Scope and key commitments
1.1Who this Policy covers
This Privacy Policy (“Policy”) applies to the SurgiTest websites, web applications, mobile applications, educational services, communications, and related features that link to it (collectively, the “Service”). SurgiTest LLC (“SurgiTest,” “we,” “us,” or “our”) is responsible for the personal data described here except where an institutional agreement makes an organization responsible for a specific processing activity.
This Policy does not govern an external website, publication, payment page, device service, or other third party that has its own privacy notice, although it explains when we use providers to operate SurgiTest.
1.2Educational service; no patient data
SurgiTest is an adult professional-education and board-preparation service. It is not a healthcare provider, clinical record system, or patient-care platform. Do not submit protected health information (“PHI”), patient names, dates of birth, medical record numbers, identifiable patient images, or other information that could reasonably identify a real patient.
Unless SurgiTest has expressly signed a written business associate agreement that applies to a specific institutional workflow, the Service is not intended to receive or process PHI. Automated screening may help identify prohibited content but does not replace your responsibility to de-identify material before upload.
1.3Our core privacy commitments
We use personal data to provide and secure the Service, personalize education, process authorized payments, support users, comply with law, and improve SurgiTest. We seek to collect the minimum data reasonably needed for those purposes, restrict internal access, and avoid placing private learning content in general analytics.
Information we collect
2.1Account, profile, and eligibility information
We collect information you provide when creating or managing an account, such as name, email address, authentication credentials or tokens, professional role, specialty, training status, location or time zone, notification preferences, and account settings. Firebase Authentication or another disclosed authentication provider may process credentials and login tokens on our behalf.
We may also maintain entitlement and eligibility data, including Readiness Pass activation, included-activity consumption, package type, specialty access, legacy access balances, feature flags, institutional seat status, and Board Group eligibility.
2.2Learning activity and session records
When you use SurgiTest, we may collect prompts presented to you, typed or transcribed answers, examiner turns, session and attempt identifiers, timing, completion status, scores, grading outputs, feedback, corrections, critical-error classifications, readiness snapshots, strengths, improvement areas, study history, content interactions, and related metadata.
Longitudinal features may combine current and prior learning records to show trends, recommend targeted practice, identify underrepresented domains, revisit earlier errors, and generate personalized educational plans.
2.3Voice and speech information
If you use a voice-enabled feature, the Service processes candidate audio to produce a transcript through SurgiTest's MedASR pipeline and, where the existing fallback or corroboration policy applies, device speech-recognition services. The Service may record server-authorized transcript text, word or segment uncertainty, timestamps, correction status, and processing metadata needed to run and grade the session.
Raw candidate audio is not retained as part of the ordinary learning record and is not placed in general analytics. Depending on the workflow, it may be transient or retained temporarily to complete an interrupted upload, preserve a retryable attempt, finish grading, support an authorized review, investigate a security incident, or meet a legal obligation, and is then deleted under the applicable lifecycle.
We do not use candidate voice to identify you, create a voiceprint, infer identity, or perform biometric authentication.
2.4Personal cases, case logs, documents, and media
For supported specialties and packages, you may submit de-identified case logs, notes, documents, images, spreadsheets, PDFs, or other educational materials. We collect the uploaded file, processing status, specialty and case metadata, de-identification or safety-screening results, and private derived artifacts such as structured cases, likely examiner targets, question plans, preparation checklists, case-mix classifications, complication or documentation signals, related learning, and portfolio insights.
Personal-case content is owner-scoped and is not placed in general analytics. You must have the right to upload the material and must remove patient identifiers and other prohibited information before submission.
2.5Automated educational inferences
We create educational inferences from your activity, such as simulated specialty and SurgiTest scores, readiness estimates, performance trends, strengths, improvement areas, critical-error categories, communication or prioritization patterns, case-mix coverage, documentation gaps, related-learning suggestions, and recommended next steps.
These inferences are for learning and product functionality. They are not official exam results, medical determinations, licensure decisions, employment decisions, credentialing decisions, or decisions that produce legal or similarly significant effects.
2.6Board Group information
If you create, join, or interact with a Board Group, we collect the group name, owner, membership and invitation status, formation window, weekly commitments, completion status, candidate-safe verified activity summaries, encouragements, privacy and notification preferences, sharing actions, and Group Rate eligibility, payment, credit, refund, or award status.
