Effective Date: June 2, 2025 (Last Updated: July 29, 2026)
Controller: SurgiTest LLC (referred to as “SurgiTest,” “we,” “us,” or “our”) is the controller of your personal data for the SurgiTest educational service. We are committed to protecting your privacy and maintaining transparency about our data practices. This Privacy Policy explains what information we collect from you, how we use and share it, and your rights regarding your data. We aim to present this information in clear, plain language in line with global privacy standards.
Note: SurgiTest is a global educational app designed for adult users (18+). It is not a healthcare or medical treatment service, and it is not intended to collect, store, or process protected health information (PHI) or real patient records. You must de-identify any educational materials before uploading them and must not include names, dates of birth, medical record numbers, images, or other identifiers for real people. Because SurgiTest LLC is not a HIPAA-covered entity or business associate, HIPAA rules do not apply to our service.
Information We Collect
We collect personal data that you provide directly and data generated through your use of the SurgiTest app or website. This includes:
- Account Information: When you create an account, we collect information such as your name, email address, and a password. We use Firebase Authentication to manage user sign-ups and logins, which securely stores your login credentials on our behalf.
- User Input and Content: The core of SurgiTest is interactive learning. When you use our service, you may input text, voice recordings, transcripts, uploaded educational case packets, and related metadata as part of practice exam sessions or personal case upload workflows. Voice Input: If you choose to speak your answers or use voice commands, we may process browser speech-recognition output and store audio files or transcripts needed to run the exam, provide feedback, and troubleshoot the experience. Personal uploads must be de-identified educational materials only.
- Payment Information: If you make any purchases (for example, subscribing to premium features or buying practice content), payment details are processed by Stripe. We do not store your full credit-card numbers or financial account information on our servers; Stripe, as a third-party payment processor, handles your payment information securely in compliance with industry standards. We may retain basic transaction details (e.g., the amount, date, and outcome of transactions) for record-keeping.
- Board Group Data: If you create or join a Board Group, we process the group name, membership and invitation status, weekly commitments, candidate-safe verified activity summaries, encouragements, privacy settings, notification preferences, and Group Rate eligibility or award status. By default, other members receive only a limited group projection such as commitments and completed activity. Exact scores, detailed feedback, transcripts, case content, personal uploads, and billing details are not shared with the group unless you deliberately use an available result-sharing control.
- Usage Data: Like many online services, we collect data about how you use our app/website. This includes technical information sent by your browser or device: Internet Protocol (IP) address, device type, operating system, browser type, referring URLs, and timestamps of actions. We also collect information on which features you use and your interactions within the app (for example, the number of practice sessions, pages visited, and buttons clicked). This usage data helps us analyze performance and improve our services.
- Cookies and Tracking Technologies: SurgiTest and our analytics partners use cookies, web beacons, and similar tracking technologies to collect information about your usage over time. For example, Google Analytics sets cookies or device identifiers to gather usage statistics (such as page views, time on page, and click streams). These technologies help us understand how users engage with our app, which pages or questions are most popular, and to diagnose performance issues. You can control cookies through your browser settings and other tools (see Cookies and Tracking Technologies section below for more details).
We do not intentionally collect sensitive categories of data such as health data, racial or ethnic origin, political opinions, biometric identifiers, or real patient PHI. Our service is focused solely on educational content for surgical board exam preparation. We ask that you do not provide personal medical information about yourself or any real patient. If we become aware that uploaded or entered content contains PHI or other sensitive personal data, we may delete, quarantine, or de-identify it.
How We Use Your Information
We use the collected information for the following purposes:
- Providing and Improving the Service: We use your account details to log you in and personalize your experience. Your session transcripts, answers, voice recordings, and de-identified educational uploads are used to provide feedback, grading, text-to-speech, daily briefs, and personal case processing. Our AI features currently use Google Gemini/GenAI on Google Cloud Vertex AI infrastructure, and examiner audio may use Google Cloud Text-to-Speech. We may analyze user input in aggregate or de-identified form to improve SurgiTest content, reliability, and safety. We do not sell voice data, transcripts, uploads, or AI inputs to third parties.
- User Account Management and Support: We use your contact information (email) to communicate with you about your account. This includes sending confirmations, important service announcements, or responding to your support inquiries. If you reach out to our support team (for example, via email at support@surgitest.com), we will use your information to assist you and resolve issues.
- Payments and Subscription Management: If you make purchases, we use information from Stripe about your payment status to activate subscriptions or premium features on your account. For example, knowing that your payment was successful allows us to grant you access to additional question banks or features.
