This policy explains what personal data OSCE AIde collects, why, and what your rights are. The data controller is OSCE AIde, United Kingdom — contact osceaide@gmail.com. We process personal data in accordance with UK data protection law (UK GDPR and the Data Protection Act 2018).
1. Who we are
OSCE AIde is an independent AI-powered study tool that lets you practise spoken clinical-communication scenarios and receive automated feedback. This policy applies to personal data collected through:
- our website at osceaide.com
- the OSCE AIde web application at app.osceaide.com
The data controller responsible for your personal data is OSCE AIde, based in the United Kingdom. If you have any questions about this policy or the personal data we hold about you, contact us at osceaide@gmail.com.
2. Personal data we collect
We collect and process the following categories of personal data:
2.1 Account data
When you create an account we collect your email address and a hashed password. We do not store your password in plain text. If you sign up through a third-party provider (for example a magic link), we receive only the identifiers that provider chooses to share with us.
2.2 Practice session data
When you complete a station we store the text transcript of the session, your examiner-style score, and any notes you choose to add. This lets you review your own progress, and lets us show you trends over time. Transcripts are never used to train AI models.
2.3 Voice input
Speech recognition happens through your browser's built-in speech-to-text service — for example, Google's engine on Chrome, or Apple's on Safari. Your spoken audio is processed by that browser provider under their own privacy policy to produce a text transcript. OSCE AIde never receives, processes, or stores your audio. Only the resulting text transcript reaches our systems.
2.4 Payment data
Subscription payments are handled by Stripe, our payment processor. Stripe collects and stores your payment card details directly — we never see or store card numbers. We receive from Stripe only the information we need to grant access: your subscription status, the plan you chose, and the period covered.
2.5 Usage data
We record limited technical information about how the Service is used: for example, how many API requests your account has made, the time and duration of practice sessions, and error logs. This is used to run the Service (fair-use limits, cost control, debugging), not to build a marketing profile of you.
2.6 Cookies and local storage
We use only strictly necessary cookies and local storage — no advertising or analytics trackers. Specifically:
- a Supabase session cookie so you stay signed in;
- browser local storage for your theme preference, cached session data, and offline access to interface elements.
Because we do not use non-essential cookies, we do not display a cookie banner.
3. Why we use your data and our lawful bases
Under UK GDPR we must have a lawful basis for processing your data. The table below sets out how each activity maps to a basis:
| What we do | Why | Lawful basis |
|---|---|---|
| Create and manage your account | To provide the Service you signed up for | Contract |
| Store your practice history and scores | Core functionality — showing you your own progress | Contract |
| Process payments and renewals | To take payment for your subscription | Contract |
| Enforce fair-use limits and detect abuse | To keep the Service fair and financially viable | Legitimate interests |
| Send service emails (confirm sign-up, password reset, billing notices) | Essential to operate your account | Contract / Legal obligation |
| Debug errors and improve the Service | To keep the product working reliably | Legitimate interests |
| Comply with our legal obligations (for example, tax records) | Legal requirement | Legal obligation |
We do not use your data for advertising or profiling, and we do not send marketing emails as things stand. If we ever want to, we will ask for your explicit consent first — and you can withdraw that consent at any time.
4. Who we share your data with
We share personal data only with the trusted service providers we need to run OSCE AIde. Each acts as a data processor under our instructions.
| Provider | What they do | Data involved |
|---|---|---|
| Supabase | Authentication and database | Email, hashed password, account records, transcripts, scores, notes |
| Vercel | Website and application hosting | Standard access logs (IP address, browser type) |
| Stripe | Subscription billing and customer portal | Email, payment details (Stripe only), billing metadata |
| Anthropic | The AI model that generates patient responses, marking and feedback | Text transcripts of your session (never linked to your name) |
| Resend | Transactional email (sign-up confirmations, password resets) | Email address, message content |
Some of these providers process data outside the United Kingdom — most commonly in the United States. Where they do, transfers are protected by recognised safeguards such as the UK Extension to the EU–US Data Privacy Framework or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
We do not sell your personal data. We do not share your data with advertising networks or data brokers.
5. How long we keep your data
We keep personal data only as long as we need it. Specifically:
- Account and practice data: kept while your account is active. If you delete your account we remove your account records and practice data promptly, and in any event within 30 days.
- Billing records: kept for six years after the end of the tax year in which a transaction occurred, as required by UK tax law.
- Support correspondence: kept for up to two years after your last message so we can respond to follow-up questions.
- Server logs (IP addresses, error logs): kept for 90 days for debugging and security.
6. Security
We take reasonable steps to protect your data:
- Passwords are hashed using industry-standard algorithms — we never see them.
- All connections between your device and our servers use HTTPS/TLS encryption.
- Payment card data never touches our servers — it goes directly to Stripe, which is PCI-DSS Level 1 compliant.
- Our database enforces row-level security, meaning each user can only ever access their own records — even in the unlikely event of a bug in application code.
- Secret keys and API credentials are held server-side only, never exposed to the browser.
- We keep the number of people with database access to the minimum required.
No online service is perfectly secure, but our design aims to ensure that a compromise of any one layer exposes as little data as possible.
7. Your rights
Under UK data protection law you have the following rights in relation to your personal data:
- Right of access — to receive a copy of the personal data we hold about you.
- Right to rectification — to have inaccurate data corrected.
- Right to erasure ("right to be forgotten") — to have your data deleted, subject to any records we must keep for legal reasons.
- Right to restrict processing — to ask us to pause processing your data in certain circumstances.
- Right to data portability — to receive your data in a portable machine-readable format.
- Right to object — to object to processing that relies on our legitimate interests.
- Right to withdraw consent — where processing relies on consent, you can withdraw it at any time.
To exercise any of these rights, email us at osceaide@gmail.com. We will normally respond within one month. There is no charge for exercising these rights.
8. Complaints
If you are unhappy with how we handle your personal data, we would like the chance to put it right — please contact us first at osceaide@gmail.com.
You also have the right to lodge a complaint with the UK's data-protection regulator, the Information Commissioner's Office (ICO). Their contact details are:
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk
9. Children
OSCE AIde is intended for adults preparing for professional dental examinations. The Service is not directed at anyone under 18 and we do not knowingly collect data from children. If you believe we have collected data from a child, please contact us and we will delete it.
10. International users
OSCE AIde is operated from the United Kingdom and this policy is written under UK data protection law. If you use the Service from outside the UK, your personal data will be transferred to and processed in the UK and — through our providers — in other jurisdictions with equivalent safeguards.
11. Changes to this policy
We may update this policy from time to time. If we make material changes we will notify you by email or in the app before they take effect. Minor edits (typos, clarifications) may be made without notice. The "last updated" date at the top of this page always shows the current version.
12. Contact
Data controller: OSCE AIde
Email: osceaide@gmail.com