2.7Institutional and faculty information
For organization-sponsored accounts, we may receive or collect organization name, department or program, roster and seat data, affiliation, role, invitation and activation status, assignments, completion data, cohort membership, aggregate or individual readiness information, faculty-review permissions, administrative actions, audit history, and support or procurement records.
The precise data visible to an organization depends on its configuration and agreement. We describe that visibility in the invitation, in-product notice, institutional documentation, or other applicable terms.
2.8Transactions and subscription information
When you purchase a package, Stripe or another disclosed payment processor receives payment-card and billing information directly. SurgiTest receives transaction identifiers, package, price, tax, billing period, payment status, limited payment-method details such as brand and last four digits, renewal date, cancellation status, refunds, disputes, and fraud or risk signals. We do not store your full payment-card number.
2.9Communications, Help & Feedback, and review requests
We collect messages and information you send to support, Help & Feedback, legal, billing, or other SurgiTest channels. Depending on the category, a submission may include a product suggestion, technical issue, clinical-content concern, score-review request, transcript-correction request, audio-review request, general feedback, optional screenshot, and permission to contact you.
To route and investigate a submission, the Service may attach your user identifier, specialty, current route, case or content version, session, attempt, turn or artifact identifier, app and device version, feature flags, non-sensitive error identifiers, and timestamp. We do not automatically attach full transcripts, candidate audio, personal-case uploads, or other sensitive artifacts. We request explicit permission before reviewing those materials when needed.
2.10Morning Brief and notification preferences
Morning Brief Delivery is currently available in app. If optional email, push, Smart delivery, cadence, reminder, or local-time controls are offered and you enable them, we may collect the selected channel, preferred address or device, delivery time, cadence, pause and reminder preferences, delivery, bounce, and unsubscribe events, and whether the brief was opened or completed where those measurements are enabled and lawful.
Email delivery is off by default. If offered and enabled, a Morning Brief email may include a retrieval question, high-yield points, an oral-board prompt, a deep link, and a high-level progress cue. It is designed to exclude personal-case titles or narratives, uploaded case information, transcripts, candidate audio, detailed scores, patient-like information, and sensitive billing data.
2.11Device, log, usage, and security data
We automatically collect technical information such as IP address, approximate location derived from IP, browser and device type, operating system, app version, language, time zone, referral URL, network and request metadata, page and feature interactions, timestamps, crashes, latency, diagnostic events, authentication and security events, and identifiers used to prevent fraud or maintain sessions.
General analytics are designed not to include PHI, raw candidate audio, full private transcripts, or personal case content. We may use pseudonymous identifiers and aggregate metrics to understand adoption, reliability, and performance.
2.12Cookies and similar technologies
Our websites and web applications use cookies, local storage, SDKs, pixels, and similar technologies for authentication, security, preferences, performance, and analytics. Section 11 explains the categories and available controls.
Sources of information
We receive personal data from the following sources:
- directly from you when you create an account, answer questions, upload material, configure settings, make a purchase, join a group, or contact us;
- automatically from your browser, device, app, and interaction with the Service;
- from service providers such as authentication, cloud, payment, email, analytics, security, and support providers;
- from an institution or organization that provisions a seat, roster, assignment, or faculty-review workflow;
- from another user who invites you to a Board Group or deliberately shares an allowed result with you; and
- from public or licensed sources used to maintain educational content, where those sources do not ordinarily identify you.
