Privacy Policy
Effective August 9, 2026 · operated by 1581455 B.C. LTD.
What 1581455 B.C. LTD. (“WhiteCoat Prep”, “we”) collects when you use whitecoatprep.com, why, who else handles it, how long we keep it, and what you can make us do about it. Section 13 says who we are and how to reach us.
1. What we collect
Account information
Signing in happens through Google and nowhere else, so the account details we hold are the ones Google passes to us when you authorise the connection: your name, your email address, and the URL of your profile picture. We never receive your Google password, we do not store passwords of any kind, and we have no way to sign in as you. Alongside that we keep the preferences you set, which product you are practising for, whether you have opted in or out of the choices described in section 2 and section 5, and a record of which version of these policies you accepted and on what date. We also keep whatever you choose to tell us about yourself: the schools you are applying to, the cycle you are aiming for, the stage you are at, and optionally your undergraduate institution and degree, whether you have applied before and how that cycle ended, and your MCAT or CASPer results. Every one of those is optional, none of them gates any feature, and you can change or clear them from your profile at any time; we ask because a station chosen for the format you are actually sitting is worth more than a generic one.
Session content
A session generates several kinds of information, and it is worth being specific about each. There is the transcript, a written record of everything you and the AI interviewer or patient said to each other. There are the delivery observations, written notes generated from your video about how you came across, covering pacing, composure, eye contact and body language; these are prose rather than a score or a biometric template, and they are stored as text in our database. There is the feedback and the scores, the structured assessment generated from the transcript and those observations, which is what you read on your results page. There is the recorded video and audio of the session itself, showing and capturing you as you answer, and because it is whatever your camera and microphone pick up it may also include your surroundings and anyone else in the room or audible nearby; recordings are stored encrypted, both in transit and at rest, in infrastructure we control, and are visible only to you and to the small number of our staff who need access to run and support the service. And there is the session metadata, meaning timestamps, format, station count, which questions you were shown, and whether you finished; we track which questions you have already seen so that we do not put the same one in front of you twice.
Payment information
Purchases are processed by Stripe, which handles the card details directly. What reaches us is a record that a purchase happened: what was bought, when, the amount, the currency, and a Stripe reference we can use to reconcile the transaction or issue a refund. We never receive or store your full card number, its expiry date, or its security code, and we could not retrieve them if we wanted to.
Technical information
Our servers keep ordinary web logs, meaning IP address, browser type, the pages requested and the time of each request, which is what makes it possible to investigate an outage, trace an error, or notice that an account is being attacked. We also keep a small number of records for fraud prevention, including a device marker that stops the one free trial per person from being taken repeatedly through new accounts. The full list of cookies and similar technologies, what each one does, and how long it lasts, is on the cookie preferences page rather than summarised here, so that it cannot fall out of date relative to what is actually set.
2. Why we use it, and our legal basis
Canadian law does not require us to publish a basis for each use, and this table is not a claim that European law governs us; section 6 says where we operate and who the service is for. We publish it anyway, because naming the reason a use is permitted is the plainest way to say why it happens, and a table you can check line by line is worth more than a paragraph asking you to take it on trust.
| Purpose | Basis |
|---|---|
| Signing you in and keeping your account | Performance of our contract with you |
| Running sessions and generating your feedback | Performance of our contract |
| Processing your face and voice to assess delivery | Your explicit consent, given at account creation and withdrawable |
| Showing your history and avoiding repeat questions | Performance of our contract |
| Taking payment and keeping financial records | Contract; legal obligation |
| Security, fraud and abuse prevention, debugging | Our legitimate interest in a working, unabused service |
| Improving the service, our question bank and our AI systems | Legitimate interest, you can opt out |
| Licensing your session recordings to organisations building AI systems (section 5) | Your explicit consent, off by default, and withdrawable |
| Answering your emails | Legitimate interest |
Improving the service, and how to opt out
We may use session content, including transcripts and the written delivery observations, to improve how the product works: to find weak questions, calibrate scoring, and develop and improve the AI systems behind it. You can turn this off in your profile, at any time, without losing any feature of the service. Turning it off applies from the moment you set it.
