Privacy policy
Version 1.0, in force from 28 August 2026. Independent legal review is scheduled.
Contents
1About this policy
This policy explains how MedMatrix Pty Ltd (ABN 37 701 007 061), trading as OSCE World (we, us, our), handles personal information when you use OSCE World, our website at osceworld.com, and any other product or service we operate under a MedMatrix brand.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where the General Data Protection Regulation or UK GDPR applies to you, section 15 explains the extra rights you have.
Personal information means information about an identified individual, or an individual who is reasonably identifiable. It does not cover information we have properly aggregated or de-identified.
This policy does not cover third party websites you reach through links from our service, or the separate handling of your information by your own university or hospital.
2What we collect
The short version. We collect the details needed to run your account, and we store what happens inside a practice station, including the full transcript of your conversation with the simulated patient, your written summary, and the marks and feedback generated for you. We do not sell any of it, and we do not use advertising trackers.
Account information. Your email address, a securely hashed version of your password (we never store the password itself), your first and last name where you or your institution provide them, your role such as student, facilitator or administrator, your portal role, your plan, your training level and whether that level is locked by your institution, the organisation and classes you belong to, whether two-factor authentication is on, whether your account is enabled, when you last signed in, and the date your account was created.
Verification and security information. One-time codes we email you to verify your address, reset your password or complete two-factor authentication. These are stored as hashes, with a count of failed attempts and an expiry, never in readable form. A record of which service emails we sent to which address and for what purpose. An audit log of administrative actions taken on accounts, recording who did what, to whom, and when.
Practice station records. For each station you attempt we store the case, the mode you sat it in, the full transcript of your exchange with the simulated patient, your post-station written summary, the result and percentage awarded, the marking breakdown, the written feedback generated for you, the training level used, and when it happened.
Voice data, only if you turn voice features on. Audio from your microphone is streamed to a speech-to-text provider and converted into text. See section 6.
Class and feedback information. Comments your facilitator writes on your work, whether a comment was addressed to you or broadcast to your class, comments facilitators save for reuse, your class memberships, and any request you make for access to a case pack.
Purchase records. Which plan you bought, when, what you paid, in what currency, when it expires, how many stations you have used against it, the Stripe checkout session, any discount code you redeemed, and whether it was refunded. Card details are handled by Stripe and never reach us.
Messages you send us. If you use the in-app feedback form we keep your message together with your name, email address, organisation, the page you were on and your browser user agent, so we can reproduce and fix the problem. If you use the contact form on our website we keep your name, email address, the topic you chose and your message.
Technical information. IP address, browser and device information, and server logs recording requests to the service. We use this for security, abuse prevention, debugging and reliability.
Where you signed up. When you create an account we record the time zone your browser reports, such as "Australia/Sydney", and the country that time zone belongs to. We use it to understand which countries and regions our students come from, so we know where to improve the service. A time zone covers a whole region and does not identify your town or address, and we do not use your IP address to work out your location.
We do not ask for and do not want health information about you or about any real patient. Please do not enter real patient details into a station. If you do, we may delete it.
3How we collect it
We collect personal information:
- directly from you, when you sign up, use a station, change a setting or contact us;
- from your institution, when a facilitator or administrator creates or manages your account, or adds you to a class;
- automatically, from your device and browser as you use the service;
- from our providers, for example when our email provider reports that a message could not be delivered.
If your email address is on a domain belonging to an organisation we already work with, your account may be linked to that organisation automatically when you sign up, which means its administrators will be able to see your account and results as described in section 7.
4Why we use it
We use personal information to:
- create and run your account, and keep you signed in;
- deliver practice stations, generate simulated patient replies, and produce your marks and feedback;
- save your history so you can review past attempts and track progress;
- let facilitators and administrators teach, mark and administer their own students, where your account is connected to an organisation;
- verify your identity, reset passwords and provide two-factor authentication;
- take payment, apply plan limits and upgrade credits, and keep the financial records a business is required to keep;
- keep the service secure and available, detect and investigate abuse, and fix faults;
- respond to your questions and support requests;
- improve our cases, marking schemes and product, using aggregated or de-identified information;
- send you service messages about your account, and occasional updates about our own products, which you can stop at any time;
- meet our legal obligations.
We do not use your personal information for automated decisions that produce a legal or similarly significant effect on you. Station marks are generated automatically, but they are practice feedback and carry no academic or professional consequence by themselves.