How we use information
We use personal data for the following purposes:
| Purpose | Examples |
|---|---|
| Provide and personalize the Service | Create and secure accounts; deliver cases, examiner turns, speech recognition, transcripts, grading, feedback, learning plans, Daily Briefs, personal-case outputs, portfolio insights, and specialty-specific content. |
| Maintain learning continuity | Save progress, show histories and trends, revisit prior errors, recommend targeted reassessment, and connect related learning across features. |
| Process access and payments | Activate the Readiness Pass, assign entitlements, manage annual packages, renewals, cancellations, taxes, Board Group credits, refunds, disputes, and institutional seats. |
| Communicate with you | Send account, security, billing, legal, support, optional Morning Brief, and notification messages; honor delivery preferences and unsubscribe requests. |
| Support and review | Troubleshoot technical issues; investigate transcript, audio, score, content, and billing concerns; prevent duplicate processing; preserve review history. |
| Improve quality and reliability | Evaluate de-identified or aggregate performance; improve prompts, rubrics, content, safety controls, accessibility, user experience, latency, and error handling. |
| Protect users and the Service | Authenticate users; detect account sharing, abuse, fraud, malware, prompt injection, unauthorized access, PHI submissions, and other prohibited conduct. |
| Comply with law and enforce agreements | Maintain required records; respond to lawful process; establish, exercise, or defend legal claims; enforce the Terms; complete audits and corporate transactions. |
We may create information that is aggregated or de-identified so that it no longer reasonably identifies you. We may use and disclose that information for lawful product, research, statistical, safety, and business purposes and will not attempt to re-identify it except to test whether de-identification is effective or as otherwise permitted by law.
Legal bases for processing
Where applicable law requires a legal basis, we rely on one or more of the following, depending on the activity:
- Contract: processing needed to create your account, deliver requested learning features, process a purchase, maintain progress, provide support, and administer the Terms.
- Legitimate interests: securing and improving the Service, preventing fraud, understanding feature performance, maintaining educational quality, supporting users, and operating our business, balanced against your rights.
- Consent: optional Morning Brief email or push delivery, optional analytics cookies where consent is required, deliberate result sharing, and review of sensitive support artifacts when we ask for permission.
- Legal obligation: tax, accounting, consumer-protection, security, regulatory, court-order, and other obligations imposed by law.
- Vital or public interests: only in the unusual situation where processing is necessary to protect a person from serious harm or respond to a lawful public-interest requirement.
Where SurgiTest processes personal data solely on behalf of an institution, the institution determines the applicable legal basis and SurgiTest acts under its instructions and contract, subject to law.
AI, speech, and automated processing
6.1OpenAI examiner, grader, and learning workflows
SurgiTest uses OpenAI business and API services for authorized AI functions, which may include live examiner turns, grading, feedback, classification, Daily Brief generation, personal-case processing, and related learning. Depending on the feature, we may send the minimum necessary prompt context, server-authorized transcript, candidate answer, session state, rubric, specialty information, de-identified personal-case text, and prior learning context needed to return the requested output.
We do not send account passwords or complete payment-card information to AI providers. Raw candidate audio is not sent to the examiner or grader pathway. Under OpenAI's business and API terms, API inputs and outputs are not used to train OpenAI's general models by default unless the customer affirmatively opts in. Provider retention may vary by endpoint and SurgiTest configuration and may include limited short-term logs for service delivery, abuse prevention, security, or legal compliance.
6.2Google Cloud, Firebase, and text-to-speech
Google Cloud and Firebase provide core infrastructure such as hosting, functions, databases, storage, authentication, security, and operational logs. Google Cloud text-to-speech or another disclosed voice provider may receive examiner text and voice settings to generate examiner audio. The provider does not need candidate audio, passwords, or complete payment details to synthesize examiner speech.
6.3MedASR and device speech recognition
SurgiTest's MedASR pipeline is the primary speech-recognition path when available. Device speech recognition may be used only under the configured fallback or corroboration policy. The system preserves a server-owned transcript and uncertainty metadata for examiner and grader continuity. Candidate audio is handled as transient processing data as described in Sections 2.3 and 12.
6.4Automated educational processing
AI and deterministic systems may analyze answers, transcripts, timing, content interactions, and prior results to produce scores, feedback, classifications, recommendations, and readiness insights. These processes support education and do not make decisions with legal or similarly significant effects. You may request review of a transcript, score, audio issue, or content concern through Help & Feedback.
6.5Product improvement limits
We may analyze aggregate or de-identified patterns to improve SurgiTest content, prompts, rubrics, safety, and reliability. General analytics do not include PHI, personal-case content, raw candidate audio, or full private transcripts. We do not authorize a general-purpose third-party AI provider to train on your private User Content by default. A separate voluntary research or data-sharing program would require a clear notice and any consent required by law.
Board Group privacy
8.1Information visible by default
A Board Group member may see group membership, the group name, weekly commitments, completion status, candidate-safe verified activity summaries, and encouragements. The group owner can manage invitations and settings but cannot manage another member's subscription, payment method, cancellation, account security, or private learning record.
