IOMMockby Nepsor
Mock testsPractice
  • Reading materialsTopic notes and formula sheets
  • SyllabusThe MECEE-BL blueprint, chapter by chapter
  • LeaderboardWho is putting in the most work this week
  • College predictorWhich seats a score has actually reached
  • MEC noticesExam dates, deadlines and counselling rounds
  • BlogCounselling guides and study advice
Pricing
Log inSign up free
IOMMock

Free & premium mock tests and study material for Nepal's MECEE-BL (IOM) MBBS/BDS entrance examination.

A product of Nepsor Technology — web, app and AI solutions from Kathmandu.

Prepare

  • Mock tests
  • Grand Mocks
  • Subject Practice
  • Chapter Tests
  • Custom Test Builder
  • Reading Materials
  • Exam Syllabus

Guidance

  • College Predictor
  • MEC Notices
  • Counselling Guide
  • Blog
  • Leaderboard

Account

  • Plans & pricing
  • Create account
  • Log in
  • Send feedback

Nepsor

  • Company website
  • IT Services
  • Careers
  • Contact Us
  • Privacy Policy
  • Terms of Service

MECEE-BL is conducted by the Medical Education Commission (MEC), Nepal. This is an independent preparation platform and is not affiliated with MEC or IOM.

© 2026 Nepsor Technology Pvt. Ltd.  |  All Rights Reserved

Model questions for practice only. Not affiliated with the Medical Education Commission or Institute of Medicine.

Legal

Privacy Policy

Last updated 9 September 2026 · Operated by Nepsor Technology Pvt. Ltd. · See also Terms of Service

This policy explains what personal data IOMMock collects, why, who we share it with, how long we keep it, and the choices you have. It is written to be read, not skimmed: if a feature collects something, it is listed here. Using the service means you have read it and agree to it, alongside our Terms of Service.

Contents

  1. 1.Who we are and what this covers
  2. 2.The personal data we collect
  3. 3.Cookies and browser storage
  4. 4.Sign in with Google
  5. 5.How and why we use your data
  6. 6.Who we share data with
  7. 7.Where your data is stored
  8. 8.How long we keep data
  9. 9.Your rights and choices
  10. 10.How we protect your data
  11. 11.Students under 18
  12. 12.Changes to this policy
  13. 13.Contact us

1. Who we are and what this covers

IOMMock is an online preparation platform for Nepal’s MECEE-BL (IOM) MBBS/BDS entrance examination. It is owned and operated by Nepsor Technology Pvt. Ltd., a company established in Kathmandu, Nepal (“we”, “us”, “our”). For the purposes of data protection law we are the data controller of the personal data described in this policy.

This policy applies to the IOMMock website and progressive web app, the emails and push notifications we send, and any support conversation you have with us. It does not cover third-party sites we link to, such as the Medical Education Commission (MEC), medical colleges, eSewa or Khalti, which have their own policies.

IOMMock is an independent study tool. We are not affiliated with, endorsed by, or acting on behalf of MEC or the Institute of Medicine (IOM), and we never receive personal data from them.

2. The personal data we collect

We only collect what a feature needs to work. In practice that is:

Account details

  • Name and email address, which you give us when you create an account, and an optional target admission year.
  • Password, if you choose one. It is stored only as a salted bcrypt hash. We cannot see it and never send it anywhere.
  • Google account identifier (the stable “sub” claim), your name and email, and whether Google has verified that email, if you use “Continue with Google”. See section 4 for exactly what Google gives us and what we do with it.
  • Whether your email has been verified, and the timestamps of when the account was created and last changed.

Study activity

  • Every mock test, practice session, daily quiz, chapter test, custom test and grand mock you start: which questions you saw, the answers you chose, how long each took, your score, rank and status.
  • Bookmarks, mistake-bank entries, flashcards and spaced-repetition review history, reading-material progress, study plans and Pomodoro focus sessions.
  • Gamification records: experience points and the events that earned them, badges, streaks and streak freezes, tournament entries, and leaderboard positions.

AI tutor and doubt-solving

  • The questions you type and the photos you upload to the AI tutor or doubt solver, the AI’s replies, and the token usage and estimated cost of each call. These are kept as conversation threads on your account so you can revisit them. Section 6 explains which third-party model providers process this content.