Automated decision-making: how a result is produced, and what it does not decide
Your scores and your written feedback are generated by artificial intelligence, with no person reading them first. That is automated decision-making in the sense several privacy laws use the phrase, and you are entitled to know it is happening whether or not the law where you live says so. What the model is sent is the question or case you sat and the marking rubric that goes with it, the transcript of what you and the AI interviewer or patient said to each other, and, where your session produced them, the delivery observations written from your video that section 1 describes. That is the whole of the input. Your name, your email address, the profile details you gave us, your purchases, and every session you have sat before are not part of it: each session is marked on its own evidence, by a model told nothing about who you are.
What it decides is nothing. The output is practice feedback: it is never sent to a school, a programme, an employer or an examining body, and no decision about your admission, your price, your credits or your account is made from it, by us or by anyone else. It is not a measurement either. The Legal Disclaimer sets out what that means in practice, including that the same answer scored twice may not come back the same, and it is worth reading before a number changes how you feel about your chances.
If a result looks wrong to you, write to privacy@whitecoatprep.com. Being straight about what happens then: nobody re-marks a session by hand, there is no appeal and no second opinion, and we are not going to describe a review process we have not built. What a person can do is tell you how the result was produced, and delete that result, or the recording behind it, if you ask, on the terms in section 7. And if we ever start using automated processing to make a decision that genuinely affects you, this section changes before that happens, not after.
Advertising measurement, and how to opt out
We buy advertising to reach applicants, and ad-platform cookies (Google, Meta, Reddit) tell us which ads led to a sign-up or purchase and let us show ads to people who visited these pages. The conversion events we send name only the fact of the event, a sign-up happened, or a purchase happened and its amount, never what you practised or how it went. Under California law this is “sharing” personal information for cross-context behavioural advertising, so it comes with a real opt-out: the Advertising toggle in cookie preferences or your profile, or a Global Privacy Control signal, which we honour automatically. In Quebec these cookies start off, as Quebec’s Law 25 requires, and run only if you switch them on. What ad platforms never receive, by design: your transcripts, recordings, delivery observations, scores, feedback, or anything you say in a session. Pixels do not load on session, review, or history pages at all, and we never build an ad audience, lookalike or otherwise, from session content or performance.
Analytics, and how to opt out
We use Google Analytics to understand how people move through the site: which pages lead to a sign-up, where people stop, and how often a session fails to start. Unlike the advertising cookies, analytics does run while you are sitting a session, because where people give up is most of what we need to fix. What Google receives is the shape of the visit, meaning which page, which station number and how long, with identifiers stripped out of the address before anything is sent, so it can be told that somebody reached station three and never which session that was. Where you have told us, it also receives two coarse facts about your cohort: roughly what stage you are at, meaning pre-medical, medical student, or resident, and which application cycle you are aiming for. Those describe a group rather than a person, which is why they are the only profile details that go, and the schools you listed are deliberately not among them. It is never sent your transcripts, your scores, your answers, or the questions you were asked. You can switch it off with the Analytics toggle in cookie preferences, a Global Privacy Control signal turns it off automatically, and in Quebec it starts off and runs only if you switch it on.
What we do not do: build behavioural profiles from your sessions, or disclose your sessions to your school, programme, employer, or any admissions or examining body, not for any price, and not on request from them. Nothing you do here is reported to anyone who decides your future. The one circumstance in which your session content goes to an outside organisation for its own purposes is the licensing programme in section 5, which is off until you switch it on.
3. Who else handles it
We keep this list short on purpose. Each of these is a processor doing a specific job, and the third column is where it does that job, because a list that does not say so leaves the most consequential fact out.