8.2Information not shared by default
We do not expose exact scores, detailed feedback, full activity history, transcripts, candidate audio, personal-case content, uploaded materials, private readiness insights, or billing details to a Board Group by default. Those items are shared only if you deliberately use an available result-sharing control that shows the intended audience and content.
8.3Group Rate administration
We use membership, formation-window, checkout attribution, payment, refund, dispute, and fraud data to determine and equalize Group Rate benefits. Other members may be shown whether a group has reached an eligible member count or rate tier, but they do not receive your payment-card details or complete transaction history.
Institutional accounts and faculty access
9.1Roles and responsibility
An institution may sponsor seats, manage rosters, assign activities, review adoption, or enable faculty and department dashboards. Depending on the arrangement, SurgiTest may act as an independent controller for your direct account relationship, as a processor or service provider acting on the institution's instructions, or in both roles for different data.
9.2Administrator and faculty visibility
Authorized administrators may be able to see seat status, affiliation, activation, assigned specialty, completion, high-level usage, aggregate cohort readiness, and audit history. If an institution enables individual coaching or faculty review, designated faculty may also receive the specific scores, feedback, transcript excerpts, session artifacts, or other information described in the institutional notice.
Raw candidate audio, personal-case uploads, complete private transcripts, and sensitive support submissions are not included in ordinary administrative analytics. Any broader faculty access must be specifically enabled, limited to authorized roles, and disclosed. Institutional agreements may impose additional privacy, security, retention, and access requirements.
9.3Questions about an organization-sponsored account
Your institution may have its own privacy notice and may be responsible for requests concerning data it controls. You may contact SurgiTest or the institution's designated administrator to understand the configuration, request access, or raise a concern. We will route requests to the responsible party where appropriate.
Email, notifications, and support
10.1Required service messages
We send messages necessary to operate and secure your account, such as verification emails, password resets, security alerts, receipts, renewal or price notices, legal notices, service-status updates, and responses to requests. These are not marketing messages and may continue while an account or transaction requires them.
10.2Optional Morning Brief Delivery
Morning Brief email is off by default. Where optional delivery is available, you may opt in, select offered timing and cadence controls, pause delivery, enable an offered reminder, or return to in-app-only delivery. Each email includes a direct link to delivery preferences or a one-click unsubscribe control. We honor an unsubscribe through the available control without requiring continued email delivery.
We do not send a Morning Brief when no valid brief is available, do not intentionally resend the same brief because of a retry, and avoid sending a simultaneous push notification when the configured email has already been sent. Delivery and reminder behavior may be adjusted by your settings and completion status.
10.3Marketing communications
We do not send promotional marketing email without the permission or other lawful basis required where you live. You can unsubscribe from marketing without affecting required account, security, billing, or legal messages.
10.4Help & Feedback and sensitive artifacts
Support and review submissions are accessible only to personnel and providers who need them to route, investigate, resolve, audit, or secure the request. Product suggestions may be used to improve SurgiTest as described in the Terms. Case-specific review content remains governed by this Policy and is not published as product feedback.
Do not include PHI or patient identifiers in a message or screenshot. If a full transcript, candidate audio, or personal-case artifact is necessary, we will seek explicit permission and use the least information reasonably needed for the review.
Data retention and deletion
We retain personal data only as long as reasonably necessary for the purposes described in this Policy, including providing longitudinal learning, maintaining security, honoring user choices, resolving support and billing issues, complying with law, and establishing or defending claims. The following describes our ordinary approach; a legal hold, dispute, institutional agreement, or mandatory recordkeeping rule may require a longer period.
