HBRMEDHBRMED Learnالعربية

Account privacy

This notice explains account sign-in and access to HBRMED Learn and HBRMED administration.

Account information

We store your Google account identifier (issuer and subject), current verified email address and display name to recognize your account. We also store access decisions, session records, sign-in times and security audit records. We do not access your Gmail inbox or profile photos, or store Google access, refresh or ID tokens.

Access decisions

The administrator manages Learn approval, rejection and suspension. When automatic approval is enabled, it applies to new Learn memberships only. Google sign-in does not grant administration rights.

Cookies and sign-in

Learn and administration use separate cookies limited to their own host, with Secure, HttpOnly and SameSite=Lax protections and no shared Domain attribute. Learn sessions end after 30 days at most, or 7 days without activity. Administration sessions end after 8 hours at most, or 30 minutes without activity. Temporary OAuth sign-in transactions and their browser-binding cookies expire after 10 minutes. Signing out revokes the current session on that host.

Storage and cleanup

Account, access and audit information is held in a dedicated SQLite database on the HBRMED VPS. Expired sessions and sign-in transactions cannot be used. Expiry does not itself delete their database records; removal requires operational cleanup. Account-data requests are handled by the owner. Anonymization removes profile fields and revokes access, while an account binding and opaque audit records may remain to preserve security decisions. Backups may retain earlier records; this notice does not promise immediate removal from every backup or a fixed deletion schedule.

Your requests

Use the HBRMED contact page to ask about your account information or request correction or removal. The owner reviews these requests. These account pages do not use advertising trackers or analytics.

Contact HBRMEDBack to sign in