5How AI processes what you write
When you take a station, your messages, the case details and your written summary are sent to DigitalOcean's inference service so it can generate the patient's reply and, at the end, your marks and feedback. This happens every time you send a message in a station. That service is located outside Australia, in the United States and Canada, even though your account and your station records are stored here. Sections 7 and 8 explain what that means.
The model runs on DigitalOcean's own infrastructure rather than being passed on to a separate AI company. DigitalOcean's published position for its inference service is that it does not store inputs or outputs, does not use them to train, retrain or fine-tune any model, and does not share them with third parties for training or fine-tuning.
Please treat a station like a written exercise that is stored and may be read by your facilitator. Do not put anything into it that you would not want kept, including real patient information, and personal details about yourself or others that are not needed for the exercise.
6Voice features
Voice input is optional and off unless you turn it on. When it is on, audio captured by your microphone is streamed to Deepgram, our speech provider, which converts it to text and returns the text to us. The text is then handled like anything else you type, and is saved in your station transcript.
We do not keep a copy of your raw audio after transcription. We instruct Deepgram not to use your audio to improve its models.
On paid plans, the patient's replies are spoken aloud using Deepgram's speech synthesis. The text sent for synthesis is our case content, not anything about you. Synthesised audio is cached on our server, keyed by the voice and the exact line of dialogue, so that a repeated line does not have to be generated twice. That cache holds our own case content and nothing personal to you.
On the free tier, the patient's voice is generated by your own browser using its built-in speech feature. That never reaches our servers or Deepgram, and the handling is governed by your browser vendor rather than by us.
You can turn voice features off at any time in settings, or by declining the microphone permission in your browser.
7Who we share it with
We do not sell your personal information. We have never sold personal information, and we do not disclose it to third parties for their own marketing. We do not use advertising trackers.
Your institution. If your account is connected to an organisation or a class, facilitators and administrators there can see your account details, your station history, your transcripts and your results, and can leave comments on them. This is what makes the teaching features work. If you would rather your school did not see your practice, use a personal account that is not connected to it.
Service providers. We share personal information with the providers that run parts of the service for us. They may only use it to provide their service to us.
| Provider | What it does | Where |
|---|---|---|
| DigitalOcean (hosting and database) | Application hosting, and the database that stores your account and your station records. | Australia |
| DigitalOcean (AI inference) | Generating the patient's replies, your marks and your feedback. Your messages and your written summary are sent to this service as you work. See section 5. | United States and Canada |
| Deepgram | Converting your speech to text when you turn voice input on, and generating the patient's spoken voice on paid plans. | United States |
| Your browser vendor | Generating the patient's spoken voice on the free tier. This does not pass through us. | Depends on your browser |
| Brevo | Sending verification codes, password resets, service notices, and routing feedback and contact messages to us. | European Union |
| Stripe | Payment processing. Stripe receives the buyer's email and handles card details directly; we never see or store a full card number. | United States and Ireland |
Legal and safety. We may disclose information where the law requires it, where we are responding to a valid request from a regulator or court, or where we reasonably believe it is necessary to prevent a serious threat to someone's life, health or safety, or to investigate serious misconduct.
Business changes. If our business is sold or merged, personal information may transfer to the buyer, who will remain bound by this policy until you are told otherwise. We will notify you before your information becomes subject to a different policy.
8Sending information overseas
Some of our providers are located outside Australia, principally in the United States, Canada and the European Union, and information about you will be disclosed to them in the course of running the service. The table in section 7 shows where each one is.
Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, including through contractual data protection terms. Overseas laws may still differ from Australian law, and a foreign authority may in some circumstances be able to compel access to information held in that country.
Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as standard contractual clauses. You can ask us for details.
9How long we keep it
We keep personal information only as long as we need it for the purposes in this policy, or as long as the law requires.
| What | How long |
|---|---|
| Account information | While your account is open. |
| Station transcripts, marks and feedback | While your account is open, so you can review your progress. You can ask us to delete a particular session and we will action it. |
| Verification and two-factor codes | Deleted shortly after they expire. |
| Security and audit logs | Up to 24 months, for security investigation and accountability. |
| Support, feedback and contact messages | Up to 24 months after the matter is closed. |
| Purchase and financial records | As long as tax and corporations law requires, generally seven years. |
| Raw voice audio | Not retained. Discarded once transcribed. |
When you close your account we delete or de-identify your personal information within 90 days, apart from anything we must keep by law and copies held in backups, which are overwritten on their normal cycle within 12 months.
Two things worth being straight about. Where your institution is required to keep assessment records, it may retain its own copy independently of us. And a comment a facilitator has written to a whole class does not disappear when one member's account closes; we remove your name from it rather than deleting other people's records.