Payments and premium plans

  • When you pay through eSewa or Khalti, the payment itself happens on their site. We receive only a transaction reference, the amount, the plan you bought and the result. We never see or store your wallet PIN, password, card number or bank credentials.
  • When you use a manual payment channel (a direct wallet or bank transfer), we store the transaction ID you enter, the sender name or number you provide, any note, and the screenshot you upload as proof, together with the reviewer’s decision and reason.
  • Your subscription history: plan, period, amount, gateway and reference.

Referrals and payouts

  • Your referral code, which accounts signed up with it, the discount and commission each produced, and their status.
  • When you request a payout: the amount, the method (eSewa, Khalti or bank), the destination number or account details and account holder name you enter, and the review outcome.

Things you write or upload

  • Reading materials you submit to the community library, feedback and bug reports (with an optional contact name and email if you are not signed in), the page you sent them from, and reports you make about individual questions (the reason, any note, and the paper you were reviewing).

Preferences and devices

  • Your email announcement setting, push notification setting, daily quiz reminder hour, sidebar layout, and whether you finished or dismissed the welcome tour and getting-started checklist.
  • If you enable push notifications, the browser-issued push subscription (endpoint and encryption keys) and the browser’s user agent string, one per device, plus delivery history for it.
  • Your in-app notification inbox: the title, text and link of each reminder, result or announcement we send you, and whether you have read it. Read items are removed after 30 days and unread ones after 120.

Technical and security data

  • Your IP address and request metadata, used for rate limiting and recorded in our hosting provider’s server logs.
  • How you found us: on your first visit we note the channel that brought you here (a UTM tag in the link, the site that referred you, or an invite link) and the first page you saw, in a cookie that lasts 30 days. If you create an account it is stored on the account as a channel name — never a full URL of another site — and the cookie is removed. We use it only to see which channels bring students who go on to study.
  • Paywall interactions: when you open the pricing page, which locked feature sent you there, and when you start or complete a checkout. We use these counts to see where students give up and never show them to anyone but administrators.
  • A security audit log of significant events on your account: sign-in and sign-up (including blocked attempts), password and email changes, payment activations, submissions, and any action an administrator takes on your account, each with a timestamp and your email.

We do not collect your phone number, date of birth, home address, government ID, exam roll number or any special-category data such as health information, and we ask you not to put such information into free-text fields, doubt photos or uploaded materials.

3. Cookies and browser storage

We use a small number of first-party cookies, all of them functional. We do not use advertising cookies, third-party analytics cookies or cross-site tracking of any kind.

NamePurposeLifetime
iom_sessionKeeps you signed in. A signed token holding your user ID, name, email and role. HttpOnly, so scripts cannot read it.30 days
g_oauth_state, g_oauth_verifierProtect the Google sign-in handshake against forgery (CSRF state and PKCE verifier). Deleted as soon as the sign-in finishes or fails.10 minutes
ref_codeRemembers the invite link you arrived through so the discount is applied if you sign up later.30 days, or until you sign up
iom_sidebarRemembers whether you collapsed the sidebar.1 year

The app also uses a service worker and browser cache so recently visited pages and static files load offline, and local storage for small conveniences such as an in-progress exam draft or a dismissed banner. None of this leaves your device. You can clear all of it from your browser settings; signing out deletes the session cookie.

4. Sign in with Google

You can create an account or sign in with your Google account instead of a password. When you do, we ask Google for the standard openid, email and profile scopes only, and we receive:

  • your Google account’s stable identifier (used to recognise you next time),
  • your email address and whether Google has verified it, and
  • your display name.

We do not request or receive access to your Gmail, contacts, calendar, Drive, photos, YouTube or any other Google service, and we never post anything to your Google account. The access token Google issues is used once, during sign-in, to read the profile above and is then discarded. We do not store Google access or refresh tokens.

If an account already exists with the same email address, and Google reports that address as verified, sign-in links the Google identifier to that account so both methods work. If Google reports the address as unverified, we refuse to link and ask you to log in with your password instead, to stop anybody claiming an account they do not own.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to create and sign you into your IOMMock account; it is not used for advertising, not sold, and not transferred to anyone else except as needed to provide the service or as required by law.

You can revoke IOMMock’s access at any time from your Google account’s third-party connections page. Revoking access does not delete your IOMMock account; use “Forgot password?” to set a password if you want to keep signing in without Google, or ask us to unlink or delete the account (section 9).

