Privacy Policy

Last updated: 8 September 2026

This Privacy Policy explains how VirtualPatients Ltd (trading as “MedMock”, “we”, “us” or “our”) collects, uses, shares and protects your personal data when anyone visits medmock.com or uses the MedMock platform (the “Platform”), whether they browse, register, take a free trial or pay for access. It also sets out our legal bases for processing under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, how long we keep your data, and the rights you have. Please read it alongside our Terms and Conditions, which govern your use of the Platform and set out important limits on our liability and your responsibility to independently verify all content.

1. Who we are

VirtualPatients Ltd is the “controller” responsible for your personal data.

  • Registered company: VirtualPatients Ltd (company number 16303492).
  • Registered office: 2 St. Mary's Road, Tonbridge, England, TN9 2LB.
  • ICO: We are registered with the UK Information Commissioner’s Office (ICO).
  • Contact for data protection enquiries: contact@medmock.com.

2. Important note about clinical scenarios

MedMock is an educational simulation tool. The patients, examiners, relatives and clinical cases you interact with are entirely fictional and AI-generated, and because the Platform is powered by artificial intelligence, which makes mistakes, the content, scores and feedback will at times be incorrect. The clinical images you are shown are a different matter: most are genuine, de-identified images of real patients, obtained from openly licensed research datasets and open-access publications and credited in clause 22 of our Terms and Conditions. The invented case is wrapped around a real image.

Never enter real patient data. Do not type or speak any real patient-identifiable information, any other person’s confidential information, or your own sensitive health information into the Platform — not names, dates of birth, NHS or hospital numbers, addresses, or any other detail that could identify a real person. The Platform is a practice simulation, not a clinical system, and it is not a medical record and not an approved place to hold patient information. Entering real patient data would breach our Terms and Conditions and may breach your own professional and data protection obligations. If you do it by mistake, email us at contact@medmock.com and we will delete the session. The Platform must never be used for real clinical decisions or in the care of any real patient, and it is your responsibility to independently verify all content before relying on it.

3. The personal data we collect

3.1 Account and profile data

Your full name, email address and password (stored only as a secure hash by our authentication provider). At signup we also ask for the institution or workplace you give us, the exam or interview you are preparing for, your subscription tier, and, depending on the exam you choose, your country, profession, training grade, clinical specialty, the month you are sitting your exam, how you heard about us, and details such as a target hospital, consultant specialty or the medical school you are applying to. Some of these are optional and you can leave them blank.

If you choose to sign in with Google, Google passes us the name, email address and profile picture on that Google account so we can create and identify your MedMock account. We do not receive your Google password and we do not get access to anything else in your Google account.

3.2 Conversation and session content

The text and voice content of your practice sessions, including your typed messages, the transcripts generated from what you say, the AI-generated patient/examiner responses, and the automated scores, feedback and coaching tips produced for each station. We also store session metadata such as the exam, station, duration and timestamps. We do not store the audio itself — your speech is transcribed as you practise and the recording is discarded; only the transcript is kept.

3.3 Payment data

When you subscribe or top up, payments are processed by Stripe. We receive limited billing information (for example your subscription status, plan, customer reference and the outcome of payments). We do not receive or store your full card number — that is handled directly by Stripe.

3.4 Usage, device and technical data

IP address, approximate location (country, region and city derived from your IP address using a third-party geolocation service, ipapi.co — see section 6), browser type and user agent, device information, pages visited, features used, and interaction and performance metrics.

3.5 Marketing and acquisition data

How you found us (referrer, landing page and any campaign/UTM parameters), and your communications and feedback when you contact us.

3.6 Loading-screen games and the leaderboard

While a station loads you can play a short game. If you set a high score, we store your first name, your country and that score, and display them to other users on a leaderboard inside the Platform. Only your first name is used, never your full name or email address, and only your best score is kept. If you would rather not appear, do not play the game, or email us at contact@medmock.com and we will remove your entry.

4. How we use your data and our legal bases

Under the UK GDPR we must have a lawful basis for each use of your personal data. We rely on the following:

  • Performance of a contract — to create and manage your account, deliver practice sessions, generate scores and feedback, process payments and provide support.
  • Legitimate interests — to secure and operate the Platform, prevent fraud and abuse, understand how the service is used, and improve our features, prompts and models using de-identified and aggregated data (see section 7). We balance these interests against your rights and you can object at any time.
  • Consent — for non-essential cookies and analytics (including Google Analytics and the Meta Pixel, which are only set after you accept them via our consent banner), for the leaderboard entry described in section 3.6, and for marketing emails: at signup we show you an unticked box, and we only send marketing emails if you tick it. You can withdraw consent or opt out at any time.
  • Legal obligation — to comply with our legal, tax, accounting and regulatory duties.