- Analytics and Performance: Usage data and cookies are used to understand how our service is performing and how users engage with it. We analyze this data to debug problems (for example, to investigate if the app crashed for you), to gather metrics on study habits (such as average time spent per question), and to make informed decisions on improving features. Google Analytics helps us see aggregated trends (e.g., which countries our users are in, which content is most viewed) so we can optimize content and UX for our global audience.
- Board Group Operations: We use Board Group data to create private groups, verify meaningful learning activity, calculate commitment progress, deliver notifications, process invitations, determine Group Rate eligibility, equalize incremental discount awards, prevent abuse, and provide customer support.
- Security and Fraud Prevention: We may use information (like IP addresses or account activity) to monitor for suspicious or fraudulent behavior and to protect the integrity of our platform. This includes detecting misuse of the Service (such as cheating bots or unauthorized access attempts) and ensuring that accounts are being used in compliance with our Terms of Service.
- Legal Compliance: Where necessary, we may use your data to comply with applicable laws and regulations or to respond to lawful requests or court orders. For example, we might retain transaction records for tax and accounting purposes, or use personal data to fulfill obligations in the event of an audit or legal requirement.
We will only use your personal information for the purposes above and will not use it in a way that is incompatible with these purposes. If we ever wish to use your data for a new purpose (for instance, if we introduce a new feature that requires additional data processing), we will update this Privacy Policy and, if required, obtain your consent or provide an opt-out option. Our goal is to be transparent and accountable in how we handle your data.
Legal Basis for Processing (International Users)
This section is applicable to users in certain jurisdictions, such as the European Economic Area (EEA), United Kingdom, or other regions with privacy laws that require a “legal basis” for processing personal data. While SurgiTest LLC may not be formally subject to GDPR or similar laws, we endeavor to align with international best practices for data protection. Thus, for transparency, we note the legal grounds on which we rely to process personal information:
- Performance of a Contract: When you create an account and use SurgiTest, you enter into an agreement (our Terms of Service) with us. We process your personal data in order to provide the service you requested – for example, using your inputs to generate exam feedback, or using your email to authenticate you. This is necessary for us to fulfill our obligations to you under that contract (i.e., to deliver the educational services you expect).
- Legitimate Interests: We process certain data as needed for our legitimate business interests, provided those are not overridden by your data-protection rights. For instance, we have a legitimate interest in analyzing and improving our products, securing our platform, and understanding how users engage with our content. We rely on these interests to use data for analytics (e.g., Google Analytics tracking) and for improving AI accuracy using your voice/text inputs. We always consider your rights and will not use personal data in ways that have an unjustified impact on your privacy.
- Consent (where applicable): In general, we do not rely on consent for most data uses (instead, we rely on contract or legitimate interests as described above). However, if we ever want to collect or use your data in a way that requires consent (for example, if in the future we introduce optional features like a newsletter or share user stories), we will ask for your consent. You have the right to withdraw any such consent at any time. With regard to cookies, in some jurisdictions, continued use of our site after seeing our cookie notice may be considered consent for analytics cookies – you can always adjust your browser settings to refuse cookies as noted below.
- Legal Obligation: If we are required by law to process data (for example, retaining transaction records for financial regulations or responding to government requests), such processing is based on legal obligation. This is less common and would typically not be done without informing you unless prohibited (e.g., a gag order in a lawful request).
If you have any questions about the legal basis for our data processing in your jurisdiction, you can contact us (see Contact Information below) and we will explain how we comply with applicable data protection laws.
Data Sharing and Disclosure
We do not sell your personal data to anyone. We also do not share your personal data with third parties for their own marketing or advertising purposes. SurgiTest LLC only shares information in the following circumstances:
- Service Providers (Processors): We use trusted third-party companies to help us operate the SurgiTest service. These vendors only process your data on our behalf and according to our instructions. The specific third-party service providers we use include:
- Google Cloud Platform (GCP): We host our application and database on Google Cloud servers. This means that your personal data (e.g., account info, transcripts, etc.) is stored on GCP infrastructure. Google Cloud provides robust security measures (including encryption of data at rest and in transit) to protect stored data. Google acts as our data processor in this context, storing and handling data as needed to run SurgiTest.
- Firebase Authentication (by Google): Firebase is used for user authentication and account management. When you log in, Firebase verifies your credentials and helps secure your account (for example, handling password storage and login tokens). Firebase may also store basic account profile information. Google (Firebase) operates under strict data processing terms, and data is under our control while Google processes it for authentication.
