Privacy Policy
Effective date: June 12, 2026
This policy explains what data Medopsy collects, how we use it, and the choices you have. The short version: we collect your account details and your examination performance data (including audio and transcripts of your practice sessions, and transcripts/reports from public demo attempts), we use it to run the Service and show your program your progress, we don’t sell it, and every patient case on the platform is fictional — the Service holds no real patient information.
1. Data we collect
- Account data: name, email address, role (resident, program director, coordinator), program affiliation, and authentication credentials (passwords are hashed; we never see them in plain text).
- Examination data: audio recordings of your practice sessions, transcripts, rubric scores, examiner decisions, performance reports, and readiness analytics derived from them.
- Demo data: if you use the public demo without an account, we may retain its transcript, generated feedback report, timestamps, browser information, and a non-reversible hash of request IP. We do not save public demo audio recordings.
- Usage and technical data: session timestamps, device and browser information, and server logs needed to operate and secure the Service.
2. How we use it
- To conduct examinations: your speech is transcribed and graded in real time.
- To produce your performance reports and longitudinal readiness analytics.
- To show authorized staff of your own program (program directors and coordinators) your results, utilization, and risk flags. Data is isolated per organization — no other program can see it.
- To operate, secure, debug, review demo quality, and improve the Service.
- To send transactional email (invitations, report notifications, password resets).
We do not sell personal data, and we do not use your recordings or transcripts to train AI models.
3. Service providers
Your data is processed by a small set of infrastructure providers:
- Supabase (database, authentication, storage — hosted in AWS us-east-1, United States)
- Vercel (application hosting)
- OpenAI (grading and report generation; API data is not used by OpenAI to train models)
- Deepgram (speech transcription and text-to-speech, depending on configuration)
- Replicate and Inworld (voice generation fallbacks, depending on configuration)
- Resend (transactional email)
- Cloudflare (DNS and network security)
4. Recordings and retention
Session audio and transcripts are retained so you and your program can review performance. By default, audio recordings are retained for 12 months (programs may arrange a different retention period). Account and report data are retained for the life of the program’s subscription. Public demo transcripts and feedback may be retained for internal quality review. When data is deleted, it is removed from production systems and expires from backups on their rotation schedule.
5. Security
Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access is designed around per-organization isolation, role-based permissions inside each program, and administrative audit logs. Practice sessions contain no real patient information by design.
6. Your rights
You may access your reports and history in the app at any time. You can request a copy of your data, correction of inaccurate account data, or deletion of your account and recordings by contacting us (residents: note that your program administers its roster, so deletion requests may be coordinated with your program). We honor applicable data-protection rights in your jurisdiction.
7. Cookies
We use only essential cookies: authentication session cookies required to keep you signed in. No advertising or cross-site tracking cookies are set.
8. Children
The Service is for medical professionals and is not directed to anyone under 18. We do not knowingly collect data from minors.
9. Changes
We will post any changes to this policy here and update the effective date. Material changes will be announced through the Service or by email.
10. Contact
Privacy questions or requests? Reach us through the contact form at medopsy.com.