5. Artificial intelligence and voice processing

The Platform uses third-party artificial intelligence services to power its simulations and feedback. When you take part in a session:

  • Your typed messages and session context are sent to Google’s Gemini generative AI service to generate patient/examiner responses, scenarios, mark schemes, feedback and coaching.
  • If you use voice, your speech is normally transcribed by your own web browser, using the speech recognition built into it. On Chrome and most Chromium browsers that means the audio is sent to Google for transcription; on Safari it is handled by Apple. This happens under those companies’ own terms and privacy policies, as part of a feature of your browser, and the audio does not pass through our servers. Only the resulting text does.
  • Where your browser does not provide speech recognition — for example inside the in-app browsers in WhatsApp, Instagram or Facebook — we fall back to sending your recorded audio to Google Cloud Speech-to-Text (and, for longer clips, Google’s Gemini) to convert your speech into text. We keep the transcript and discard the audio.
  • The virtual patient’s and examiner’s spoken replies are voiced by ElevenLabs, our text-to-speech provider. The AI-generated reply text is sent to ElevenLabs to be converted into audio; because those replies respond to what you say in a session, they may occasionally include personal data you have chosen to share (for example, your name).

5.1 AI tools we use behind the scenes

Separately from your practice sessions, we use an AI coding assistant — currently Anthropic’s Claude — to build and maintain the Platform, to draft and quality-check our practice material, and to investigate technical faults and account problems. Almost all of that work involves only our own source code and fictional, synthetic clinical content.

Where we investigate a fault or a problem with an account, we use internal identifiers such as your account reference wherever we can, rather than your name or email address, and we keep the personal data involved to the minimum needed to fix the problem. Some personal data about you may still be provided to this tool where that is necessary to diagnose the issue — for example your email address, an error log, or the contents of a session that is not working.

We use Claude under Anthropic’s commercial terms and a data processing agreement, which do not permit Anthropic to use the content we submit to train their models. Your practice sessions are not routed to Anthropic as part of the normal running of the Platform.

These providers process this content on our behalf to return a result to you. The scores and feedback are produced by automated systems for educational purposes only; they are not a definitive assessment of your competence and have no bearing on any official examination. They do not produce decisions that have legal or similarly significant effects on you, and you can contact us if you wish to discuss any feedback.

6. Who we share your data with

We do not sell your personal data. We share it only with the service providers (“processors”) needed to run the Platform, each under a contract that limits how they may use it:

  • Google Cloud Platform / Firebase — hosting, database (Firestore), authentication, file storage and analytics.
  • Google (Gemini & Cloud Speech-to-Text) — AI generation and speech transcription, as described in section 5.
  • Your own browser’s speech recognition (Google on Chrome, Apple on Safari) — transcription of what you say, as described in section 5. These act under their own terms, not as our processors.
  • ElevenLabs — text-to-speech generation of the virtual patient’s and examiner’s voices, as described in section 5.
  • Stripe — payment processing.
  • Resend — sending transactional and marketing emails (for example verification, password reset, renewal reminders, support replies, and any marketing emails you have agreed to receive).
  • Sentry — crash and error reporting. When something goes wrong in the Platform, technical details of the failure are sent to Sentry so we can find and fix it: the error message and stack trace, the page or feature it happened in, your browser and device type, and the IP address the report came from. It is configured to send errors only — no session recording or replay, no tracing of your activity, and no exam answers, audio or account details. Our Sentry data is hosted in the European Union.
  • Cloudflare (Turnstile) — bot and abuse protection on our sign-up and contact forms.
  • ipapi.co — IP-based geolocation. When you sign up and during your sessions, we send your IP address to ipapi.co to derive your approximate location (country, region and city), which we use to understand where our users are and to comply with regional legal requirements.
  • Meta Platforms (Meta Pixel) — advertising measurement on our website, so we can measure the effectiveness of our advertising on Meta’s platforms (Facebook and Instagram). The Pixel only runs if you accept it via our consent banner; if you decline, no Pixel identifiers are set.
  • Anthropic (Claude) — an AI coding assistant used in our development, content-production and support work, as described in section 5.1. It receives personal data only where that is needed to investigate a technical fault or an account issue, and only to the minimum extent necessary; Anthropic acts as our processor under a data processing agreement. It is not used to deliver your practice sessions.
  • Other users of the Platform — only your first name, country and best score, and only if you play the loading-screen game (section 3.6).
  • Professional advisers and authorities — for example legal, accounting or regulatory bodies, where we are required to do so by law, court order, or to establish, exercise or defend legal claims.

If our business is restructured, sold or merged, personal data may be transferred to the relevant party, subject to this Policy.