- Stripe (Payments): Stripe is our payment processor for handling subscription fees or other payments. If you purchase a subscription or any service, the payment information (such as your credit card number, billing name, and address) is provided directly to Stripe via secure checkout forms. Stripe processes your payment and confirms to us that the payment was made. We may receive limited information from Stripe (like the last four digits of your card or the expiration date, plus payment status). Stripe is obligated to protect your payment data and only use it for payment processing. We do not store your sensitive financial details on our own servers.
- Google AI and Text-to-Speech Services: We use Google Gemini/GenAI on Google Cloud Vertex AI infrastructure for AI exam flow, grading, daily briefs, and personal case processing. We also use Google Cloud Text-to-Speech for examiner audio. When these features run, the minimum necessary session content, de-identified upload text, prompt context, or audio text may be sent to Google Cloud services to return results to SurgiTest. We do not provide your password or full payment details to AI providers, and we instruct users not to submit PHI or real patient identifiers.
- Google Analytics: We use Google Analytics to collect aggregate information about how users interact with our website and app. Google Analytics may set cookies or use mobile identifiers to collect usage data (see the Cookies and Tracking Technologies section). The information shared with Google Analytics includes data like page visits, session duration, and geographic region (by IP address). This data helps us improve the user experience. Google acts as a service provider in this role; we have configured Google Analytics to anonymize IP addresses where applicable and not to share data with other Google products. Google does not get to use this Analytics data for its own purposes under our account settings, aside from providing us the analytics service.
- Business Transfers: If SurgiTest LLC is involved in a merger, acquisition, investment, financing due diligence, restructuring, bankruptcy, or sale of all or a portion of our business, personal data may be transferred to a successor or affiliate as part of that transaction. We would ensure that any new owner continues to honor the commitments we have made in this Privacy Policy regarding your personal information.
- Legal Requirements and Protection: We may disclose personal information if we honestly believe that such action is necessary to comply with the law or legal process. For example, we might disclose data in response to a subpoena, court order, or other governmental request. We may also share information when we believe it’s necessary to enforce our Terms of Service, to protect the rights and safety of our company, our users, or others. This can include exchanging information with other organizations for fraud protection and credit risk reduction (though this does not involve selling data, just preventative measures).
- Your Consent or Direction: Apart from the situations above, we will share your personal data with third parties only if you direct us to do so or give us your explicit consent. For instance, if in the future we implement a feature that lets you share your study progress with a mentor or publish a success story, we would only do so with your knowledge and agreement.
Importantly, we do not “sell” Personal Data or share it for behavioral advertising purposes. All third parties who handle user data are service providers that use the data solely to provide services to us (and ultimately to you), under strict data processing agreements. They are not allowed to use your information for any other purpose.
Cookies and Tracking Technologies
As noted, SurgiTest uses cookies and similar tracking technologies to run our service and to understand user behavior:
What Are Cookies: Cookies are small text files that websites store on your browser or device. They often include a unique identifier and are used to remember information about your visit. Similarly, mobile apps may use device identifiers or storage that serve a comparable purpose.
How We Use Them: We utilize cookies for a few key reasons:
- Authentication & Preferences: When you log in to SurgiTest, cookies (or similar tokens) help keep you logged in as you navigate through different sections of the app or website. They also might store your preferences (like language or interface settings) so that you have a consistent experience.
- Analytics: As mentioned, we use Google Analytics which sets cookies to gather data on site usage. These analytics cookies allow us to see how many users visit our site, how they move through the content, and other usage metrics. This information is aggregated and does not directly identify you. It helps us track the effectiveness of new features or content changes over time.
- Performance and Debugging: We might use tools that employ cookies or local storage to monitor the performance of the app (for example, logging errors or load times). This helps us ensure the app runs smoothly and to troubleshoot issues that affect many users.
No Third-Party Advertising Cookies: We do not use any third-party advertising networks or cookies for targeted advertising. You will not see third-party ads on SurgiTest, so we do not track you for advertising purposes across other sites.
Your Choices: When you first visit our website, you might see a notice about cookies. By continuing to use the site, you agree to our use of cookies for the purposes stated. You can control and delete cookies through your browser settings. Most browsers allow you to refuse new cookies, delete existing cookies, or notify you when a cookie is being set. If you disable cookies, note that some features of SurgiTest (especially login and session features) may not function properly. For our mobile app, your device operating system may provide options to reset or limit tracking identifiers.