| Data category | Ordinary retention approach |
|---|---|
| Account and profile | Retained while the account is active and for the limited period needed to complete deletion, resolve account matters, prevent fraud, and meet legal obligations. Required billing, tax, security, and dispute records may be retained longer. |
| Raw candidate audio | Not part of the ordinary retained learning record. Depending on the workflow, audio may be transient or retained temporarily through the acknowledgment, recovery, grading, or authorized-review lifecycle, and is then deleted unless a support, security, or legal hold requires otherwise. |
| Transcripts, turns, scores, and feedback | Retained for the life of the account or until you delete the supported session or account, because these records power histories, trends, reassessment, review, and learning continuity. |
| Learning profiles and inferences | Retained while needed to provide readiness, trend, recommendation, portfolio, and targeted-learning features. They are deleted or de-linked with the associated account or source record, subject to stated exceptions. |
| Personal cases and derived artifacts | Retained while the source case remains in your account. Deleting the source case or account is intended to remove or de-link the related structured case, defense plan, questions, classifications, checklist, and private portfolio artifacts. |
| Examiner text-to-speech audio | Generated or cached only as long as reasonably needed for playback, reliability, and limited troubleshooting, then expired under the applicable lifecycle. |
| Board Group data | Retained while the group or membership is active and for the limited period needed to administer invitations, commitments, Group Rate awards, fraud controls, support, and disputes. User-directed shared results follow the retention of the source record and group feature. |
| Institutional records | Retained according to the institutional agreement, disclosed dashboard purpose, account relationship, and applicable law. Aggregate or de-identified cohort statistics may be retained longer. |
| Support and review requests | Retained as needed to resolve the request, document corrections or outcomes, identify recurring issues, maintain auditability, protect rights, and comply with law, then deleted or de-identified under the support retention schedule. |
| Transactions and billing | Retained for subscription administration and as required or permitted for tax, accounting, payment disputes, fraud prevention, audits, and legal compliance. Complete card numbers remain with the payment processor. |
| Security, diagnostic, and analytics data | Retained under configured operational and provider schedules for security, reliability, fraud prevention, and product analysis. Aggregate or de-identified statistics may be retained longer because they no longer reasonably identify you. |
12.1Provider-side retention
A service provider may retain limited data under its own contract and configured service behavior. For example, an AI provider may keep short-term abuse-monitoring or application-state logs unless a different approved retention control applies. Payment processors maintain records required for financial compliance. We configure providers and endpoints with privacy and retention in mind and do not claim zero provider retention unless that control is actually enabled for the relevant workflow.
12.2Backups and deletion completion
After deletion from active systems, residual encrypted copies may remain in restricted backups, caches, or logs until they expire through ordinary rotation. Those copies are not restored for ordinary use and remain subject to access controls. We may retain a minimal record of a deletion request, fraud event, legal hold, or transaction when required or permitted by law.
12.3Account deletion
You may initiate account deletion through the account settings made available to you or by emailing support@surgitest.com. We may verify identity before completing the request. Account deletion is different from subscription cancellation, and the deletion flow will explain any billing step. Deleting an app from a device does not delete an account.
Security
We use technical and organizational safeguards designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. Measures may include encryption in transit, provider-managed encryption at rest, role-based access controls, least-privilege permissions, multi-factor authentication for sensitive administrative access, logging, monitoring, secure development practices, dependency updates, backups, and incident-response procedures.
Access to private learning data is limited to personnel and service providers who need it for an authorized purpose and are subject to confidentiality and security obligations. We review controls as the Service evolves. No transmission or storage system is completely secure, and we cannot guarantee absolute security.
Protect your credentials, use a unique password, enable available security features, and contact support@surgitest.com promptly if you suspect unauthorized access. If a security incident affects your personal data, we will investigate, mitigate, and provide notices required by applicable law.
International data transfers
SurgiTest is based in the United States and uses providers that may process data in the United States and other countries. Those countries may have privacy laws different from the laws where you live. When applicable law requires a transfer mechanism, we use measures such as contractual protections, data-processing agreements, approved standard contractual clauses, provider certifications, or another lawful basis.
Data-residency and regional-processing options depend on the provider, endpoint, account configuration, and institutional agreement. Selecting a region for one provider may not apply to system metadata, another provider, or a feature that requires processing elsewhere. Contact us for information relevant to a specific institutional deployment or legally protected transfer request.
Your privacy rights and choices
Depending on where you live and subject to legal exceptions, you may have the following rights:
- Access: request confirmation of processing and a copy of personal data we hold about you.
- Correction: update inaccurate or incomplete account information.
- Deletion: request deletion of personal data, subject to legal, security, billing, dispute, and other permitted exceptions.
- Portability: receive certain data you provided in a structured, commonly used, machine-readable format where required.
- Restriction: ask us to limit processing in specified circumstances.
- Objection: object to processing based on legitimate interests or to direct marketing.