| Who | What they do, and what reaches them | Where |
|---|---|---|
| Amazon Web Services | Hosting, the database, and encrypted storage of session recordings. Holds everything in section 1 that we hold ourselves. | United States (US East) |
| Sign-in. Confirms who you are and passes us your name, email and picture URL. privacy policy. | Global | |
| Tavus (built on Daily.co) | Live AI video, transcription and delivery analysis. Receives your live audio and video during a session. privacy policy. | United States |
| OpenRouter, routing to Google (Gemini) | Feedback and scoring. Receives your transcript text and delivery observations. OpenRouter is a gateway: it passes what we send to the model provider behind the model we ask for, today Google’s Gemini, so both organisations handle that text. Whether either retains or trains on it depends on account-level settings and provider terms we have not yet confirmed, so we do not make a promise about it here; when we have confirmed them this row will say so. OpenRouter privacy policy. | United States |
| Stripe | Payments. Takes your card details directly; we receive only the transaction record. privacy policy. | United States and global |
| Loops | Email. Sends everything that reaches your inbox, from receipts to the notice that your feedback is ready, and holds your name and email address to do it, along with a record of which of our emails you have been sent. Never session content. privacy policy. | United States |
| Sentry | Error diagnosis. When something breaks, receives the report we would otherwise only have in a log file: your IP address, your browser and the details of the request that failed, and which signed-in account hit it. Only on errors, never on an ordinary page, and never session content. privacy policy. | United States |
| Google Analytics | Measurement of how the site is used. Receives page addresses with identifiers removed, and the two cohort facts in section 2. Never session content. privacy policy. | Global |
| Google Ads, Meta, Reddit | Advertising measurement. Receive page visits on marketing pages and the fact of a sign-up or purchase, never session content. Set only with your consent, and never on session pages. | Global |
Every organisation above is a processor: it handles your information to do a job for us, under contract, and may not use it for its own ends. That is a different relationship from a licensee under section 5, which does receive data for its own purposes, which is exactly why licensing is opt-in and this is not.
We may also disclose information if the law requires it, to enforce our Terms, or to protect someone's safety. If our business is ever sold or merged, your information may transfer with it; we would tell you first, and this policy would continue to apply until replaced.
4. Face and voice, biometric information
This section matters more than the rest, so it is separate. To hold a real-time conversation with you and to tell you anything useful about how you came across, our video provider Tavus processes your facial geometry and your voice while a session is live, and in some places, including Illinois, Texas and Washington in the United States, that processing is regulated as biometric information. We therefore ask for your explicit, separate consent before your first session and we record that you gave it; you are not required to consent, but the service genuinely cannot work without it, because there is no version of a live video interview that does not involve a camera reading your face. What that processing is used for is narrow: running your session and generating your feedback. It is not used to identify you, and it is not matched against any other person or against any database. We do not generate or store a biometric identifier or template of any kind, meaning no faceprint, no voiceprint, and no mathematical representation of you that could be matched against anybody else; what we keep is the recording itself, the transcript, and prose observations about your delivery. We are conscious that a recording of your face and voice is, in some of those jurisdictions, capable of being treated as biometric information in its own right, and that is precisely why we ask for consent separately, keep the recording encrypted, and never license it without a second and entirely separate opt-in of the kind described in section 5. Tavus's own retention of biometric data is governed by its policy, which states that it is kept until the purpose is satisfied or one year after your last interaction, whichever comes first. You can withdraw your consent at any time by deactivating your account from your profile or by emailing us, and that is the only mechanism there is: because a session cannot run without this processing, withdrawal is the end of the account rather than a checkbox beside it, and we would rather name the real door than describe one that is not there. Withdrawing stops any future processing; it does not undo sessions you have already completed, though you can ask us to delete their results. Finally, where a law prohibits profiting from biometric data outright, Illinois' Biometric Information Privacy Act being the strictest example, section 5 does not operate at all regardless of what you have opted in to. How long each of these is kept, and how it is destroyed, is set out separately in our biometric data retention and destruction policy, which is its own public document because Illinois requires it to be one.
5. Licensing session recordings, opt-in
We license session recordings to organisations that build and evaluate artificial intelligence systems, and we are paid for it. Under California law this is a sale of personal information, and we are calling it that rather than hiding behind a softer word.
It is off unless you switch it on. Every account starts with it off, it is a separate switch in your preferences, it is never bundled into accepting these policies, and it is never a condition of anything. Your price, your credits, your feedback and every feature are identical either way. We would rather you said no than felt manoeuvred into yes.
What a licensee would receive
If, and only if, you opt in, a licensed record may contain:
- The video and audio recording of your session, in which you are visible and identifiable.
- The transcript, the delivery observations, and the feedback and scores.
