Back to home

Legal

Privacy Policy

How we collect, use, and protect your personal information on SimPatient.

Effective 5 June 2026 · Version 2.1 · Applies to simpatient.co.uk and app.simpatient.co.uk

1. Introduction

SimPatient ("SimPatient", "we", "us", "our") provides an AI-powered medical training simulation platform that enables learners to practise clinical communication with virtual patients in text, audio, and video modes.

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy applies to:

If you are using SimPatient as part of a university, NHS organisation, or other institution, that institution is the Controller of your personal data for the purposes of the simulation service, and SimPatient acts as a Processor on its behalf. Where you have signed up directly as an individual, SimPatient is the Controller.

2. Who we are

SimPatient is operated by St Andrews Medical Innovations Limited (trading as SimPatient), a company registered in Scotland (SC705314).

3. Scope and summary

At a glance:

4. Personal data we collect

4.1 Data you provide directly

CategoryExamplesWhen collected
Account dataFull name, email address, password (hashed), profile image, user role, organisation membershipSign-up, profile updates, institutional invitations
Authentication dataSession tokens, multi-factor one-time codesLogin flow
Consultation dataChat transcripts, audio recordings (where audio mode is used), video session data (where video mode is used)Your use of the simulation
Reflection dataFree-text reflection answers after each consultationReflection step of the case flow
Feedback dataAI-generated feedback on your consultation (strengths, improvements)Generated by our AI layer
Support dataIn-app feedback, bug reports, screenshots you choose to attachOptional feedback widget
CorrespondenceEmails you send us, and our repliesDirect communication

4.2 Data collected automatically

CategoryExamplesNotes
Device and log dataIP address, user agent, browser type, timestampsCookies and similar technologies
See section 11 below
Usage dataWhich cases you open, session duration, credit consumption
Consent recordsPolicy version you accepted, timestamp, IP address, user agent (kept as an audit trail)

4.3 Data we do not collect

5. Special category data (Article 9)

SimPatient generates synthetic clinical scenarios. Simulated patient personas and the medical content within them are fictional and are not the personal data of any real person.

Your use of the platform may produce content that resembles health data (because you are practising clinical consultations). Because this content relates to a simulated patient and reflects your own educational performance, we do not treat it as Article 9 "special category" data about a real data subject.

You are contractually prohibited from entering real patient information, real clinical records, or any identifiable third-party health data into the platform. If you do so inadvertently, contact us immediately at hello@simpatient.co.uk and we will delete it.

We do not rely on the contractual prohibition alone. To reduce the foreseeable risk of real patient data being entered, we apply technical and organisational guardrails, including in-product warnings at the point of input, detection and redaction measures where feasible, and data-protection training for administrators. We assess this risk in our Data Protection Impact Assessment and keep these measures under review.

6. Why we use your personal data and our legal bases

PurposeLegal basis
Creating and managing your account; authenticating you; delivering the simulation serviceContract . Art. 6(1)(b)
Routing consultations through our AI providers to generate responses, voices, and avatarsContract . Art. 6(1)(b)
Storing transcripts and feedback so you can review your progressContract . Art. 6(1)(b)
Keeping the platform secure, preventing abuse, enforcing acceptable useLegitimate interests . Art. 6(1)(f)
Producing anonymised, aggregated analytics for service improvementLegitimate interests . Art. 6(1)(f)
Recording your acceptance of this policy and other consentsLegal obligation . Art. 6(1)(c) / Legitimate interests . Art. 6(1)(f)
Sending transactional emails (invitations, password resets, verification codes)Contract . Art. 6(1)(b)
Sending marketing communications (if you opt in)Consent . Art. 6(1)(a)
Non-essential cookies and in-app feedback widgetsConsent . Art. 6(1)(a)
Complying with legal, regulatory, and tax obligationsLegal obligation . Art. 6(1)(c)
Establishing, exercising, or defending legal claimsLegitimate interests . Art. 6(1)(f)

You can withdraw any consent you have given at any time by emailing hello@simpatient.co.uk or updating your preferences in the app. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.

7. Who we share your personal data with

We share your personal data only with the sub-processors listed below, all of which are contractually bound by Data Processing Agreements and process your data exclusively on EU/UK infrastructure.

7.1 Sub-processors

We use a small number of carefully selected sub-processors (for cloud hosting, database and authentication, AI model inference, voice and avatar generation, transactional email, and in-app support) to deliver the Service. Each is bound by a written Data Processing Agreement, processes personal data exclusively on EU/UK infrastructure, and is contractually prohibited from using your data to train AI models.

A current, itemised list of our sub-processors (including the specific providers, their role, the data they process, and their processing region) is available to customers and prospective customers on request, by emailing hello@simpatient.co.uk. We will notify customers at least 90 days before adding or replacing a sub-processor that handles personal data. Institutional customers may object in accordance with their Data Processing Agreement.

7.2 Other recipients

We may also share your personal data with:

We do not sell your personal data, and we do not share it with advertising networks.

8. International transfers

All sub-processors listed above have committed to processing SimPatient customer personal data on infrastructure located within the European Union or the United Kingdom.

Where a sub-processor is a US-headquartered company (for example, OpenAI, ElevenLabs, Resend, Userback, Vercel, or Google Cloud), your personal data is nevertheless processed exclusively in an EU or UK region under a Data Processing Agreement that restricts the transfer of personal data outside those regions in identifiable form.

In the limited circumstances where a transfer outside the UK/EU becomes necessary (for example, support engineering access), we rely on:

together with supplementary technical measures including encryption in transit (TLS 1.2+), encryption at rest, and role-based access controls. A copy of the transfer mechanism in use for any particular sub-processor is available on request.