- Withdraw consent: turn off optional Morning Brief delivery, optional notifications, analytics consent, sharing, or another consent-based feature without affecting prior lawful processing.
- Appeal: appeal a denial of a privacy request where applicable state law provides that right.
- Complain: contact the appropriate privacy or data-protection authority where you live.
15.1How to exercise a right
Use available account settings or email support@surgitest.com. Describe the request and identify the account email. We may verify identity and authority, ask for additional information reasonably needed to locate records, or use an authorized-agent process where required by law.
We will respond within the period required by applicable law. If we deny or limit a request, we will explain the reason and any appeal option where required. We do not discriminate against you for exercising a privacy right, although deleting or restricting data needed for the Service may prevent us from providing a feature.
15.2Self-service choices
You can manage profile information, available Morning Brief and notification settings, cookie preferences, Board Group sharing, and supported session or personal-case deletion through controls made available in the Service. Some records, such as tax or fraud-prevention data, cannot be removed through self-service controls.
United States state privacy notice
This Section supplements the rest of the Policy for residents of U.S. states with comprehensive privacy laws. The exact rights and definitions vary by state. In the preceding 12 months, we may have collected and disclosed the following categories for the business purposes described in this Policy:
| Category | Examples | Collected or disclosed for business purposes |
|---|---|---|
| Identifiers | Name, email, account ID, IP address, authentication and device identifiers. | Yes |
| Customer records and professional information | Contact information, specialty, role, training status, institution, package and seat information. | Yes |
| Commercial information | Package, transaction, renewal, cancellation, refund, Group Rate, and limited payment-method data. | Yes |
| Internet or electronic activity | Pages, features, clicks, session metadata, device, browser, logs, diagnostics, and security events. | Yes |
| Audio or sensory information | Transient candidate voice input and generated examiner audio used for speech-enabled features. | Yes, with raw candidate audio generally transient |
| User content | Answers, transcripts, support messages, de-identified personal cases, files, and deliberate sharing actions. | Yes |
| Inferences | Scores, readiness estimates, strengths, improvement areas, classifications, and recommendations. | Yes |
| Sensitive personal information | Not intentionally collected; users are prohibited from submitting PHI, government identifiers, precise financial credentials, or patient data. | Not intentionally |
16.1No sale or targeted-advertising sharing
SurgiTest has not sold personal data for money and does not share personal data for cross-context behavioral advertising or targeted advertising as those terms are defined by applicable state law. We do not offer a financial incentive in exchange for personal data. The Board Group Rate is based on eligible paid group membership, not on the sale or disclosure of member data.
16.2State-specific rights
Applicable law may give you rights to know, access, correct, delete, or obtain a portable copy of personal data; opt out of sale, targeted advertising, or certain profiling; limit use of sensitive personal information; and appeal a denied request. Because we do not sell or use personal data for targeted advertising, those opt-outs generally do not change our ordinary practices, but we honor them where legally applicable.
16.3California disclosures
California residents may request the categories and specific pieces of personal information collected, categories of sources, business purposes, and categories of third parties to whom information was disclosed, subject to legal exceptions. California's “Shine the Light” law permits certain requests regarding disclosure for third-party direct marketing; SurgiTest does not disclose personal data for that purpose.
Children’s privacy
SurgiTest is intended for adults preparing for professional examinations and is not directed to anyone under 18. You must not create an account or provide personal data if you are under 18. We do not knowingly collect personal data from children. If we learn that a child has provided personal data, we will take reasonable steps to delete it. A parent or guardian may contact us at support@surgitest.com.
Changes to this Policy
We may update this Policy to reflect changes in the Service, providers, data practices, legal requirements, security measures, or business operations. We will update the date and version at the top. If a change is material, we will provide a prominent in-Service notice, email, or other notice required by law before or when the change takes effect.
Where applicable law requires consent for a new use, we will request it rather than relying only on continued use. We encourage you to review the Policy when you receive a change notice.
Contact information
SurgiTest LLC
Privacy questions, requests, account deletion, or complaints: support@surgitest.com
Terms and formal legal notices: legal@surgitest.com
Attn: Privacy and Legal16192 Coastal Highway
Lewes, Delaware 19958
United States
If an institution controls the data involved in your request, we may direct you to its designated privacy or program contact while assisting as required by the applicable agreement and law.