7. Using data to improve the service

We may use de-identified and aggregated data — with personal identifiers removed — to monitor quality, debug issues, and improve our prompts, scoring and the Platform’s performance. We do not use your identifiable conversation content to train third-party foundation models. If you would prefer your content not to be used even in de-identified, aggregated form to improve the service, contact us at contact@medmock.com and we will honour that request.

8. YouTube API Services

We use the YouTube API Services as part of our own internal marketing tools, to publish MedMock’s own promotional videos to our own YouTube channel. This use is governed by the YouTube Terms of Service (https://www.youtube.com/t/terms), and by using this integration we agree to be bound by the Google Privacy Policy (https://policies.google.com/privacy). This integration does not process the personal data of MedMock users or candidates — it is limited to our own marketing content and our own authorised channel. You can revoke MedMock’s access to your Google Account at any time via the Google security settings page (https://myaccount.google.com/permissions).

9. How long we keep your data

We keep your personal data only for as long as necessary for the purposes set out in this Policy. In practice:

  • Your account and profile — for as long as your account is open. If you delete it, see section 10.
  • Practice sessions, transcripts, scores and feedback — for as long as your account is open, so that you can review your own progress. They are deleted when your account is deleted.
  • Database backups — our database keeps rolling backups and point-in-time recovery for disaster recovery. A record you delete can persist in those backups for up to 14 days, after which it is purged automatically. We do not restore deleted accounts from backups.
  • Error and crash reports (Sentry) — up to 90 days.
  • Server and security logs — up to 30 days, and longer only where we are investigating abuse, fraud or a security incident.
  • Email delivery records (Resend) — in line with our email provider’s standard retention, currently up to 30 days. Records of unsubscribes and bounces are kept for longer, because we need them to avoid emailing you again.
  • Transaction and billing recordssix years from the end of the relevant accounting period, because tax law requires it. Stripe also keeps its own record of your payments as the payment processor.
  • Records of your consents and your acceptance of our terms — for as long as your account is open and for six years afterwards, as evidence that we had permission to do what we did.
  • Aggregated and anonymised statistics — indefinitely. These are no longer personal data and cannot be traced back to you.

If your account is inactive for a long period we may contact you before deleting it. We will always give you notice and a chance to keep it.

10. Deleting your account and your data

You can permanently delete your MedMock account and its associated personal data yourself at any time, from Profile & Settings → Delete account in your dashboard. Alternatively, email contact@medmock.com and we will action it within one month.

What is deleted immediately: your profile and account details, your saved practice sessions, transcripts, scores and feedback, your login, your leaderboard entry, and your remaining credits (which are forfeited — see clause 4.2 of the Terms). Any active subscription is cancelled at the same time.

What remains, and for how long:

  • Copies in our database backups, for up to 14 days, after which they are purged automatically (section 9).
  • Transaction and billing records, for six years, because tax and accounting law requires us to keep them. Stripe keeps its own record of your payments.
  • A one-way, keyed digest of your email address, so that a deleted account cannot be recreated simply to claim another free trial. It cannot be reversed to recover your email address.
  • If you have unsubscribed from marketing or an email to you has bounced, a record of that, so we do not email you again.
  • Aggregated and anonymised usage statistics, which are no longer personal data.

Data obtained through Google/YouTube API Services (see section 8). The only data we obtain through the YouTube API is our own authorisation token for our own channel; we do not obtain or store any MedMock user’s Google data. That token can be deleted at any time by disconnecting the account in our internal dashboard, or by revoking MedMock’s access via the Google security settings page (https://myaccount.google.com/permissions); we do not retain it after access is revoked.

11. International transfers

Your account and session data are stored on Google infrastructure located in the European Union: our databases run in Google’s eur3 multi-region (data centres within the EU), and our application servers run in London (europe-west2). Some of our providers (including Google, Stripe, Resend, Cloudflare, ipapi.co, Meta, ElevenLabs, Sentry and Anthropic) may process limited data outside the UK and EEA, including in the United States. Where data leaves the UK, we rely on an appropriate safeguard — such as an adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with the additional technical and organisational measures those safeguards require — so that your data continues to be protected to UK standards. You can ask us at contact@medmock.com which safeguard applies to a particular provider, and for a copy of the relevant terms.

12. How we keep your data secure

We protect your data using encryption in transit, access controls, server-side enforcement of who can read each user’s data, and reputable infrastructure providers. No system is completely secure, but we take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, alteration or disclosure, and we will notify you and the ICO of a personal data breach where we are legally required to do so.

13. Your rights

Under the UK GDPR you have the right to:

  • be informed about how we use your data (this Policy);
  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to certain processing, including processing based on legitimate interests and any direct marketing;
  • data portability — receive your data in a structured, commonly used, machine-readable format; and
  • withdraw consent at any time, where we rely on consent.