- Session metadata: format, station type, question or case, timings.
What is never included: your name, email address, profile picture, payment records, or account identifiers. Those are stripped before anything leaves. We recognise this does not make you anonymous, your face and voice are in the recording, and pretending otherwise would be dishonest. Treat opting in as a decision to be personally identifiable to a licensee.
What they may and may not do with it
- They may use it to train, fine-tune, evaluate and benchmark AI systems. This is the point of the programme.
- Our licence terms prohibit using it to identify you, to build a biometric or facial-recognition system, to contact you, to make any decision about you, or to publish or broadcast you. Sub-licensing is restricted and onward sale is not permitted.
- Licensees are contractually bound to delete records we withdraw, on the timetable below.
Changing your mind
You can switch this off whenever you like, from the same place you switched it on. From that moment nothing further is licensed, and we notify every licensee that already holds your records and require deletion within 30 days.
Being straight with you about the limit of that: we can require deletion and we do, but a copy that has already been delivered has left our control, and a model that has already been trained on a recording cannot be made to forget it. If that possibility is unacceptable to you, and it is a perfectly reasonable thing to find unacceptable, leave this switched off. That is the honest reason to decide up front rather than to try it and revoke later.
Who is excluded regardless of what they have clicked
- Anyone who has not separately confirmed that they are 18 or older. We do not ask for your date of birth, and we would rather not hold one, so this is a confirmation of its own rather than something we work out from a record we keep. An account that has not given it is excluded whatever else it has agreed to, and an account that has never been asked counts as not having given it. Where the age of consent for this kind of processing is higher than 18 where you live, that higher age applies.
- Anyone whose browser sends a Global Privacy Control signal, which we honour as an opt-out request in its own right.
- Anyone in a jurisdiction whose law does not permit it, including the biometric statutes named in section 4.
- Any session predating your opt-in that you have asked us to exclude.
We keep a dated, versioned record of exactly what each person agreed to and when, and no export can select a user who is not in that record. If we cannot evidence your consent, you are not in the dataset.
6. Where your data goes
We are a British Columbia company, but our servers and every processor in section 3 are in or route through the United States; our own infrastructure, meaning the application, the database and the encrypted recording storage, runs in Amazon Web Services' US East region in Northern Virginia. Your information is therefore stored and processed outside Canada. Note that your personal information may be available to the United States government or its agencies under legal process made in the United States. There is no version of this service today in which that is not true, so we say it here plainly rather than leaving you to infer it, and by using the service you understand that the transfer takes place.
Every organisation in section 3 handles your information under its terms with us, which permit it to use that information only to provide its service to us and not for its own ends. We are not going to name a specific cross-border transfer mechanism until we have confirmed, processor by processor, which one each of them relies on; when that is done this section will say so. We have no European or United Kingdom infrastructure. The service is built and sold for applicants in Canada and the United States and is not directed anywhere else; if you are in the United Kingdom or the EEA and use it anyway, we are not going to turn you away, and what this policy describes is what happens to your information, in the United States, under the terms above.
7. How long we keep it
- While your account is open: your account details, session history, transcripts, delivery observations, and feedback are kept so you can review your progress.
- Recordings are kept for 3 years from the session, then deleted. That period is set by the strictest rule that applies to us: Illinois’ Biometric Information Privacy Act requires destruction once the purpose is satisfied or within three years of your last interaction with us, whichever comes first, and we apply it to everyone rather than only to Illinois. The full schedule, and how destruction actually happens, is in our standalone biometric data retention and destruction policy. To have an individual recording deleted sooner, email privacy@whitecoatprep.com. Deleting a recording does not delete the feedback built from it; your progress record survives.
- Licensed records: if you opted in to section 5, the copy held by a licensee is governed by our licence agreement with them, which requires deletion within 30 days of us withdrawing the record. Our own copy follows the retention rule above like any other.
- Consent records (what you agreed to, when, and against which version of this policy) are kept for 7 years after your account closes. They outlive the data they describe on purpose: if anyone ever asks whether we had your permission, the answer has to be provable after the recording itself is gone.
