OSCELab

Privacy Policy

Last updated 8 June 2026

This policy explains how OSCELAB — referred to here as "OSCELab", "we" and "us" — collects, uses, and stores information when you use our web and mobile apps. It applies to users in Australia, the United Kingdom, the European Union and elsewhere.

Information we collect

  • Account data, including your email address, password hash, and app account token used to link app store purchases.
  • Profile inputs such as performance insight instructions you choose to save.
  • Learning activity and content, including quiz answers, scores, marksheets, conversation transcripts, AI prompts you submit, and generated outputs.
  • Uploads and documents, including files you upload, file metadata, extracted text, OCR text, summaries, and generated learning assets.
  • Device and usage data such as session cookies, IP address, user agent, request IDs, error logs, usage telemetry, and device tokens for notifications.
  • Payment and subscription identifiers from Stripe and app stores (for example customer, subscription, and transaction IDs). We do not store full card numbers.

How we use information

  • Provide the service, authenticate sessions, and manage subscriptions and entitlements.
  • Generate learning content, feedback, and performance insights.
  • Enable voice conversations and store related transcripts for review and scoring.
  • Send transactional and support emails such as welcome and password reset messages.
  • Monitor reliability, diagnose issues, and protect the platform from misuse.

How we share information

We share data with service providers that help us operate OSCELab, including:

  • Payment processors (Stripe and app stores) to process subscriptions and purchases.
  • AI and voice providers (OpenAI, DeepSeek, Retell, Vapi, and ElevenLabs) to process prompts, transcripts, and voice interactions. During a voice conversation, your microphone audio is streamed in real time to our voice provider (ElevenLabs, using the LiveKit real-time audio transport) to generate the simulated patient's responses.
  • Email delivery providers to send account and support communications.
  • Product-analytics and error-monitoring providers (PostHog and Sentry) to understand how the service is used and to keep it reliable. These receive usage events and a stable identifier (such as your account ID or email), but not your learning content.
  • Infrastructure providers that host and secure our services.

We may also share information if required by law or to protect the safety and integrity of our services.

Sensitive information

OSCELab is for education and exam preparation. Please avoid submitting real patient identifiers. If you choose to include sensitive information in your inputs or uploads, it will be processed and stored as part of your learning activity.

Data retention and choices

We retain information for as long as your account is active or as needed to provide the service, comply with legal obligations, and resolve disputes. You can update your profile and control notification permissions in your device settings. You can delete your account from the Profile page in OSCELab. For access or correction requests, contact us at [email protected].

Our legal basis (UK/EU users)

Where the UK or EU GDPR applies, we process your information to perform our contract with you (providing the service, marking, feedback and managing your plan), for our legitimate interests (keeping the platform reliable, secure and continually improved), with your consent (for example, optional analytics cookies and voice recording), and to comply with our legal obligations. Where processing is based on consent, you can withdraw it at any time.

International data transfers

We operate from Australia and use service providers located overseas, including in the United States (for example OpenAI, Retell, Vapi, ElevenLabs, LiveKit, Stripe, Sentry, and our hosting and email providers), the European Union (our product-analytics provider, PostHog), and — for some AI text processing — in China (DeepSeek). This means your information may be transferred to, stored in, or processed in countries whose data-protection laws differ from your own. Where required, we put appropriate safeguards (such as standard contractual clauses) in place for these transfers. If you would prefer your data not be processed by a particular provider, contact us before using the related feature.

Voice recordings

Voice-based simulated patients need access to your microphone. When you start a voice conversation, your audio is streamed in real time to our voice provider to generate responses, and a transcript is stored as part of your learning activity for review and scoring. By starting a voice conversation you consent to this processing. You can use the rest of OSCELab without voice features.

Cookies and similar technologies

We use cookies and similar technologies that are strictly necessary to run the service (for example, to keep you signed in and to keep the site secure). We also use limited analytics and error-reporting telemetry to understand reliability and improve OSCELab. Where the law requires consent for non-essential cookies, we ask for it through our cookie banner, and you can change your choice at any time. You can also block or delete cookies in your browser settings, although some features may stop working as a result.

How we protect information

We use reasonable technical and organisational measures to protect your information, including encryption in transit, access controls, and reputable infrastructure providers. No method of transmission or storage is completely secure, so we can't guarantee absolute security. If we become aware of a data breach likely to cause serious harm, we will notify affected users and the relevant regulator as required by law, including under the Australian Notifiable Data Breaches scheme.

Your privacy rights

Depending on where you live, you may have rights to access, correct, update, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. You can update your profile and delete your account from the Profile page in OSCELab. To make any other request, email us at [email protected] and we will respond within the time the law requires. If you are in Australia and aren't satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au); in the UK, to the Information Commissioner's Office (ico.org.uk); in the EU, to your local data-protection authority.

Children and young people

OSCELab is intended for users aged 18 and over. If you are under 18, you may only use OSCELab with the involvement and consent of a parent or guardian who agrees to our Terms on your behalf. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information without appropriate consent, contact us and we will delete it.

Contact

Questions about privacy? Email us at [email protected].

We use essential cookies to run OSCELab and optional analytics to help us improve it. Privacy Policy