9. How long we keep your personal data

We keep your personal data only for as long as necessary for the purposes described in this policy.

CategoryRetention period
Account data (name, email, role, organisation)For the life of your account, plus 90 days after deletion
Consultation transcripts and messages24 months from creation, or the term of your institution's contract, whichever is longer
Audio recordings (held on ElevenLabs)24 months, subject to sub-processor retention policy
Reflection and feedback data24 months from creation
Consent records (audit trail)6 years after the consent was given or withdrawn
Invitation records3 months, or until accepted/revoked
One-time codes (MFA)Up to 5 minutes, then automatically deleted
Activity / session trackingDeleted automatically when a user is inactive beyond the platform threshold
Anonymised, aggregated analyticsIndefinitely (no longer personal data once anonymised)
Support correspondence3 years from last contact

When you request account deletion, we delete or irreversibly anonymise your personal data within 30 days, subject to any legal obligation that requires us to retain specific data for longer (for example, financial records).

10. Your rights under UK GDPR

You have the following rights in relation to your personal data:

To exercise any of these rights, email hello@simpatient.co.uk. We will respond within the applicable time period under the UK GDPR. That period runs from the latest of: the date we receive your request, the date we have verified your identity (where we reasonably need to do so), and the date we receive any fee we are permitted to charge. It is normally one month, extendable by up to two further months for complex or numerous requests (we will tell you if an extension applies).

We may need to verify your identity before acting on a request. This is to protect your data from unauthorised disclosure.

Complaining to us first. If you are unhappy with how we have handled your personal data, we ask that you raise it with us first by emailing hello@simpatient.co.uk, so we have the opportunity to put things right. We will acknowledge your complaint within 30 days of receiving it, keep you informed of our progress, and aim to provide a substantive response within three months. We provide this complaints route in accordance with section 164A of the Data Protection Act 2018.

Complaining to us does not remove your right to complain to the UK's supervisory authority. You may complain to us, to the Information Commissioner's Office, or both:

11. Cookies and similar technologies

We use a small number of cookies and similar technologies:

CookiePurposeTypeLifespan
next-auth.session-token (prod: __Secure-next-auth.session-token)Keeps you signed in across pagesEssentialUp to 30 days
superadmin_tokenAuthenticates super administratorsEssentialSession
pendingInviteTokenCarries an invitation through single sign-on so the right role and organisation are applied when you redeem itEssentialShort-lived (cleared once the invite is applied)
Userback sessionRuns the in-app feedback and bug-report tool for signed-in users (functional support tool, not analytics or advertising)EssentialSession

All of the cookies we currently use are essential: they are strictly necessary to sign you in, keep you signed in, authenticate administrators, apply invitations, and run the in-app feedback and support tool. Under the Privacy and Electronic Communications Regulations (PECR) these may be set without consent. We do not use analytics, advertising, or third-party tracking cookies in the app.

If in future we introduce any non-essential cookies (for example, analytics), we will not set them until you have given explicit consent through a cookie banner that lets you accept or reject them with equal prominence, and you will be able to change your choice at any time.

Full details are available in our separate Cookie Policy at simpatient.co.uk/cookies.

12. Security

We take the security of your personal data seriously. Our measures include:

No system is 100% secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify you without undue delay.

13. Children and age

SimPatient is designed for adult medical learners (age 18+) using the platform in an educational context, either through an institution or as an individual learner.

You must be at least 18 years old to create an account as an individual. Where a learner under 18 uses the platform under institutional supervision (for example, a university or NHS trust), the institution is responsible for obtaining any necessary parental or guardian consent before inviting the learner.

Where any user of the platform is under 18, we treat their personal data as meriting higher protection. We have regard to the heightened protections for children's data under the Data (Use and Access) Act 2025 and to the ICO's Age Appropriate Design Code (the Children's Code), and we assess the processing of any under-18 user's data in our Data Protection Impact Assessment. The UK age at which a child can consent to information society services on their own behalf is 13; we do not rely on a child's own consent as a lawful basis for the simulation service, which is instead provided to institutional learners under the institution's lawful basis.

If you believe a child has provided us with personal data outside an institutional arrangement, contact hello@simpatient.co.uk and we will delete it.

14. Automated decision-making and profiling

We do not make decisions about you that produce legal or similarly significant effects using solely automated means (Art. 22 UK GDPR).

Our platform uses AI models to generate simulated patient responses and educational feedback. These outputs are educational in nature and are not decisions about you that have legal effect. A human (you, and where applicable your tutor) remains in control of any educational evaluation.

The AI-generated feedback is a formative learning aid. It is not designed or intended to be used as an automated assessment, grading, or examination tool, and it must not be used as the sole basis for any academic or professional decision about a learner. Any summative assessment remains the responsibility of the learner's institution and its human assessors.

15. Marketing

Where you have opted in, we may send you occasional emails about new features, product updates, or SimPatient-related educational content.

You can unsubscribe at any time via the link in every marketing email, or by emailing hello@simpatient.co.uk. Unsubscribing from marketing does not affect transactional emails (such as invitations, password resets, and service notices), which you cannot opt out of while you hold an account.

16. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Previous versions are available on request.

17. Contact us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us using the details below.

Contact

St Andrews Medical Innovations Limited (trading as SimPatient) Data Protection Officer: Mr Christopher Milne, Head of Information Assurance and Governance DPO email: dataprot@st-andrews.ac.uk General email: hello@simpatient.co.uk Post: Walter Bower House, Main Street, Guardbridge, St Andrews, Fife, KY16 0US This Privacy Policy is governed by the laws of Scotland.