SimPT ← Back to the simulator

DRAFT — for attorney review before payment features launch.

Drafted 2026-08-05. Bracketed items [like this] are decisions or details to finalize.

Privacy Policy

Effective date: [DATE]

This Privacy Policy explains what information SimPT ("we," "us") collects when you use simpt.us (the "Service"), how we use it, and the choices you have.

The short version: we collect your email to sign you in, your practice encounters to show you your work and improve the Service, and operational logs to keep the Service safe and affordable. We don't sell your data. Simulated patients are fictional — there is no real patient data in SimPT, and you must not enter any.

1. Information we collect

Account information. Your email address (used for passwordless sign-in links), the invite code you signed up with (if any), your account role (e.g., student or clinician), and sign-in timestamps.

Practice activity. For signed-in users: your simulated encounters — transcripts of what you typed, tests you ordered, findings revealed, evaluations you submitted, and the scores and feedback generated. For anonymous play of the public case, encounter state is stored in your browser, not on our servers. [CONFIRM AGAINST BUILD 1 IMPLEMENTATION AT PUBLICATION.]

Feedback you give. Case endorsements, "something was off" reports, and any notes you submit.

Operational data. Server logs (including IP address and request metadata), rate-limit and abuse events, aggregate AI-usage cost accounting, and product events (e.g., case created, case reviewed). We use session cookies (httpOnly) to keep you signed in; we do not use advertising cookies or third-party analytics trackers. [UPDATE IF ANALYTICS ADDED LATER.]

Payment information (when paid plans launch). Payments are processed by Stripe. We receive subscription status and limited billing metadata; we do not store full payment card numbers.

2. What we do not collect

Do not enter real patient information into SimPT. The Service is for fictional simulated encounters only. We do not knowingly collect protected health information, and the Service is not intended to create, receive, or transmit PHI under HIPAA. We do not knowingly collect information from children under 18; the Service is for adults in professional and pre-professional education.

3. How we use information

4. How information is shared

We do not sell personal information. We share it only with:

5. AI processing — plain-language note

SimPT's simulated patients and grading are powered by large language models via the Anthropic API. What you type in an encounter is sent to that API to generate the patient's reply and your scored debrief. We configure this processing for service delivery — [CONFIRM CURRENT ANTHROPIC API DATA-USE TERMS AT PUBLICATION, e.g., API inputs/outputs are not used to train models per Anthropic's commercial terms].

6. Students and FERPA

Individual accounts you create yourself are consumer accounts, not education records maintained by your school. If your institution adopts SimPT with rostering or instructor dashboards, encounter records tied to that program may constitute education records under FERPA; in that case SimPT acts as a service provider to the institution under a written agreement, uses such records only to provide the Service, and looks to the institution for FERPA compliance decisions. [ACTIVATE WITH INSTITUTIONAL FEATURES.]

7. Retention and deletion

We retain account and encounter data while your account is active. You may request deletion of your account and associated personal data at [support email]; we will delete or de-identify personal data within [30] days, except records we must keep for legal, billing, or security purposes. De-identified, aggregate data (e.g., scoring statistics, case-quality metrics) may be retained to improve the Service.

8. Security

Sign-in is passwordless via time-limited email links; sessions are revocable server-side tokens in httpOnly cookies. Data in transit is encrypted (TLS), including database connections verified against a certificate authority. Access to production data is limited to the operator. No system is perfectly secure; we will notify affected users of a breach as required by law.

9. Your choices and rights

You can sign out everywhere (revoking sessions), request a copy of your data, or request deletion at [support email]. Depending on where you live, you may have additional rights (e.g., under state privacy laws); we honor verified requests consistent with applicable law. [ATTORNEY: confirm whether state-specific disclosures (CA, CO, VA, etc.) are required at expected scale.]

10. Changes to this Policy

We may update this Policy; material changes will be announced via the Service or email with an updated effective date.

11. Contact

[support email @simpt.us]
[Entity legal name and address]