To exercise any of these rights, email us at contact@medmock.com. We will respond within one month. There is normally no charge, and we may need to verify your identity first.

14. Cookies and analytics

We use a small number of essential cookies needed to keep you signed in and to operate the Platform. We also use Google Analytics to understand how the Platform is used, and the Meta Pixel to measure the effectiveness of our advertising on Facebook and Instagram. Non-essential analytics and advertising cookies are only set after you accept them via our consent banner; until you choose, they stay off, and if you decline, they are never set.

Changing your mind. You can change your cookie choice at any time using the Cookie settings link in the footer of any page, or here: . Choosing “Decline” turns analytics and advertising cookies off again. Disabling essential cookies will stop you being able to sign in.

14.1 If you are signed in

If you have accepted analytics cookies and you are signed in, we also send Google Analytics an account identifier for you — a random internal reference, not your name or email address. This lets us see that one person using a phone and a laptop is the same person, so our usage figures are not double-counted. It also means your activity can be linked across your devices within Google Analytics. If you decline analytics cookies, no identifier is sent. You can withdraw consent at any time using the Cookie settings link above.

14.2 What we set

  • __session — essential. Keeps you signed in between pages. First party, expires when your session ends.
  • mm_cookie_consent — essential. Remembers your cookie choice so we do not ask again. Stored in your browser’s local storage on your device; it never leaves it.
  • Other mm_ entries — functional. Remember interface preferences and your best scores in the loading-screen games. Stored on your device only.
  • _ga and _ga_<id> — analytics, consent-gated. Set by Google Analytics to tell returning visits apart and measure how the Platform is used. Third party (Google), expire after up to 2 years.
  • _fbp — advertising, consent-gated. Set by the Meta Pixel to measure whether our Facebook and Instagram advertising works. Third party (Meta), expires after about 3 months.
  • Cloudflare Turnstile — essential security. Short-lived tokens used to tell real users from bots on our sign-up and contact forms. Third party (Cloudflare), expire quickly.

15. Marketing

We only send you marketing emails if you have opted in: when you sign up, we show you an unticked box asking whether you would like study tips, product updates and offers for your exam, and we send marketing only if you tick it. You can manage your email preferences at any time in your account settings, opt out using the unsubscribe link in any marketing email, or by contacting us. Transactional and service messages (such as verification, billing, renewal reminders and security notices) are not marketing and may still be sent while you hold an account.

16. Children

The Platform is intended for users aged 16 or over. We set this age because some of the exams we help people prepare for — medical school interviews in particular — are sat by students who are still at school and are typically 17. We do not knowingly collect personal data from anyone under 16, and if you believe someone under 16 has given us their data, please contact us and we will delete it.

If you are 16 or 17. We treat your data with the same care as everyone else’s, and we have designed the Platform with that in mind: marketing emails are off unless you actively opt in, we do not build advertising profiles of the people who use the Platform, we do not use nudge techniques to push you into sharing more than you need to, and you can delete your account and everything in it yourself at any time. You need your parent or guardian’s permission before you pay for anything — see clause 3.1a of our Terms and Conditions. A parent or guardian can contact us at contact@medmock.com on your behalf at any time.

We have carried out a data protection impact assessment covering our use by 16- and 17-year-olds, in line with the Information Commissioner’s Age Appropriate Design Code. You can ask us for a summary of it at contact@medmock.com.

17. If your university or employer pays for your access

Where a university, trust, employer or other organisation pays for your access, we remain the controller of your personal data and you hold your own account with us in your own name. The organisation that pays is a separate controller for whatever data it holds about you; it is not our processor and we are not its processor.

We do not give that organisation your scores, marks, transcripts, feedback reports or any record of how you performed, unless we have told you before you start and you have agreed to it. We may tell it only aggregate, anonymised information about the group as a whole, such as the total practice time the cohort has used. You are free to share your own results with them yourself if you want to. See clause 12 of our Terms and Conditions.

18. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or for legal, operational or regulatory reasons. If we make significant changes, we will notify you by email or by placing a prominent notice on the Platform before the change takes effect. The “Last updated” date above shows when this Policy was last revised.

19. Complaints

We hope to resolve any privacy concern you raise, so please contact us first at contact@medmock.com or through our contact form. We will acknowledge your complaint and give you a substantive response within 30 days; if we need longer, we will tell you why and when you can expect an answer.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or with the data protection authority in your country of residence. You can do that at any time, but we would appreciate the chance to put things right first.

20. Contact us

If you have any questions about this Policy or how we handle your data, contact us at contact@medmock.com, or write to us at VirtualPatients Ltd, 2 St. Mary's Road, Tonbridge, England, TN9 2LB.