- When you deactivate: a 30-day grace period runs, during which you can reactivate and nothing is deleted. After it expires the account cannot be reactivated, and your session content is removed, including asking Tavus to delete its own copy of every conversation so you do not have to chase them yourself. What survives that is listed above: the consent record, and payment records we are required to keep.
- Removing session content on request: you can ask us to remove your session content and delivery observations at any time, whether or not you have deactivated, by emailing privacy@whitecoatprep.com. We remove them within the timeframes in section 8 and ask Tavus to delete the corresponding conversation records on its side.
- Payment records are kept as long as tax and accounting law requires, typically seven years. These are transaction records, not session content, and are retained regardless of any deletion request.
- Web logs, meaning the request and error logs described in section 1, are kept for 30 days and then deleted automatically.
8. Your rights
Wherever you live, you can ask us to: show you what we hold, correct it, delete it, export it in a portable form, or stop a particular use. You can also withdraw consent for biometric processing, by deactivating your account from your profile or by emailing us (section 4 explains why that is the only mechanism), opt out of your session content being used to improve the service (section 2), and opt out of licensing (section 5). We do not discriminate against anyone for exercising these rights, your price, your credits, and every feature stay exactly the same.
Do Not Sell or Share My Personal Information. Licensing under section 5 is a sale, so this right matters here. Because it is off by default, doing nothing already exercises it. Advertising cookies (section 2) are “sharing” and are on by default (off by default in Quebec), so that half of the right takes one action: untick Advertising in cookie preferences, or send a Global Privacy Control signal and it happens without the click. To be certain, open your preferences and confirm the licensing switch is off. We also honour the Global Privacy Control signal automatically, and record that we did, you do not need to make a request as well.
To ask us to delete your data, email privacy@whitecoatprep.com. Deactivating your account in your profile revokes your access immediately and starts the 30-day grace window. For any other rights request (access, correction, portability, an objection, or a complaint about how we handled one), email the same address. Rohit Singla, our Privacy Officer, answers all of them, so there is one door rather than two. We answer within 30 days and may need to verify who you are first, usually by confirming you control the account's email.
If you are in Canada and we have not resolved your concern, you may complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner (in British Columbia, the Office of the Information and Privacy Commissioner for BC). If you are somewhere else, your own national or state privacy regulator is the step after us. We are not going to tell you what any particular one of them can do about a British Columbia company processing in the United States, because we do not know; what we can tell you is that the rights in this section are ones we answer for everybody, wherever you are, on the same terms and in the same 30 days.
10. Children
The service is not for children under 16, and we do not knowingly collect their information. If you believe a child has given us personal information, email us and we will delete it.
The licensing programme in section 5 has a higher bar: 18. A minor cannot opt in, and we do not accept a parent's consent on their behalf for it. Because the account itself only requires you to be 16, that bar is a separate confirmation asked at the point of opting in rather than an assumption made from anything else we hold, and an account that has not given it is excluded. Where the age of consent for this kind of processing is higher than 18 where you live, that higher age applies.
11. Security
How we protect this information, encryption, access control, what our infrastructure looks like, and how to report a vulnerability, is described on the Security page. No system is perfectly secure, and we do not claim otherwise.
12. Changes
We may update this policy. When a change is material, we will notify registered users by email or in-product message at least 14 days before it takes effect, and we will ask you to accept the new version. We record which version you accepted and when.
We will not apply a materially different use to information we already hold without asking you first, a new purpose applies to data collected after you agree to it, not retroactively.
13. Who we are, and who to write to
WhiteCoat Prep is operated by 1581455 B.C. LTD., the organisation responsible for the information described above. General enquiries: feedback@whitecoatprep.com. By post: 106 – 1130 East Broadway, Vancouver, British Columbia V5T 1Y7, Canada.
Rohit Singla, our Privacy Officer, is the person responsible for the protection of personal information here, and answers anything in this policy (what we hold, a correction, a deletion, an export, or a complaint you want answered by a person rather than a form) at privacy@whitecoatprep.com. Quebec’s Law 25 requires that person to be identified by title as well as reachable, which is why the title is here and not only the name: one named individual answers for this, not a department and not a certified programme, neither of which we have.
Questions?
Email feedback@whitecoatprep.com and a human will answer.