Home/Privacy Policy/User Agreement

ROSCADEMY Legal

Privacy Policy

This Privacy Policy explains how ROSCADEMY collects, uses, discloses, stores, and protects personal data when you use roscademy.com and related tools.

Last updated: 26 June 2026

1. Who We Are

ROSCADEMY provides medical education, documentation, and AI workflow tools. For privacy questions, contact [email protected].

If you use ROSCADEMY through a hospital, university, employer, training program, or other institution, that organisation may also have its own privacy notices, clinical governance rules, medical-record policies, and data-protection obligations.

2. Scope

This Policy applies to personal data processed through ROSCADEMY, including EMNOTES, EMSCRIBE, EMQBank, ABG Analyzer, Labs, browser extensions, and userscripts.

ROSCADEMY can process clinical notes, patient identifiers, images, and generated medical documentation. You must only enter patient or clinical information where you are authorised to do so and where that use is permitted by your institution, applicable law, and patient confidentiality obligations.

Unless we separately agree in writing, ROSCADEMY is not provided as a HIPAA business associate service and is not intended for use with US protected health information that requires a business associate agreement.

3. Personal Data We Collect

Account and profile data

We collect your name, email address, profile image, account role, app approvals, access-request status, password credentials if you use email/password login, Google OAuth account information if you use Google sign-in, and account/session metadata.

Authentication and security data

We process session tokens, login and logout events, password reset events, IP address, user agent, session expiry information, revoked sessions, audit logs, and administrative security actions.

App access and administration data

We process access requests, app approvals, tier and entitlement settings, administrator review actions, model settings, system settings, and related operational records.

EMNOTES data

If you use EMNOTES, we process notes, document titles, descriptions, markdown or rich-editor content, web sources, uploads, media, revisions, draft/published status, ownership, and catalog preferences.

EMSCRIBE and SOAP Review data

If you use EMSCRIBE, SOAP Review, browser extensions, or userscripts, we may process clinical note text, SOAP sections, impressions, plans, patient workspace data, snapshots, stored analyses, patient names, patient IDs, MRNs, IC numbers, source labels, first-seen timestamps, patient-chat messages, generated summaries, references, and related metadata.

SOAP Review summaries may be keyed by patient identifiers rather than by a ROSCADEMY user account. A normal account deletion may therefore not automatically delete every SOAP Review summary associated with a patient identifier.

ABG Analyzer and image data

If you use ABG Analyzer or image-based tools, we process uploaded or submitted images and extracted or interpreted blood gas values and related output.

EMQBank data

If you use EMQBank, we process question banks, selected topics, practice or exam sessions, submitted answers, scores, feedback, progress, AI essay evaluations, AI vetting results, chat threads, messages, review flags, and admin/editor changes.

Labs and AI chat data

If you use Labs or AI chat features, we process prompts, messages, selected models, model/provider settings, generated responses, request payloads, retrieved references, and thread history.

Reference and retrieval data

Administrators and authorised users may upload, import, crawl, parse, index, and store reference documents, PDFs, images, media assets, metadata, chunks, embeddings, web-search results, and cached search/crawl output for retrieval-augmented generation.

AI usage and provider logs

We log AI interactions, request IDs, app and feature names, selected provider/model, status, timing, token usage, provider call metadata, error codes, and limited error messages. We try to avoid storing raw malformed model output in AI logs when it may contain sensitive prompt content.

Cookies and browser storage

We use cookies and similar technologies required for sign-in, session management, security, and app operation. The app may also store preferences and drafts in your browser local storage or session storage, including theme, sidebar state, selected models, web-search preferences, editor drafts, patient-workspace drafts, chat state, and upload/review UI state.

We do not currently use third-party advertising pixels or third-party behavioural advertising analytics.

4. How We Use Personal Data

  • Create, authenticate, secure, and administer accounts.
  • Provide access to ROSCADEMY apps and related features.
  • Save notes, patient workspaces, chats, question sessions, uploads, references, and user preferences.
  • Generate, stream, evaluate, reformat, retrieve, search, and display AI-assisted outputs.
  • Route requests to configured AI, search, OCR, parsing, email, authentication, and infrastructure providers.
  • Monitor reliability, cost, abuse, rate limits, errors, and security events.
  • Provide password reset, access approval, security, and service emails.
  • Support administrators in managing users, sessions, app approvals, references, models, and settings.
  • Comply with legal, regulatory, professional, contractual, and institutional requirements.
  • Enforce terms, protect ROSCADEMY, investigate incidents, and prevent misuse.

5. Legal Bases and Consent

Depending on where you are located and how you use ROSCADEMY, we may rely on one or more legal bases, including consent, performance of a contract or requested service, legitimate interests in operating and securing the service, legal obligations, protection of vital interests where applicable, or another permitted basis for sensitive health-related data.

If you enter patient or clinical information, you are responsible for ensuring that you have the necessary authority, consent, institutional approval, or other lawful basis to do so.

