Privacy Policy

Last updated: 11 October 2026 · Version 1.0

Your simulated conversations and learning records deserve clear explanations. This policy describes the current handling of information in PhysioCase AI and the connected Clinical Training Lab services, and explains how to ask about or exercise your privacy rights.

Review notice: this policy is a draft. Legal operator details, retention schedules, AI-provider terms and international-transfer safeguards must be confirmed and reviewed before it is relied on as a final legal notice.

1. Who we are and what this policy covers

This policy explains how PhysioCase AI, the AI-supported simulation experience available within Clinical Training Lab (CTL) at clinicaltraininglab.com, handles personal information. It covers visitors, learners, instructors and community members, including chat interactions, feedback, accounts and optional public profiles. Privacy enquiries should be sent to support@clinicaltraininglab.com.

The legal name and registered address of the organisation responsible for this service remain to be confirmed. This published draft must be reviewed and completed with those details, the applicable legal framework and verified service-provider arrangements. It is not a claim of certification or compliance with every privacy law.

2. Information we handle

Account information includes your name, email, sign-in identity and account role. Learning records can include case identifiers, difficulty, scores, generated feedback, completion history, time spent, assignments, course progress and achievements. We also handle content you choose to submit, such as simulated chat messages, diagnostic reasoning, assessment and management plans, community posts, uploads and support requests.

Optional professional profiles can contain a photo, biography, location, clinic information, professional interests, contact details and submitted credentials. Operational records include service events, AI usage metadata, billing references and notification preferences. Hosting, sign-in and payment services may also handle technical identifiers such as network and device information to deliver and secure their services.

3. How simulated chat data is handled

During a standard case interview, the conversation is held temporarily in the open page’s memory. The standard interview does not continuously save a separate transcript to your browser’s persistent storage or to the application database. Leaving, restarting or reloading the simulation can remove that in-page conversation; this does not undo information already sent for processing.

When you send a question, the relevant conversation history and case context are sent to our server-side service and the AI service to generate the simulated patient response. When you request feedback, your conversation and written submission are sent for grading. Saved grading and result records include generated feedback, scores and case information, rather than a dedicated complete interview transcript. Feedback may quote or summarise your interaction, so parts of a conversation can remain in saved feedback.

4. Do not submit real patient information

PhysioCase AI is an educational simulator, not a patient-record system, medical consultation or confidential clinical reporting channel. Use the fictional case provided. Do not enter real patient names, contact details, record numbers, identifiable photographs, health records or combinations of details that could identify someone. Do not include passwords or full payment-card details.

Clinical language about a fictional patient is not permission to upload sensitive information about a real person. If you accidentally submit identifiable or confidential information, stop sharing it and contact support with the case identifier and approximate time, without repeating the sensitive information. We will assess the request and available removal steps; information already processed or copied elsewhere cannot always be recalled.

5. AI processing, recipients and model training

The core patient simulation and mentor feedback currently use Google Gemini through Lovable AI Gateway. The gateway and underlying AI provider process the input necessary to generate a response, including conversation text, case context and your submitted reasoning. Your sign-in token is used by our service to authorise the request; the core AI prompt does not require your account name or email. Avoid identifying yourself in free-text submissions.

The application records AI usage metadata such as account identifier, function, model, token counts, response status and duration. These usage records are not a separate full chat transcript. Technical error diagnostics can contain service responses or excerpts, and providers may maintain operational or security logs under their own arrangements.

This policy does not grant permission to use your private submissions for unrelated model training. Provider-specific training restrictions, prompt retention, gateway logging and processing locations require contractual verification; we do not claim that all providers retain nothing or that every diagnostic copy is immediately erased. Contact support for the current verified processing arrangements before submitting information requiring special confidentiality.

6. Purposes and legal bases

We use information to operate accounts, deliver simulations and feedback, maintain progress, administer purchases and assignments, provide community features, answer support requests, prevent abuse and understand use of the service. Applicable legal bases may include performing the service contract, compliance with legal obligations, proportionate legitimate interests where recognised, and consent where required.

The appropriate basis depends on the processing, your location and any institutional arrangement. Where consent is required, accepting general terms or this notice is not a substitute for obtaining it. You can withdraw consent for consent-based processing without affecting earlier lawful processing. Optional marketing is separate from providing your purchased service.

7. Who can access learning information

Your private scores and feedback are not made public merely because you use the platform. Authorised staff may access records when needed for support, service administration, security or review. An authorised instructor or institution may see participation and performance linked to the learning they are permitted to manage. Group or live-session features may display participation or standings to their intended audience.

An AI score is a formative educational aid, not a medical diagnosis or an independently validated decision about fitness to practise. If an institution uses learning records for consequential assessment, ask it about its own privacy notice, oversight and appeal process. You may report inaccurate records or disputed feedback to CTL support.

8. Public profiles and community content

Community posts and profile information are visible to the audience of the feature where you publish them. A published CTL achievement record or professional profile can be reachable by direct link. Directory listing and search-engine indexing are separate settings: leaving the directory does not by itself make a published profile private. Optional field controls determine which professional details are displayed.

Public content, achievement links and QR codes can be copied, shared or indexed. Search engines and other people may retain copies after a change or removal. Review your settings before publishing, and contact support for profile withdrawal or removal requests. Do not post another person’s confidential information.

