Privacy Policy
Last updated: August 2026
DRAFT. Attorney review pending.
This document is a working draft, has not been reviewed by counsel, and is not legal advice. Legal entity, contact address, and governing-law state are placeholders pending finalization.
1. Who we are
OutLoud MD (the "Service"), operated by IsraeliTech, is an AI-powered study simulator for the oral board exam in emergency medicine. This policy explains what data we collect, how we use it, and your rights.
2. Information we collect
Information you provide directly
- Account details: name, email address, and a hashed password when you register and sign in.
- Google sign-in: if you choose to sign in with Google, we receive your name and email address.
- Chat conversations: the messages you send to the AI examiner during a practice session.
- Voice recordings: if you choose to speak instead of type, your recording is sent for speech-to-text processing (see Section 4).
- Practice results: scores, phases completed, cases practiced, and feedback received.
- Cases you create: content is stored if you author your own clinical cases.
- Feedback: ratings and comments on the examiner, on cases, and on individual answers, and survey responses.
- Support inquiries: the content of messages you send us.
- Other information you choose to provide: such as profile details, preferences, and settings.
Information collected automatically
- IP address: for security and abuse prevention.
- Device information: browser type and operating system (in session data).
- Usage events: actions such as sign-in, session start, and case completion, collected via PostHog (hosted in the EU).
- Service logs: records of requests and queries for performance monitoring, quality improvement, and security.
3. How we use information
- Providing the Service: processing your questions, running the practice session, and storing history, scores, and feedback.
- Quality improvement: reviewing conversations and feedback to improve examiner accuracy and case quality.
- Security: rate limiting and abuse prevention.
- Analytics and error monitoring: understanding usage patterns, diagnosing technical errors, and improving product performance only. We do not use analytics for any other purpose.
- Communication: service updates and responses to support inquiries.
Educational use only: the Service is a study tool and does not provide medical advice. See our Terms of Service for the full limitations.
4. Conversation and voice data
- Your chat messages are stored in our database to preserve your session history.
- Conversations are sent to third-party AI providers for processing (their terms apply).
- Voice recordings are sent to third-party speech-to-text providers for transcription (if you use voice input).
- Text the examiner speaks is sent to third-party text-to-speech providers to generate audio (if you use narration).
- We may review conversations to improve the Service and case quality.
- Conversation content is retained for a limited period for quality improvement, fault monitoring, and usage-cost tracking.
- Conversations and recordings are not sold to third parties.
- AI providers may retain conversation content for a limited period to monitor abuse, per their own terms.
5. Third-party service providers
We share information with service providers to operate the platform:
| Provider | Purpose | Data |
|---|---|---|
| AI language-model providers | Natural-language processing (the examiner) | Conversation content, case context |
| Speech-to-text providers | Transcribing voice to text | Voice recordings |
| Text-to-speech providers | Generating audio narration | Text to be spoken |
| Neon PostgreSQL (US) | Database storage | All stored data |
| PostHog (EU) | Product analytics and service logs | Usage events, conversation content |
| Google OAuth | Sign in with Google | Name, email |
| Resend | Transactional email delivery | Email address, message content |
| Vercel | Hosting and web servers | IP address, request data |
| Others | Supporting services as needed | As operationally required |
We do not sell your personal information to third parties, nor do we share data with third-party advertisers or data brokers.
6. International data transfers
Your information may be stored and processed in more than one country:
- Database: Neon PostgreSQL (US).
- Analytics: PostHog (EU).
- Hosting: Vercel (global network).
- AI, speech-to-text, and text-to-speech: third-party providers (servers may be in the US, EU, and elsewhere).
We work to ensure our service providers meet accepted data-protection standards.
7. Data retention
- Authentication sessions: expire after 7 days.
- Practice history: retained until you request deletion.
- Scores and results: retained to track your progress.
- Cases you create: retained until you delete them or request account deletion.
- Analytics events: retained for a limited period.
- Service logs: retained for service improvement and security.
8. Your rights
Depending on your state of residence, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of marketing communications:
- Access: review the personal information we hold about you.
- Correction: correct inaccurate information.
- Deletion: request deletion of your information.
- Opt out: unsubscribe from marketing email at any time.
To exercise your rights, contact us at support@outloudmd.com. We will respond within a reasonable time. Deletion requests are handled promptly, except for information we are required to retain by law. We will not discriminate against you for exercising these rights.
9. Data security
- Data is stored in managed, encrypted databases.
- Passwords are hashed. We do not have access to your password.
- All communication is encrypted with HTTPS.
- Session tokens expire after 7 days.
10. Data breach notification
In the event of a security breach that may affect your privacy, we will:
- Notify affected users as soon as reasonably possible after discovery.
- Report to the relevant authorities as required by applicable law.
- Describe the type of information exposed and the steps taken.
11. Cookies and tracking tools
We use cookies and measurement tools solely for the proper operation of the Service and product improvement, never for advertising or commercial marketing:
- Essential cookies: HTTP-only cookies used for authentication and basic preferences (such as language and theme), required for the Service to function.
- Analytics and fault monitoring (PostHog): internal product telemetry (servers located in the EU) to measure usage, track errors, and improve the learning experience. We do not use this tool for cross-site tracking or targeted advertising.
- No advertising or third-party marketing cookies: the Service does not use ad cookies, social media tracking pixels (such as Meta Pixel), or commercial tracking networks.
- You can block cookies through your browser settings, but blocking essential cookies may prevent you from signing in or using the Service.
12. Children
The Service is not intended for anyone under 18 years of age, and it is not directed to children under 13. We do not knowingly collect information from children under 13.
13. Changes to this policy
Updates to this policy will be posted on this page with a revised date. Material changes will be communicated by email.
14. Governing law
This policy is governed by the laws of the State of Israel, without regard to its conflict-of-laws rules.