Privacy Policy

Effective Date: March 11, 2026 · Last Updated: March 11, 2026

1. Introduction

Generate Surgery Mock Orals LLC (“we,” “our,” or “us”) operates GenSurgMockOrals.com (the “Platform”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services. By using the Platform, you consent to the practices described in this policy.

2. Information We Collect

Information You Provide Directly

  • Account registration information (name, email address, password)
  • Professional information (residency program, PGY year, specialty)
  • Payment and billing information (processed through Stripe, a PCI-compliant third-party processor)
  • Communications you send to us (support requests, feedback)

Information Collected Automatically

  • Device and browser information (IP address, browser type, operating system)
  • Usage data (pages visited, features used, session duration, practice session performance)
  • Cookies and similar tracking technologies
  • Referral source (how you found our Platform)

3. How We Use Your Information

  • Provide, operate, and maintain the Platform
  • Process transactions and manage your subscription
  • Personalize your experience and deliver relevant content
  • Track your progress and generate performance analytics
  • Communicate with you about your account and updates
  • Improve our Platform, AI models, and educational content
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following limited circumstances:

  • Service Providers: Supabase (authentication & database), Stripe (payment processing), OpenAI (AI examiner), Deepgram (speech-to-text), Pinecone (search), Upstash (rate limiting), and Resend (email delivery). These providers are contractually obligated to protect your information.
  • Legal Requirements: When required by law, regulation, legal process, or governmental request.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
  • With Your Consent: We may share information when you explicitly authorize us to do so.

5. Data Security

We implement reasonable administrative, technical, and physical safeguards to protect your information, including:

  • Encryption of data in transit (SSL/TLS) and at rest
  • Secure authentication via HTTP-only cookies and access controls
  • Regular security assessments and monitoring

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. We may also retain information as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. When your information is no longer needed, we will securely delete or anonymize it.

7. Your Rights and Choices

  • Access and Update: You can access and update your account information through your account settings at any time.
  • Delete Your Account: You may delete your account and associated data through your account settings. Deletion is processed immediately, subject to any legal retention requirements.
  • Opt-Out of Marketing: You can unsubscribe from promotional emails by clicking the “unsubscribe” link in any marketing email.
  • Cookies: You can manage cookie preferences through your browser settings. Disabling cookies may affect Platform functionality.

8. Cookies and Tracking Technologies

  • Essential Cookies: Required for the Platform to function properly (authentication, security).
  • Analytics Cookies: Help us understand how users interact with the Platform (e.g., Google Analytics).
  • Preference Cookies: Remember your settings and preferences for future visits.

9. Children's Privacy

The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will take steps to promptly delete that information.

10. California Privacy Rights (CCPA)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. To exercise these rights, please contact us at support@contact.gensurgmockorals.com.

11. International Users

If you access the Platform from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States. By using the Platform, you consent to this transfer.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. Your continued use of the Platform after changes are posted constitutes acceptance of the revised policy.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at support@contact.gensurgmockorals.com.