Contents
1. Who we are
OtoPrep is responsible for the processing of personal information described in this Privacy Policy (the “Data Controller” where that term applies).
2. Scope
This Privacy Policy applies to information we collect through the Services. It does not apply to third-party websites or services that you access through links in the Services or that operate independently from us.
3. Information we collect
A. Information you provide
- Account details: name, email address, login credentials (stored in encrypted/hashed form), and optional profile details you add.
- Purchases & billing: purchase history, subscription status, receipts/invoices, and payment confirmations. Payment card data is typically handled by payment processors; we generally do not store full card details.
- Support & communications: messages you send (support tickets, emails, feedback) and our replies.
- User inputs: written answers, notes, uploads, and other content you submit in the Services.
B. Information collected automatically
- Device & technical data: IP address, browser type, device/OS, language, referring URLs, approximate location inferred from IP.
- Usage data: pages/screens viewed, click/activity data, session duration, feature usage, and error logs.
- Cookies & similar tech: see Section 8.
C. Information from third parties
- Payment processors: payment status, charge outcomes, fraud indicators, and billing metadata necessary to process transactions.
- Infrastructure/security providers: hosting, content delivery, and security services may generate logs to keep the platform stable and safe.
- Analytics providers: aggregated measurements to help us understand performance and usage (depending on your cookie settings and configuration).
4. Voice/Viva & Oral Examination Practice data
If you use OtoPrep’s Oral Examination Practice System (where available), we may process additional data to deliver the feature. This may include Viva Modules, Voice Live Coach, and AI-generated Viva Feedback.
What may be processed
- Microphone audio: real-time audio input while a Voice Session is active (subject to your device/browser permissions).
- Transcripts: text created from your audio, plus any edits/corrections you make.
- Session metadata: mode (e.g., Viva/Tutor/Socratic), time spent, question progression, prompts shown, and interaction logs.
- Generated outputs: AI-generated responses and, where enabled, post-session Viva Feedback reports derived from transcripts/session criteria.
- Usage & credits: credits balance, grants, deductions, limits, and enforcement records used to operate the system and prevent abuse.
Where processing happens
To provide voice transcription and AI-assisted outputs, your audio and/or transcripts may be processed by technology providers acting on our behalf under contractual restrictions. We do not sell your personal information.
5. How we use information
- Provide and operate Services: create accounts, authenticate users, provide access to purchases and subscriptions.
- Transactions: process payments, manage orders, handle refunds, and maintain accounting records.
- Deliver learning features: run modules, track progress, and maintain session history.
- Voice/Viva features: enable Voice Sessions, generate transcripts, and (where enabled) produce Viva Feedback.
- Support: respond to queries, troubleshoot, and communicate important service notices.
- Security and integrity: prevent fraud/abuse, enforce limits/credits, detect suspicious activity, and secure the platform.
- Analytics and improvement: understand usage patterns and improve stability, content quality, and user experience.
- Marketing (where permitted): send product updates, newsletters, and offers. You can opt out (see Section 10).
- Legal compliance: comply with legal obligations and protect our rights and users.
6. Legal bases for processing (where applicable)
In some jurisdictions (e.g., EEA/UK), we must state legal bases for processing. Where applicable, we process information under one or more of:
- Contract: to provide the Services you request (accounts, access, subscriptions, sessions).
- Legitimate interests: to operate, secure, and improve the Services (fraud prevention, analytics, feature reliability).
- Consent: for certain cookies/marketing and for microphone access via your browser/device permissions.
- Legal obligation: where required by law (e.g., tax/accounting, lawful requests).
7. How we share information
A. Service providers
We share information with trusted providers who help us run the Services (e.g., payments, hosting, email delivery, analytics, security, and where enabled, voice transcription and AI generation). These providers are permitted to process information only to provide services to us.
B. Legal and safety
We may disclose information if reasonably necessary to comply with law, lawful requests, or to protect the rights, safety, and security of OtoPrep, our users, or others.
C. Business transfers
If we are involved in a merger, acquisition, restructuring, financing, or sale of assets, your information may be transferred as part of that transaction, subject to appropriate safeguards.
D. With your direction
We may share information when you ask us to do so, or when you consent (for example, if you authorize an integration).
8. Cookies & tracking technologies
We use cookies and similar technologies (e.g., pixels and local storage) to operate the Services and improve performance.
- Strictly necessary: required for login, security, and core site functionality.
- Preferences: remember settings and improve your experience.
- Analytics: help us understand usage and improve reliability.
- Marketing: measure campaign performance or deliver relevant communications (where enabled).
How do I disable cookies?
Most browsers let you block or delete cookies through settings. You can also use private/incognito mode. Note that some site features may not work properly if you block essential cookies.
Do you use analytics?
We may use analytics tools to understand how the Services are used and to improve performance. Depending on configuration and cookie settings, this may include aggregated or pseudonymized data.
9. International data transfers
We may process and store information in countries other than where you live (for example, where our providers operate). Where required by law, we use appropriate safeguards for international transfers (such as contractual protections).
10. Your rights & choices
Depending on your location, you may have rights regarding your personal information, including access, correction, deletion, portability, restriction, and objection.
- Account settings: you may be able to update some information by logging into your account.
- Marketing opt-out: use the unsubscribe link in emails or contact us (you may still receive transactional/service emails).
- Voice/Viva transcripts: you can request access or deletion of stored transcripts and session history, subject to legal and operational limits.
11. Data retention
We keep personal information only as long as necessary for the purposes described in this policy, including to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and maintain security and fraud prevention.
If you request deletion, we will take reasonable steps to delete or anonymize information unless retention is required or permitted by law (for example, for billing records, security logs, fraud prevention, and enforcing usage limits/credits).
12. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
13. Children’s privacy
The Services are not intended for individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will take appropriate steps.
14. Third-party links
The Services may include links to third-party sites or services. We are not responsible for their privacy practices. We encourage you to review their privacy policies before providing information.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in practices, technologies, or legal requirements. When we update it, we will revise the “Last Updated” date at the top. Continued use of the Services after changes are posted means you acknowledge the updated policy.
16. Contact us
When contacting us, please include the email address associated with your account to help us locate your information quickly.