9. Service providers and other disclosures

We use Lovable Cloud for application hosting, account and database services, Lovable AI Gateway and Google for core AI processing, Stripe for supported payments, and email delivery services for account and notification messages. Brevo is used for marketing campaigns where applicable. Providers receive the information needed for their role. Payment-card details are entered through the payment provider rather than in simulation chats; CTL keeps billing and entitlement references.

Information may also be disclosed to an institution you participate through, at your request, or where necessary and lawful to meet legal duties, respond to a valid authority request, investigate abuse or protect rights and security. If an organisational transfer occurs, any transfer of personal information must be subject to applicable safeguards and notice requirements. External websites, Google sign-in, payment pages and WhatsApp links have their own privacy practices.

10. Cookies, browser storage and analytics

Sign-in sessions, language and interface preferences may use browser storage or functional cookies. Live-room guest tokens can be stored locally to let a participant rejoin. The platform’s own funnel measurement uses a persistent anonymous browser identifier and session markers to record steps such as visits, sign-up, case starts, completion, offer views and purchases; signed-in events may be associated with an account. This is pseudonymous measurement, not a guarantee of anonymity.

You can clear or block cookies and browser storage through your browser, although sign-in, preferences or live-room rejoining may then stop working. Clearing browser storage does not delete saved account records and a new measurement identifier may be created on a later visit. Where non-essential tracking requires consent or an opt-out under applicable law, the required controls must be provided; this notice itself is not consent. Contact support with an objection or question about measurement.

11. Data retention and deletion limits

Temporary standard interview history lasts in the current simulation page’s memory as described above. Saved feedback, case results, course progress, account records and community content remain in the service unless removed through an applicable process. No universal automatic deletion period is currently specified for these records or for AI usage logs. Do not assume that inactivity, signing out, cancelling payment or closing a tab deletes them.

Retention must be limited to what is needed for the purpose, applicable legal or accounting requirements, security, fraud prevention and resolving disputes. The detailed retention schedule, backup expiry and provider-specific periods remain to be confirmed and documented. Ask support about a particular record or request deletion; we will assess it under applicable law rather than promise an unsupported number of days.

Deletion can require separate handling across account, learning, community, billing, technical logs and providers. Some records may be retained lawfully, restricted or anonymised rather than erased immediately. Backups and third-party copies may persist under separate retention arrangements. A browser reset or account-profile deletion is not proof that every associated record has been erased.

12. Your privacy rights and how to exercise them

Depending on the law that applies, you may have rights to know how information is used, obtain access or a copy, correct inaccurate data, request erasure, restrict processing, receive eligible data in a portable format, object to certain processing and withdraw consent. You may also complain to the competent data-protection authority. These rights have legal conditions and exceptions; they are not waived by using CTL.

Email support@clinicaltraininglab.com from your account address with the subject “Privacy request” and specify the right or records concerned. Do not send passwords, patient data or card details. We may request proportionate identity verification, clarify scope and explain any lawful refusal or retained records. Requests will be handled within applicable statutory deadlines; this draft does not invent one deadline for every jurisdiction.

You can use available profile and notification settings for supported changes. For account closure, data export or deletion not available in the interface, contact support. Mention any active subscription so billing cancellation and data deletion can be coordinated; one request is not automatically proof that the other has been completed.

13. Email preferences

Account security, purchase and essential service messages are different from optional community digests and marketing. Use notification settings or the unsubscribe mechanism in an optional email where provided, or contact support. Opting out of marketing does not necessarily stop security, receipt or essential billing messages.

Marketing campaigns, including those sent through Brevo, may record delivery, opens or link clicks according to campaign settings and provider practices. Consent or another valid legal basis must apply where required. Signing up or purchasing is not, by itself, blanket consent to unrelated promotions.

14. International processing

Our hosting, AI, payment and email providers may process information outside your country, where privacy laws can differ. This draft does not promise storage exclusively in Lebanon, the European Union or any other territory; exact processing regions and contractual transfer safeguards require verification.

Where applicable law requires safeguards for an international transfer, appropriate measures such as approved contractual clauses or another recognised mechanism must be in place. Contact support to request the verified locations, recipient details and applicable safeguards for your use or institutional requirements.

15. Security and younger users

The service uses authenticated access, permission controls and server-side handling of AI credentials. These measures reduce risk but do not guarantee absolute confidentiality, uninterrupted availability or immunity from security incidents. Protect your account, use your own credentials and report suspected exposure promptly. If an incident requires notice to users or authorities under applicable law, those duties apply.

CTL is intended for educational use by physiotherapy learners and professionals, not unsupervised use by children. Where a minor participates lawfully through a guardian or institution, the required permissions and protections must apply. Contact support if you believe a child’s information has been collected without the necessary authority.

16. Updates and interpretation

The date and version identify this policy. Material changes to data practices will require appropriate notice and, where necessary, additional consent. An update does not retrospectively authorise a new use of information without a lawful basis. English and French versions are intended to describe the same practices; contact support about discrepancies. Mandatory privacy rights always apply.

Contact support@clinicaltraininglab.com. Do not include patient information, passwords or payment-card details.