10How we protect it
We take reasonable steps to protect personal information, including:
- encrypting traffic between your device and the service;
- storing passwords only as salted hashes, never in a readable form;
- storing verification codes as hashes, with a limit on failed attempts and a short expiry;
- holding your session in a secure, httpOnly cookie that scripts on the page cannot read;
- offering two-factor authentication, which is on by default;
- restricting access by role, so facilitators and administrators see only their own students, and limiting staff access to what is needed to run and support the service;
- logging administrative actions, and rate limiting sensitive endpoints.
No online service can be completely secure, and we cannot guarantee absolute security. Please use a strong, unique password and leave two-factor authentication on.
11If something goes wrong
If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. We will tell you what happened, what information was involved, and what you should do about it.
We assess suspected breaches promptly and, where an assessment is required, complete it within 30 days. Where the GDPR or UK GDPR applies, we will also notify the relevant supervisory authority within 72 hours where the law requires it.
12Cookies and similar technologies
We use a small number of strictly necessary cookies. The main one holds your signed-in session. There is also an optional cookie if you ask us to remember your device between sign-ins. Both are httpOnly, which means page scripts cannot read them.
We store some preferences, such as your theme and voice settings, in your browser so the app behaves the way you left it.
We do not use advertising cookies, third party tracking pixels or cross-site profiling. If that ever changes, we will ask for your consent first. Blocking essential cookies will stop you from signing in.
13Your rights and choices
You can ask us to:
- access the personal information we hold about you;
- correct anything inaccurate or out of date. Most details you can change yourself in settings;
- delete your account and the information associated with it;
- export a copy of your account and station history in a portable format;
- object to or restrict particular uses, or withdraw consent you have given, such as for voice features or product emails.
Email [email protected] and we will respond within 30 days. We may need to verify your identity first. Access is free, except that we may charge a reasonable cost for a repeated or unusually large request, and we will tell you before we do. If we cannot give you what you ask for, we will explain why and how to complain.
If your account was created by your institution, some requests may need to go through its administrator, because the institution controls that account. We will tell you if that applies and help you get there.
14Emails and marketing
We will always send you service messages you cannot opt out of while you hold an account, such as verification codes, password resets, security notices and changes to these documents.
Product updates and offers. While you hold an account with us we may send you occasional emails about MedMatrix products and services, including OSCE World and any other brand we operate. We keep these infrequent and relevant to what you use. Every one says who sent it and carries an unsubscribe link that works, and we will stop promptly. You can also ask us to stop at any time by emailing [email protected]. This is consistent with the Spam Act 2003 (Cth), which allows messages of this kind on the basis of the account you hold with us.
If your account was created by your institution, we do not send you these. That account exists for your institution's teaching, not for our marketing.
We will ask first before anything wider. If we ever want to email you about something outside our own products and services, we will ask you to agree to that separately, and you can withdraw that agreement at any time.
15If you are outside Australia
We are based in Australia and your information will be handled here and in the countries listed in section 7.
If the GDPR or UK GDPR applies to you, we act as the controller for the handling described in this policy, and our legal bases are:
- performance of our contract with you, to provide the service and your account;
- our legitimate interests, in securing, supporting and improving the service, balanced against your rights;
- your consent, for optional features such as voice input and for marketing, which you can withdraw at any time;
- compliance with legal obligations.
You have the right to lodge a complaint with your local supervisory authority.
Where your university or hospital determines how your information is used for its own purposes, it acts as the controller for that use and we act as its processor.
16Children
The service is intended for people aged 16 and over and is not directed at children. We do not knowingly collect personal information from anyone under 16.
If you believe someone under 16 has given us personal information, contact [email protected] and we will delete it.
17Changes to this policy
We may update this policy as the service changes. The version and date at the top show when it last changed. If a change materially affects how we handle your personal information, we will tell you by email or in the app before it takes effect.
18Contact us and how to complain
For any privacy question or request, email [email protected]. For general help, email [email protected].
MedMatrix Pty Ltd (ABN 37 701 007 061), trading as OSCE World.
If you think we have mishandled your personal information, please tell us first so we can put it right. We will acknowledge your complaint within 7 days and give you a decision within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. If you are in the European Economic Area or the United Kingdom, you can complain to your local data protection authority.
OSCE World is a registered business name of MedMatrix Pty Ltd (ABN 37 701 007 061), a company registered in New South Wales, Australia.
Terms of serviceUsage policyEnd user licence agreementAccessibility
Back to the part that helps.
Two stations free, no credit card, and a marked report at the end of each one.