Do-Not-Track Signals: Some browsers have “Do Not Track” (DNT) features that signal a preference not to have online activity tracked. Currently, our systems do not respond differently to DNT signals, in part because there is not yet an industry consensus on how to interpret them. However, remember that we do not engage in cross-site tracking aside from analytics as described, and you can opt out of Google Analytics specifically by using Google’s opt-out browser add-on or similar tools.
For more information on cookies and how they work, you can visit websites like AllAboutCookies.org. By using SurgiTest, you consent to our use of cookies and tracking technologies as described here. We only use these technologies to improve your experience and our service performance, not for any invasive tracking.
Data Retention
How long do we keep your data? We retain personal data only as long as reasonably necessary to provide the Service, maintain security, comply with legal obligations, resolve disputes, and improve SurgiTest in aggregate or de-identified form.
However, we also want to be transparent about our current practices:
Session Transcripts and AI Grading Feedback: At present, session transcripts and AI grading feedback that you generate are retained for a minimum of 90 days. This means that for at least 90 days after a study session, you will be able to access and download those transcripts from your account. (We implemented this retention period to ensure you have ample time to review and save your progress. It also allows us to use recent session data to improve our AI models.)
Voice Recordings: If you use voice input, audio files may be stored for up to 30 days so we can provide grading, support faculty review, and maintain service reliability. Audio is then deleted under our storage lifecycle unless a shorter period applies to an account-deletion request or retention is legally required. Written transcripts and grading records follow the separate retention period described above.
Personal Uploads: Personal case packet uploads and derived draft cases are retained while they are being processed, reviewed, and made available in your account. You must upload only de-identified educational material. We may delete, quarantine, or reject uploads that appear to contain PHI, real patient identifiers, unlawful content, or material outside the educational scope of SurgiTest.
Account Information: Basic account details (like your email and profile info) and purchase history are kept for as long as you have an account. If you delete your account (or request deletion), we will remove or anonymize these within a reasonable period (unless a longer retention is required by law).
Analytics Data: Aggregated analytics data may be retained indefinitely for historical analysis. However, this data does not identify individual users. Google Analytics data is typically retained for 14 months in our configuration, but we may keep high-level aggregated metrics longer.
Legal and Backup Retention: We may keep certain information as necessary for legal compliance or legitimate business purposes. For instance, if we disable an account for violating terms, we might retain information about that account to prevent future misconduct. Also, data may persist in backup archives for a period of time; if we have backups encrypted and stored by our cloud provider, your data might remain in those archives until they are rotated or destroyed in the normal course of operations.
Even if we mark data for deletion, it might not be immediately removed from all systems. We follow a thorough process to safely delete or anonymize data from active databases and from any caches or backups. According to Google’s infrastructure practices, residual copies may remain temporarily on backup storage before being overwritten, even after active deletion, but will no longer be readily accessible. We will not retain personal data longer than necessary and will periodically review and purge data that is no longer needed.
In summary, some data (like your account info and transcripts) we keep as long as you’re using SurgiTest, and other data (like certain voice inputs or logs) might be pruned after 90 days under current policy, though we may adjust retention periods over time. If we do change our retention practices in a significant way, we will update this Policy or notify users as required.
Your Rights and Choices
We believe it’s important that you have control over your personal data. Subject to applicable law, you have several rights regarding the information we hold about you. These rights include:
- Access and Portability: You have the right to request a copy of the personal data we hold about you and to obtain information about how we process it. Much of your data is readily accessible by you directly: for example, you can view your session transcripts, grading feedback, and profile information by logging into your account. You can also download your session transcripts and feedback through the app interface. If you need a full export of your data or have trouble accessing any information, you can contact us to request it. We will provide your data in a commonly used, machine-readable format (for instance, a CSV or PDF report) so that you can take it to another service if you wish.
- Correction (Rectification): If any of your personal information is inaccurate or outdated, you have the right to correct or update it. You can do some of this through your account settings (e.g., update your name or email if allowed), or by contacting us. We encourage you to keep your information up to date, and we will make reasonable efforts to correct the data upon your request.
- Deletion (Right to be Forgotten): You have the right to request deletion of your personal data. This includes the ability to delete your account and all associated data. We allow users to delete their accounts by contacting our support email. To request deletion of your account and data, please email us at support@surgitest.com. Once we verify your identity and request, we will delete or anonymize your personal information from our active systems, except for data we are required or permitted to retain by law. Please note that after deletion, you will no longer have access to the service with that account, and this process is irreversible. (Data may persist in backups for a short period as explained in Data Retention, but will be purged according to our retention policy.)
