Skip to main content

Privacy Policy

Effective Date: 24 September 2026

This page explains what personal data NextGen MedPrep collects when you use nextgenmedprep.com and our related services, why we collect it, who we share it with, and what rights you have. We've tried to write it in plain English. If anything is unclear, email contact@nextgenmedprep.com.

1. Who we are

NextGen MedPrep is a UK-based educational service providing tutoring and guidance for medicine and dentistry applicants. For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller for personal data collected through this site.

Contact: contact@nextgenmedprep.com

2. What data we collect

We group the data we collect into three categories.

2.1 Strictly necessary (always on)

This is data we must collect for the site to work at all:

  • Session and authentication cookies - to keep you logged in when you use the student or tutor dashboard
  • CSRF tokens - to protect form submissions from cross-site attacks
  • Payment processing data - when you book a consultation or purchase materials, Stripe collects card details directly. We never see or store your card number.
  • Email + name - when you create an account, sign up for a free guide, or apply to join the team

Lawful basis: Necessary for the performance of a contract (Article 6(1)(b) UK GDPR), and our legitimate interest in operating a secure service (Article 6(1)(f)).

2.2 Analytics (with your consent)

We use a product analytics tool to understand how the site is used and improve it:

  • PostHog (EU region) - captures page views, button clicks, guide downloads, sign-up conversions, and similar interaction events. PostHog assigns each visitor a random distinct ID on first visit, which is pseudonymous. If you sign up for an account or download a free guide via the email gate, we link your email address to that distinct ID so we can analyse the full conversion path (this is standard product analytics practice). We do not store your full IP address - only the country code derived from it. PostHog is hosted by PostHog Inc. on infrastructure in Frankfurt, Germany.

Lawful basis: Consent (Article 6(1)(a) UK GDPR + PECR regulation 6). You can withdraw at any time using the section below.

2.3 Marketing (with your consent)

We use marketing tools to measure ad effectiveness and reach new applicants:

  • Meta (Facebook) Pixel - captures page views, conversion events (purchases, sign-ups, downloads), and creates retargeting audiences for Facebook and Instagram ads. Operated by Meta Platforms Ireland Ltd; data may be transferred to Meta Platforms Inc. in the United States under Standard Contractual Clauses.
  • Vercel Analytics - basic aggregate visitor counts and Core Web Vitals performance metrics. Vercel uses no cookies for this product, so it's arguably also lawful under legitimate interest, but we treat it as analytics for transparency.

Lawful basis: Consent (Article 6(1)(a) UK GDPR + PECR regulation 6). You can withdraw at any time.

3. Cookies and similar technologies

We use a small number of cookies and one item of browser local storage:

  • Necessary: session cookie (Supabase auth), preferences cookie (currency, accessibility settings)
  • Analytics: PostHog distinct-ID cookie + localStorage entry - only set after you grant analytics consent
  • Marketing: Meta Pixel cookies (_fbp, _fbc) - only set after you grant marketing consent
  • Consent record: we store your consent decision in browser localStorage under the key ngmp-consent-v1 for 12 months. This is functional and doesn't require its own consent under PECR.

4. Who we share data with

We share data only with the following service providers (acting as data processors on our behalf), each under a written agreement:

  • Supabase (database + authentication, EU region) - stores account data, downloads, bookings
  • Vercel (hosting + basic analytics) - serves the site, may briefly process request metadata
  • Stripe (payments) - processes card transactions
  • Resend (transactional email, EU region) - sends booking confirmations and password resets
  • Render (hosting) - runs our backend API, which processes account, booking and tutoring data
  • Cloudflare Stream (video hosting) - delivers tutor videos and hosts the video feedback a tutor records for your personal statement review
  • Twilio (text and WhatsApp messages) - receives your mobile number and the message content when we send you an interview reminder or other notification by text or WhatsApp, or a phone verification code
  • Anam, Anthropic, AssemblyAI, ElevenLabs, LiveAvatar (HeyGen) and LiveKit - power our AI mock interviews, OSCE stations and personal-statement feedback. See section 4.1 for exactly what each receives.
  • PostHog Inc. (analytics, EU region) - only if you grant analytics consent
  • Meta Platforms Ireland (advertising) - only if you grant marketing consent

We do not sell your data, and we do not share it with any other third party for their own marketing purposes.

4.1 AI interview, OSCE and personal-statement processing

Our AI mock interviews, AI OSCE stations and AI personal-statement feedback rely on the providers below. They process your data on our behalf to deliver the feature you are using.

