in, either by ticking the marketing box at registration or by enabling the toggle in Settings. The legal basis is your consent (GDPR Art. 6(1)(a)). You can withdraw consent at any time, with no effect on your account: turn the toggle off in Settings, or use the one-click unsubscribe link included in every such email. Withdrawing consent stops marketing and reminder emails; we still send transactional email (sign-in and confirmation links, password resets, invoices, invitations) because it is necessary to operate your account.
6. Sharing
We use Supabase (database, auth, storage), Resend (transactional email), Stripe (payments) and Oblio (e-invoicing) as data processors under DPAs. We do not sell or rent your data to anyone. We disclose data only when required by law or to protect users from imminent harm.
7. Retention
Account data is retained while your account is active and for 24 months after you delete it (to handle disputes and legal obligations). Activity data is anonymised after account deletion. Backups roll off within 30 days.
8. International transfers
Our infrastructure is hosted within the EU (Supabase eu-north-1). Email and payment processors may transfer data to the United States under GDPR-approved Standard Contractual Clauses.
9. Your rights
You may access, correct, export, restrict or delete your data, or object to processing. Email contact@anescore.com — we respond within 30 days. You also have the right to lodge a complaint with ANSPDCP (Romania's data protection authority) at www.dataprotection.ro.
10. Children
AnesCORE is intended for medical professionals and adult learners. We do not knowingly collect data from anyone under 18.
11. Changes
We will post any material change here and notify active users by email. Continued use after a change means you accept the updated policy.