Privacy Policy
How account, educational, payment, usage, and support information is handled.
Effective July 28, 2026Information collected
The service may process account information, institution details, roles, cohort and course records, evaluation evidence, audio, optional video, timestamp-selected video frames, transcripts, supporting files, generated scenarios, scores, remediation records, surveys, audit history, device and request information, subscription status, and support communications.
Payment card information is collected and processed by Stripe. Maynard Protocol Systems does not store full card numbers.
First-party product analytics
The service may collect content-free product usage metadata such as account role, an anonymous browser-session identifier, page category, approved action category, outcome, coarse duration bucket, device class, and timestamp. This helps identify confusing or underused workflows.
Product analytics do not record screens, screenshots, keystrokes, names, email addresses, student identifiers, search terms, typed content, transcripts, grades, audio, video, documents, files, or private knowledge content. Fictional demo activity and the platform-owner account are excluded.
How information is used
- Provide authentication, evaluation, reporting, scenario, Comprehensive Scope of Practice, remediation, accreditation, and administrative features.
- Process subscriptions, enforce purchased limits, and provide customer support.
- Secure the service, investigate errors, maintain audit history, and prevent abuse.
- Improve reliability and usability using appropriately limited operational and content-free product information.
Service providers
Information is processed using service providers that may include Supabase for authentication, database, and storage; Render for application hosting; Stripe for billing; OpenAI for configured AI-assisted generation and transcription; and an authorized email provider for transactional messages. Each provider processes information according to its agreement and applicable configuration.
AI processing
AI features are initiated by authorized users. When authorized faculty request targeted video evidence review, the service sends only a small set of timestamp-adjacent still frames rather than the entire video. The application requests non-persistent processing where supported and does not treat AI output as a final academic or clinical decision. Institutions should avoid submitting unnecessary sensitive information and must follow their own privacy and records policies.
Education records and institutional responsibility
Institutions determine what student information is appropriate to place in the service and are responsible for required notices, consent, records policies, and compliance obligations. The platform should not be represented as independently establishing FERPA, HIPAA, accreditation, or other legal compliance.
Retention and deletion
Information is retained while needed to provide the service, maintain required audit and billing records, resolve disputes, and meet contractual or legal obligations. Authorized administrators may request account assistance or deletion review through Support. Some records may be retained when required for security, financial, legal, or institutional audit purposes.
Sharing and sale
Personal information is not sold. Information may be shared with authorized institution users, contracted service providers, or authorities when required by law or necessary to protect rights, safety, and service integrity.
Security and choices
Administrative, technical, and contractual safeguards are used as described in the Security Overview. Users may update account information through authorized administrators and may contact Support regarding privacy questions.
Contact
Submit privacy questions through the Support page.