5. How and why we use your data

We use personal data to:

  • Run the service: create and secure your account, deliver and score tests, keep your history, bookmarks and plans, compute your analytics and predictions, and show your standing on leaderboards.
  • Provide AI features: send your question, the related exam question, and any photo you attach to a model provider and return the reply, within the daily and monthly limits of your plan.
  • Process payments and payouts: verify a payment with the gateway or by manual review, activate the plan you bought, send a receipt, attribute referral discounts and commissions, and pay out referral earnings.
  • Communicate with you: transactional email (email verification, password reset, receipts, payment-review results, payout results); optional grand mock announcements and reminders by email; optional push notifications (daily quiz reminders, results and event updates) on devices where you turned them on.
  • Moderate and review: check submitted reading materials, payment proofs, payouts and feedback, and act on abuse.
  • Keep the platform safe: rate-limit abusive traffic, detect duplicate accounts and leaderboard or referral manipulation, investigate security incidents, and keep an audit trail of administrative actions.
  • Improve the product: analyse aggregate usage, for example which questions are answered wrongly most often or which options students pick, to fix questions and build better features. Wherever possible this is done on aggregated or de-identified data.
  • Comply with law: keep records that tax, accounting or other legal obligations require, and respond to lawful requests.

Legal bases

Where a legal basis is required, we rely on: performance of our contract with you (the Terms of Service) for everything needed to run the account and plan you asked for; your consent for optional announcements, push notifications, Google sign-in and uploading photos to the AI; our legitimate interests in securing, moderating and improving the service; and legal obligation for financial records. You can withdraw consent at any time as described in section 9.

We do not use your personal data for automated decisions that have legal or similarly significant effects on you. Rank and college predictions are estimates for your information only, generated from your score and published MEC merit-list data, and are never shared with any institution.

6. Who we share data with

We do not sell personal data and we do not share it with advertisers or data brokers. We share it only with service providers that process it on our behalf and under contract, with other users where a feature is designed to be visible, and where the law requires.

Service providers (processors)

We run on specialist providers rather than our own servers. Each one receives only what its job needs, acts on our instructions under a contract, and may not use your data for anything else. The current list of providers is available on request (section 13).

CategoryWhat they do for usData involved
Cloud hosting providerRuns and serves the application and keeps its server logsAll traffic, including IP addresses
Managed database providerStores the databaseEverything in section 2
GoogleSign-in with GoogleThe profile data in section 4
eSewa, KhaltiPayment gatewaysAmount, plan, transaction reference; they collect what they need on their own site
Email delivery providerSends transactional and announcement emailYour name, email address and the message content
AI model providersGenerate AI tutor replies, doubt solutions and study plansThe text you type, the exam question in context, any photo you attach, and your plan tier for rate limiting. Your name, email and account ID are not sent.
Browser push servicesDeliver push notifications, operated by the maker of your browserThe push subscription and the notification text

AI providers may process your content on servers outside Nepal and may retain it briefly for abuse monitoring under their own policies. We choose providers and settings that do not train models on our traffic where the provider offers that option, and we may change provider without notice. Do not put personal data about yourself or anyone else in an AI question or photo.

Other users

  • Leaderboards and tournaments show your score, rank, XP or streak next to a masked version of your name (first name and last initial), including to visitors who are not signed in.
  • Community reading materials you submit are, once approved, published under your account name.
  • Referrals: the person who invited you can see that their invite converted and the commission it earned, but not your name or email. You can see the first name of whoever invited you.
  • Peer statistics (what percentage of students chose each option) are shown only in aggregate and only once at least three students have answered a question.

Our staff

Administrators and moderators can view accounts, attempt history, submissions, payment proofs, payout requests and feedback in order to run the service. Every such action is written to the audit log.

Legal and corporate

We may disclose data when required by Nepali law, a court order or a lawful request from a public authority, to enforce our terms, or to protect the rights, property or safety of users or the public. If Nepsor Technology Pvt. Ltd. is involved in a merger, acquisition or sale of assets, your data may be transferred to the successor, who will remain bound by this policy.

7. Where your data is stored

We are based in Nepal, but our infrastructure is not. The database is hosted in Asia pacific, and our hosting, email, AI and push providers operate mainly from the United States and the European Union. By using the service you understand that your data will be stored and processed outside Nepal. We choose providers that publish security commitments and contractual data-protection terms, and we transfer only what each one needs.

