What the library records, why, and what you can ask us to do about it.
Last updated: 7 October 2026
This policy covers the GlobalCastMD medical education library at library.globalcastmd.com: the public pages, the search and answers features, the Spaces that host content, and the accounts used to sign in. It does not cover the separate StayCurrentMD platform and applications, which have their own terms.
The library is a professional education resource. It is not a place to submit patient information, and you should not enter patient-identifiable details into search boxes, comments or any other field.
You do not need an account to read most of the library. When you browse we record, against a random session identifier rather than your name:
That session identifier is not linked to you personally unless you sign in. We do not build advertising profiles and we do not sell this data.
Accounts hold your email address, your display name, and your role, plus any sign-in provider you have linked (see Signing in with Google, Microsoft or Apple). Signing in with an email code stores that code only as a hash, with an expiry and an attempt counter, and clears it once used. Where an account has a phone number for verification, it is handled the same way. Once you are signed in, the activity above is associated with your account rather than with an anonymous session.
Content you publish — recordings, documents, images, collections, the text that describes them and your name as the author — is intended to be seen. Items in a public Space are visible to anyone; items marked for healthcare professionals or kept private to a Space are restricted accordingly.
Our content delivery network and web servers keep ordinary access logs, which include IP addresses, for security, abuse prevention and troubleshooting. Within the library's own analytics we do not store raw IP addresses: an address is used transiently to apply rate limits, and where a record of origin is genuinely needed it is stored as a hash rather than the address itself.
We use a small number of cookies: one to keep you signed in, one to remember collections you follow so the list survives a reload, and an administrator-only cookie that previews a design change. We do not use cookies to track you across other websites.
The library uses Google Analytics to understand which material is useful and where people get stuck. Email is delivered through Amazon Web Services. The library runs on Amazon Web Services infrastructure in the United States, which is where content and account records are stored.
We do not sell personal information, and we do not use your activity to target advertising.
Credentials and keys are held in a managed secrets store rather than in code or configuration files. Traffic is encrypted in transit. Access to production systems is restricted and audited. No system is perfectly secure, and we do not claim otherwise.
You can ask us to show you what we hold about you, correct it, delete your account, or stop sending you email. A newsletter can be stopped by replying to it or by writing to the address below. Published content that other people rely on may be retained or attributed differently rather than erased outright; we will tell you which applies to your request.
You can sign in with an email one-time code, or with a Google, Microsoft or Apple account. Using a provider is optional — the email route always works.
We ask for the smallest set that identifies you:
| Provider | Scopes requested | What we receive and keep |
|---|---|---|
openid email profile |
Your Google account identifier, email address, whether Google has verified that email, and your display name. | |
| Microsoft | openid email profile User.Read |
Your Microsoft object identifier, email address and display name. |
| Apple | name email |
Your Apple identifier and email address — including a Hide My Email relay address if you use one — and your name, which Apple sends only on the first sign-in. |
We do not take your profile photo, contacts, calendar, files or anything else from these accounts, and we never receive your password. We store the identifier, the email, whether it was verified, your display name, and the issuer and subject of the sign-in token — nothing further from the provider's response.
If you sign in with Google using an email address that Google has verified and that already has an account here, we attach the Google sign-in to that existing account rather than creating a second one. Verified ownership of the address is what makes that safe.
Microsoft and Apple are never matched by email address. Microsoft is matched only on its own account identifier; Apple only on its identifier, because a Hide My Email relay is not proof of who owns an address. With those two you may end up with a separate account if you previously signed in another way.
We keep a record of sign-in attempts — the time, which method was used, whether it succeeded, and enough to detect someone attacking an account. The IP address and browser string in that record are stored as hashes, not in readable form. Password reset links are stored only as a hash and expire.
Where you ask for clinician access, we may ask you to match yourself to the public CMS National Provider Identifier registry, and we store the NPI number, the name and the specialty it returns. That registry is public information, and matching is how we confirm professional access to restricted material.
You can remove a provider from your account and continue with the email route, or ask us to delete the account entirely — which deletes the linked sign-in identities with it. You can also revoke our access from the provider's own settings: Google, Microsoft, Apple. Revoking there stops future sign-ins; write to us to have what we already hold deleted.
Parts of the library connect to Google services. This section describes that access in the terms Google's API Services User Data Policy requires, including its Limited Use requirements.
There are two, and they are worth keeping apart.
Signing in. You may create an account or sign in with
Google. That uses the basic openid email profile
scopes and is described under
Signing in with Google, Microsoft or Apple below.
It gives us your email address and name, and nothing else from your Google
account.
Running the library. The scopes in the table below are a different thing entirely. They are authorised by a GlobalCastMD administrator against GlobalCastMD's own Google accounts — our YouTube channel, our analytics properties, our Drive folders — so the library can publish and report on our own material. They are never requested from a visitor, and signing in with Google does not grant any of them.
| Scope requested | What it is used for |
|---|---|
youtube.upload |
Publish a recording from the admin uploader to the GlobalCastMD YouTube channel. |
youtube |
Place an uploaded recording into the right playlist and read back its status. |
youtube.readonly |
Read view and subscriber figures for our own channel, for internal reporting. |
yt-analytics.readonly |
Read YouTube Analytics for our own channel, for the same reporting. |
webmasters.readonly |
Read Google Search Console data for library.globalcastmd.com, to see which pages are indexed and found. |
analytics.readonly |
Read Google Analytics figures for this website, to see which material is used. |
drive |
Read files an administrator places in designated GlobalCastMD Drive folders — exported reports we ingest — and write our own generated reports back to those folders. |
OAuth tokens are held in AWS Secrets Manager or in restricted storage on our servers, never in our source code. Traffic to Google is encrypted in transit. Access to the systems holding these tokens is limited to administrators and is audited. Data retrieved from these APIs — view counts, search impressions, report files — is stored in our own database and object storage under the same controls as the rest of the library.
We do not share, transfer or disclose Google user data to third parties. It is used only inside GlobalCastMD, to run and report on the library. The one exception is where we are required to by law, or must act to investigate a security incident or prevent abuse.
An OAuth token stays only while the connection is in use. Revoking the connection — in the admin panel, or from the Google account's own third-party access settings — invalidates the token, and we delete our stored copy. Figures already retrieved for reporting are kept for as long as the reporting needs them and are removed when it does not. To have Google data we hold deleted sooner, write to the address below and we will remove it.
GlobalCastMD's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
We keep information for as long as it is needed for the purpose it was collected for, and then remove it. Account records last as long as the account does. Sign-in codes are discarded as soon as they are used or expire. Published content stays in the library until it is withdrawn. Usage records are kept in the aggregate form that tells us which material is useful, and are not retained in a form that identifies an individual reader longer than is needed for that purpose.
The library runs on Amazon Web Services infrastructure in the United States, which is where content, account records and backups are stored. If you use the library from outside the United States, your information is processed there.
The library is intended for healthcare professionals and other adults. It is not directed at children, and we do not knowingly collect information from them.
Email: info@globalcastmd.com
Web: Contact page
When this policy changes we will update the date at the top. If a change materially affects what we do with your information, we will say so rather than rely on the date alone.