- Withdrawal of Consent: In cases where we rely on your consent to process data (for example, if you agreed to receive a newsletter or if we ever ask for consent for a new feature), you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of any processing we already performed, but it will stop that particular processing going forward. For instance, if you opt in to a research study and later change your mind, you can withdraw and we will stop using your data for that study.
- Objection to Processing: You have the right to object to certain processing activities. If you object to our use of your data for analytics or improvement based on legitimate interests, we will consider your request. In some cases, we may have compelling legitimate grounds to continue processing (for example, ensuring the security of our service), but we will honor objections to direct marketing or any processing that is not necessary. Currently, SurgiTest does not send marketing emails without consent, and we do not process data for advertising, so this likely applies mainly to analytics. If you do not want your data used for Analytics, you can use the opt-out mechanisms described in the Cookies section (or contact us for assistance).
- Restriction of Processing: You have the right to request that we restrict processing of your data in certain circumstances – for example, while we verify an accuracy claim or an objection, or if you prefer limited processing rather than full deletion. When processing is restricted, we will still store your data but not actively use it until the restriction is lifted.
- Non-Discrimination: If you exercise any of these rights, we will not discriminate against you. For example, if you choose to delete your data or opt out of certain processing, we will not deny you services except as needed to perform the service (obviously, if you delete your account, you can’t use it further). We do not offer financial incentives for your data, so no penalties or benefits are tied to any privacy choices.
California “Shine the Light” (if applicable): While we do not share personal data with third parties for their own marketing, California residents can request a list of what personal information (if any) we disclosed to third parties for direct marketing in the past year. However, we currently have nothing to report under this rule since we don’t engage in that practice.
To exercise your rights, you can contact us at our support email (support@surgitest.com). For certain requests, we may need to verify your identity (to protect your privacy) before fulfilling the request. We will respond to your request within a reasonable timeframe and in accordance with applicable law. In general, we aim to complete requests within 30 days. If we need more time or if we cannot fulfill your request (for example, due to a conflicting legal obligation), we will inform you of the reason and keep you updated on the timeline.
Finally, if you have concerns about how we handle your data, you have the right to lodge a complaint with a data protection authority (if your country has one). For example, users in the EU can contact their local Data Protection Authority. We would, however, appreciate the chance to address your concerns directly, so we encourage you to reach out to us first with any complaint or question.
Security Measures
We take the security of your personal data seriously and have implemented various measures to protect it:
- Encryption: All communication between your device and SurgiTest is encrypted using HTTPS/TLS. This means that data (such as your login credentials, answers, or voice input) is encrypted in transit and cannot be easily intercepted. Additionally, data stored in our databases on Google Cloud is encrypted at rest by default. Google Cloud Platform uses strong encryption standards (like AES-256) to scramble data on disk, adding a layer of protection to stored information.
- Access Controls: Within our organization, personal data is accessed only by authorized personnel who need it to operate and improve the service (for example, support staff assisting you, or engineers maintaining the system). We limit access based on roles, and employees or contractors with such access are subject to strict confidentiality obligations. Administrative access to our cloud servers, databases, and third-party dashboards (Firebase, Stripe, etc.) is protected with multi-factor authentication and secure passwords.
- Security Testing and Updates: We regularly update our software, libraries, and platforms to address security vulnerabilities. Our development practices include reviewing code for security issues and using industry-standard frameworks that receive security updates. We may also perform periodic security audits or assessments, and we closely follow security advisories from our vendors (e.g., Google Cloud, Firebase, Google AI services, Stripe) to act swiftly if any issue arises.
- Network and Infrastructure Security: Our servers are protected by firewalls and monitoring systems to guard against intrusions. Google Cloud Platform, as our hosting provider, offers robust physical security for the data centers and built-in defenses against common web attacks. We benefit from Google Cloud’s security capabilities and best practices, which include measures against DDoS attacks and regular backups.
- Anonymization and Pseudonymization: Where feasible, we anonymize or pseudonymize personal data to reduce risk. For example, analytics data is analyzed in aggregate without directly identifiable info. When improving AI models, we may remove personal identifiers from the training data. Voice recordings used for AI improvement might be processed in a way that is not linked back to user identities.