8. How long we keep data

  • Account, study history and preferences: for as long as your account exists. Attempt history is the product, so we do not prune it while you are a member.
  • AI conversations and photos: for as long as your account exists, so you can revisit them; deleted with the account.
  • Payment proof screenshots: until the proof has been reviewed and any dispute window has passed, and in any case no longer than 12 months after the review, after which we delete the image and keep only the transaction record.
  • Payment, subscription, referral and payout records: 7 years after the transaction, as accounting and tax rules require, even if the account is deleted.
  • Security audit log: 24 months, then deleted or de-identified.
  • Password-reset and verification tokens: 1 hour and 24 hours respectively, and they are single-use.
  • Push subscriptions: until you turn push off on that device, the browser revokes it, or deliveries keep failing.
  • Server logs held by our hosting provider: about 30 days.

When you delete your account (section 9) it is locked at once and, after a 7-day grace period, we erase your personal data: profile, test history, bookmarks, flashcards, study plans, AI conversations and notification devices. What remains is the financial record set above with your name and email removed, and anything we need to keep to establish or defend a legal claim. Backups are overwritten on a rolling cycle within a further 30 days. Community materials you authored stay published without your name unless you ask us to take them down.

9. Your rights and choices

You have the right to know what personal data we hold about you, to have it corrected, to have it deleted, to receive a copy of it in a portable format, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. These rights apply under Nepal’s Individual Privacy Act, 2075 (2018) and, if you are in a jurisdiction such as the EEA or UK, under its own data protection law.

What you can do yourself

  • Turn email announcements and push notifications on or off, and set or clear the daily reminder, at /notifications. Every announcement email also carries a one-click unsubscribe link that works without signing in.
  • Set or change a password from /forgot-password.
  • Revoke Google’s connection from your Google account (section 4).
  • Remove bookmarks, flashcards and study plans from within the app.
  • Clear cookies and offline caches from your browser.
  • Delete your account from /account. You are signed out everywhere immediately and the account is locked. Signing in again within 7 days cancels the request; after that the data described in section 8 is erased permanently and cannot be recovered. Deleting your account ends any remaining premium period without refund except as set out in the Terms of Service.

What to ask us for

Contact us (section 13) to access or export your data, correct your name or email, unlink Google, take down a material you submitted, or have us delete an account you can no longer sign in to. We will confirm your identity, act within 30 days, and tell you if any part of the request cannot be honoured and why.

If you believe we have handled your data unlawfully you may complain to us first, and you also have the right to complain to the competent authority in Nepal or in your own country.

10. How we protect your data

  • All traffic is encrypted in transit with TLS.
  • Passwords are hashed with bcrypt and never stored or logged in clear text.
  • Session cookies are HttpOnly, SameSite and, in production, Secure-only; sessions expire after 30 days.
  • Password-reset and verification links are random, single-use, short lived, and stored only as SHA-256 hashes.
  • Google sign-in uses CSRF state and PKCE, and links accounts only on a Google-verified email.
  • Payments are confirmed server-side with the gateway (signature check or lookup) and an amount check before any plan is activated.
  • Sign-in, sign-up, password reset and submission endpoints are rate limited; administrative actions are audit-logged.
  • Access to production systems is restricted to staff who need it.

No system is perfectly secure. If we learn of a breach that affects your personal data we will notify you and any relevant authority without undue delay, and tell you what happened and what we are doing about it. Please choose a password you do not use elsewhere, and tell us at once if you think your account has been accessed by someone else.

11. Students under 18

The service is built for students preparing for an undergraduate medical entrance, most of whom are 17 or older, and it may be used by anyone aged 16 or above. If you are under 18, please use the service with the knowledge and consent of a parent or guardian, who accepts our Terms of Service on your behalf. We do not knowingly collect personal data from anyone under 13; if you believe a child under 13 has created an account, contact us and we will delete it.

A parent or guardian of a user under 18 may exercise that user’s rights in section 9 on their behalf once we have verified the relationship.

12. Changes to this policy

We will update this policy when the service or the law changes. The date at the top shows the current revision. For material changes, such as a new category of data, a new purpose, or a new kind of recipient, we will give notice by email or an in-app notice before the change takes effect. Continuing to use the service after that date means you accept the revised policy.

13. Contact us

To ask a question about this policy or exercise any of your rights, contact Nepsor Technology Pvt. Ltd. through any of:

  • Email: dev.nepsor@gmail.com
  • The feedback form at /feedback (works without an account)
  • The company contact page at nepsor.com/contact

Please write from the email address on your account, or tell us which account you mean, so we can verify that the request is genuinely yours before acting on it.