6. AI Providers, Search Providers, and Other Processors

ROSCADEMY can route prompts, files, images, clinical text, patient context, retrieved references, and generated output to selected providers depending on administrator configuration and user selection.

These providers may include:

  • OpenAI;
  • OpenRouter and model providers available through OpenRouter;
  • LM Studio or other locally hosted model runtimes;
  • Resend for account and access workflow email;
  • Google OAuth for sign-in, if enabled;
  • web-search, crawling, OCR, parsing, and retrieval tools such as Brave Search, DuckDuckGo-style plugins, Fetch tools, Crawl4AI, Docling, MarkItDown, or similar configured services;
  • hosting, database, storage, logging, and infrastructure providers used to operate the app.

Cloud AI and search providers may process submitted content outside your country. Locally hosted providers process content within the infrastructure where they are deployed, but their privacy and security still depend on how that infrastructure is configured.

Do not submit identifiable patient data, confidential institutional data, or regulated health information to an AI or search provider unless you are authorised and the relevant provider arrangement permits it.

7. Disclosure of Personal Data

We may disclose personal data:

  • to service providers and subprocessors that help operate ROSCADEMY;
  • to configured AI, OCR, search, email, authentication, hosting, storage, and infrastructure providers;
  • to administrators who manage users, settings, references, access, security, logs, or app content;
  • to your institution, employer, training program, or authorised representative where required for service administration or compliance;
  • where required by law, regulation, court order, professional obligation, or lawful request;
  • to protect rights, safety, security, and the integrity of the service.

We do not sell personal data or use personal data for third-party targeted advertising.

8. Retention

We retain personal data for as long as needed to provide the service, maintain account and security records, comply with legal or institutional obligations, resolve disputes, and enforce agreements.

  • Account, profile, access, app content, patient workspace, EMQBank, EMNOTES, Labs, and user-linked chat data are generally retained while your account is active unless deleted earlier.
  • Account deletion removes the user account and most database-backed user-linked data through database relationships.
  • AI interaction logs are designed to be cleaned up after 365 days when the cleanup job is run.
  • Authentication audit logs, security logs, server logs, and administrative records may be retained as needed for security, compliance, and incident response.
  • SOAP Review summaries keyed by patient identifiers may remain until separately deleted or overwritten.
  • Files stored in browser local storage remain on your device until removed by the app or your browser.
  • Backups may retain deleted data temporarily until backup rotation completes.

9. Security

We use administrative, technical, and organisational safeguards intended to protect personal data, including authenticated access, app-level approvals, role-based admin access, session controls, hashed external-session tokens, password hashing, rate limits, audit logs, and restricted admin actions.

No internet service, AI system, browser extension, local model runtime, or storage system can be guaranteed to be completely secure. You are responsible for protecting your account, browser, device, external tokens, and any patient or institutional data you choose to submit.

10. Your Choices and Rights

Depending on applicable law and your relationship with ROSCADEMY, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal data.

Within the app, you may be able to:

  • update your display name and profile image;
  • change or set a password;
  • revoke browser-tool or userscript tokens;
  • delete patient-chat messages or user-linked records where supported;
  • delete your account, except for protected administrative accounts.

To request access, correction, deletion, restriction, portability, or other privacy assistance, contact [email protected]. We may need to verify your identity and may be unable to fulfil a request where retention is required by law, security, audit, professional obligations, institutional obligations, backup integrity, or legitimate operational needs.

11. International Transfers

ROSCADEMY may use providers, infrastructure, AI services, or administrators located outside your country. Where required, we take steps intended to support lawful cross-border transfers, such as using appropriate provider terms, contractual protections, access controls, or other safeguards.

12. Sensitive Health and Patient Data

Clinical and patient information may be sensitive personal data. You must not use ROSCADEMY to store or process identifiable patient data unless you are authorised and the use is lawful.

Before submitting patient data, consider whether de-identification, pseudonymisation, redaction, local-only processing, or an institutionally approved workflow is required. You should not submit data that exceeds what is necessary for the clinical, educational, or documentation task.

13. Automated Processing and AI Outputs

ROSCADEMY uses AI models to assist with drafting, summarisation, analysis, search, retrieval, question evaluation, and interpretation. AI outputs may be inaccurate, incomplete, or inappropriate for a specific patient or context.

ROSCADEMY does not make autonomous clinical, employment, legal, or similarly significant decisions about users or patients. Users remain responsible for reviewing AI outputs and making professional decisions.

14. Children's Privacy

ROSCADEMY is intended for authorised medical, educational, administrative, or professional users. It is not directed to children. Do not create an account or submit personal data if you are not old enough to use the service under applicable law or institutional rules.

15. Changes to This Policy

We may update this Policy from time to time. Material changes may be notified through the app, by email, or by another appropriate method.

16. Contact

Privacy requests and questions can be sent to [email protected].