- Incident Response: Despite all measures, no system is completely foolproof. In the event of a data breach or security incident, we have a response plan. We will promptly investigate the issue, mitigate any vulnerabilities, and notify affected users and relevant authorities as required by law. We follow the practice of notifying regulators within 72 hours of a significant breach affecting personal data, in line with EU GDPR guidelines, and will also inform users of steps they should take to protect themselves if needed.
Please understand that while we work hard to protect your information, no method of transmitting or storing data is 100% secure. The security of your account also depends on you: keep your password confidential and consider changing it periodically. If you have any reason to believe that your interaction with us is no longer secure (for example, if you suspect your account has been compromised), please contact us immediately.
International Users and Data Transfers
SurgiTest LLC is based in the United States, but we serve a global user base. This means your personal data may be transferred to, and stored on, servers located in countries different from your own. Specifically, most of our data is stored on Google Cloud servers which may reside in the United States or other locations. Likewise, our service providers (Firebase, Stripe, Google AI services, etc.) may process data in the U.S. or other countries.
If you are located outside the United States (for example, in the European Union, the United Kingdom, or elsewhere), please be aware that your information will likely be transferred to and processed in the United States. Data protection laws in the U.S. may differ from those in your home country. However, we take steps to ensure that adequate protections are in place to safeguard your personal data in line with this Privacy Policy and applicable law:
EU and UK Users: For personal data collected from individuals in the EEA, UK, or Switzerland, any international transfer of data is done in compliance with GDPR/UK GDPR requirements. This typically means we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms to ensure lawful and secure data transfers. These SCCs are legal contracts between entities transferring data (for example, between SurgiTest and our service providers like Google or Stripe) that commit all parties to protect the privacy and security of personal data. In addition, some of our providers (like Google and Stripe) participate in frameworks or maintain certifications that demonstrate their compliance with international standards.
Other Regions: For users in Canada, Asia, or other parts of the world, we also ensure compliance with relevant data transfer rules. For example, Canada’s PIPEDA allows transfer as long as protections are in place, and we meet those obligations. Where required, we obtain your consent for cross-border transfer by virtue of you using our service (since transferring your data is necessary to provide the service).
Our Commitment: Regardless of where your data is processed, we will handle it according to the principles outlined in this Policy. We will protect your data with appropriate technical and organizational measures and will only share it with organizations that are obligated to treat it securely and confidentially.
Local Storage: In the future, if our user base grows in certain regions and legal requirements evolve, we may explore options to store data regionally (for instance, hosting data on EU servers for EU customers). We will update our practices and this Policy if such changes are made.
By using SurgiTest, you understand that your information will be transferred to the United States and other jurisdictions as necessary for the purposes described. We strive to ensure any international data transfers comply with applicable legal requirements and that your data remains protected to the standards of your home jurisdiction.
If you have questions about our international data practices, please feel free to contact us. We understand that cross-border data transfer can be complex, and we are happy to address any concerns you might have.
Children’s Privacy
SurgiTest is intended for adult users – specifically, those preparing for professional surgical board exams (who are typically medical professionals or trainees). Our service is not directed to children under the age of 18. We do not knowingly collect personal information from anyone under 18 years old. If you are under 18, you are not permitted to use SurgiTest or provide any personal data to us.
In the event that we discover we have collected personal information from a child under 18 (for example, if a high school student signed up in violation of our terms), we will take prompt steps to delete that information. If you are a parent or guardian and believe that your child under 18 has provided us with personal information, please contact us immediately so that we can delete the account and any related data.
For users in certain jurisdictions, the minimum age may be even higher (for example, some countries set digital consent age at 13 or 16). Our rule is 18 globally because our content is not relevant to children. We encourage parents to be aware of their children’s online activities and to help enforce this policy.
Changes to This Privacy Policy
We may update or modify this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will update the “Last Updated” date at the top of this Policy. If changes are significant, we will provide a more prominent notice (such as by emailing registered users or posting a notice on our website or in-app) to inform you of the updates.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of SurgiTest after any changes to this Policy constitutes your acceptance of the revised Policy. If you do not agree with any updates or changes, you should stop using the Service and, if you wish, delete your account.
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please do not hesitate to contact us:
SurgiTest LLC
Attn: SurgiTest LLC
16192 Coastal Highway
Lewes, DE 19958 USA
Email: support@surgitest.com
Thank you for trusting SurgiTest with your board exam preparation. We are committed to protecting your privacy and providing a secure, valuable learning experience. If you have any questions about this Privacy Policy, please reach out to us. Your privacy matters, and we welcome feedback on our practices.