Cookie Policy
Last updated: 3 October 2026
1. About this policy
This policy explains the cookies and similar browser storage (local storage, session storage and IndexedDB) used on MedMock, at medmock.com and in the MedMock platform. MedMock is a trading name of VirtualPatients Ltd, a company registered in England and Wales (company number 16303492). Read it with our Privacy Policy, which explains how we use personal data and your rights. In this policy, “cookies” includes that other browser storage.
2. Your choice
The first time you visit, our banner asks whether you accept analytics and advertising cookies. You can accept or decline with one click each. Nothing from Google or Meta loads until you click Accept, nothing optional is switched on before you choose, and if you decline none of it is used.
Your choice lasts 13 months; after that we ask again. You can change it at any time with Cookie settings in the footer of our website, in Profile & Settings when you are signed in, or here: . Withdrawing your consent deletes the analytics and advertising cookies, and our own analytics entries, from your device.
3. Strictly necessary
These are needed for the Platform to work or for features you ask for, so they do not need your consent.
- Sign-in (Google Firebase) — keeps you signed in. Stored by Firebase, our sign-in provider, in your browser’s IndexedDB storage (or local storage if that is unavailable) until you sign out.
- __session — a first-party cookie. When you start a practice case, it lets your browser load that case’s images, and lasts up to 30 days. For organisation, reviewer and staff sign-ins it keeps that sign-in, and lasts up to 12 hours.
- mm_cookie_consent — your cookie choice and when you made it, in local storage, for 13 months.
- Cloudflare Turnstile — short-lived tokens that tell real people from bots on our sign-up, sign-in, password reset, contact and report-a-problem forms. Third party (Cloudflare); they expire within minutes.
- Settings and game scores — mm_examiner_mode, mm_show_mood, mm_autosend_mode, mm_send_delay_ms, mm_delayhint_seen, mm_frcsct_subspecialty, mm_lounge_game, mm_defib_best, mm_oncall_best and selectedExamId remember settings you choose and your best scores in the loading-screen games, in local storage on your device until you change them or clear your browser.
- Practice in progress — mm_station_resume_v1, mm_live_station_v1, mm_live_station_scenario_v1, mm_live_station_draft_v1, premed_mmi_run_v1, cons_full_panel_v1 and fullmock_<exam> entries let you carry on with a station or mock exam after a reload. Most are kept in that browser tab (session storage), which clears them when the tab is closed; mm_station_resume_v1 and a full mock exam’s progress are kept on your device (local storage) and removed when the station or mock ends.
- medmock-referral-draft-v1 — the referral code you type, or arrive with, on the sign-up form, kept in that browser tab (session storage) until it is closed.
4. Analytics (only if you accept)
- _ga and _ga_<id> — set by Google Analytics to tell returning visits apart and measure how the Platform is used. Third party (Google); kept for up to 2 years. If you are signed in, Google Analytics also receives your account’s internal user ID (a random string, not your name or email address), so your use on different devices counts once.
- mm_activated, mm_purchase_<id> and mm_score_recorded_<id> — our own markers, in local storage, that stop an analytics event (your first completed station, a purchase, a recorded score) being counted twice.
5. Advertising measurement (only if you accept)
- _fbp — set by the Meta Pixel to measure whether our advertising on Facebook and Instagram works. Third party (Meta); kept for about 3 months.
- mm_first_touch — how you found us: the website that referred you, the page you first landed on, any campaign labels and, if you came from an advert on ChatGPT, OpenAI’s ad click identifier. Until you accept it is held only in your browser’s memory and never saved; once you accept it is saved in local storage for up to 13 months and, if you then sign up, copied to your account.
6. Your browser’s controls
You can also block or delete cookies in your browser’s settings. Blocking the strictly necessary ones will stop you signing in. Your browser settings may not tell us that you have withdrawn consent, so please use Cookie settings as well.
7. Changes and contact
We will update this policy when the cookies we use change. Questions? Email contact@medmock.com, use our contact form, or write to VirtualPatients Ltd, 2 St. Mary's Road, Tonbridge, England, TN9 2LB.