  • Anam (AI interviewer video, speech recognition and voice) - runs the video interviewer you see in an AI mock interview. The audio from your microphone is streamed from your browser to Anam, which transcribes what you say and turns the interviewer's replies (written by Anthropic, below) into the voice and animated face of the interviewer. Anam receives your voice, not your camera video. We switch off Anam's session recording, so it does not keep a recording of your interview; it keeps a session report, including the transcript, under its own terms. Anam AI Ltd is a UK company; it processes session data in the EU (Spain) and the United States, under the EU Standard Contractual Clauses and the UK Addendum, and does not use session content to train its models.
  • AssemblyAI (speech-to-text) - during an AI OSCE station, and any AI mock interview not run by Anam, the audio from your microphone is streamed from your browser to AssemblyAI, which returns a live transcript of what you say. AssemblyAI receives your voice, not your camera video. Its default streaming service, which we use, may process audio in the United States or the EU.
  • Anthropic (the Claude AI model) - receives the text transcript of your answers so the AI interviewer or patient can reply, and again after the session to produce your scores and feedback report. If you leave "Let the interviewers read my application" ticked when you book a mock, it also receives your school choices, UCAT score, applicant type, application stage and up to three recent work-experience diary entries. When you ask for AI feedback on a personal-statement section, the draft text of that section (and any notes you add) is sent to Anthropic. Anthropic receives text only, never audio or video. Anthropic stores API data in the United States, and the model itself may run in other countries. Anthropic's data processing addendum includes the EU Standard Contractual Clauses and the UK Addendum.
  • ElevenLabs (text-to-speech) - in an AI OSCE station, and any AI mock interview not run by Anam, receives the text the AI interviewer or patient is about to say, which can refer back to your answers, and turns it into a voice. It does not receive your own voice or video. ElevenLabs stores customer data in the United States as standard, and its data processing addendum includes the EU Standard Contractual Clauses and the UK Addendum.
  • LiveAvatar (a HeyGen product; avatar video) - used for the patient in AI OSCE stations, and for any AI mock interview not run by Anam. Receives the generated interviewer or patient voice audio and returns the animated video of the avatar you see. We do not send it your microphone or camera. Our LiveAvatar session is set up with Deepgram as its speech-to-text provider for compatibility reasons, but because we never send LiveAvatar your microphone, no audio of yours reaches Deepgram through it. HeyGen is a company established in the United States.
  • LiveKit (real-time video transport) - the avatar's video and audio reach your browser through a LiveKit Cloud room that LiveAvatar sets up for your session. LiveKit therefore sees your connection data (IP address and browser details) for the duration of the session; we do not send your microphone or camera into that room. We are also building an experimental server-side interviewer mode in which your microphone and camera would be sent through a LiveKit Cloud room we operate to our own interviewer service. It is switched off by default and is not enabled for any student at the date above; we will update this section before it is. LiveKit Incorporated is based in the United States and processes personal data there; it publishes a data processing addendum and relies on the EU-US Data Privacy Framework, adequacy decisions or contractual protections for transfers.

Your camera. Recording is optional: you choose when you book, and your feedback is marked from the transcript, not the video. If you choose to be recorded, your webcam and microphone are recorded during an AI mock interview and uploaded to our own storage (Supabase), not to any of the providers above, so you can watch it back. NGMP coaches can also view it when reviewing your session. Where your browser supports it, how often you look towards the camera is measured inside your browser and only the resulting figures are saved. AI OSCE stations are not currently video-recorded. Some practice screens also offer voice dictation using your browser's built-in speech recognition; that is provided by your browser maker under its own terms, not by us.

How long it is kept.

  • Mock interview recordings - available to watch for 7 days after the recording finishes uploading, then deleted automatically (our clean-up runs every hour). If an upload is interrupted and never completes, any part of the recording that reached our storage is deleted automatically within 4 days. Email us if you want a recording deleted sooner, or confirmation that it has gone.
  • Transcripts, scores and feedback reports (mock interviews and OSCE stations) - kept for as long as your account exists so you can return to your debriefs. They are not deleted automatically; they are deleted when your account is deleted, or sooner if you ask us.
  • Personal-statement drafts - saved only in your own browser. We do not store the draft you send for AI feedback, or the feedback itself, on our servers.
  • Personal statement reviews by a tutor - the statement you upload is stored in our own storage (Supabase) and the tutor's video feedback on Cloudflare Stream. The video is deleted automatically 7 days after the tutor submits it (for feedback submitted before 16 September 2026, 7 days from that date); the sweep runs hourly. The statement file and the download link to the video are then kept until we run a retention purge of older reviews. Before a purge deletes your files we email you the deletion date (normally 14 days' notice) with links to download both your statement and, if it still exists, the feedback video. The review record itself (without the files) is kept for our accounts.
  • At the providers - Anthropic deletes API inputs and outputs within 30 days, unless it needs to keep them longer to enforce its usage policy or is required to by law. ElevenLabs keeps a log of text sent for speech and the audio it generates under its standard settings (its zero-retention mode is only offered to enterprise customers, and we do not use it). Anam does not keep a recording of your interview (we switch its session recording off); its session report, including the transcript, is kept under its own terms, as is data held by AssemblyAI and HeyGen.

5. International transfers

Supabase, Resend and PostHog store data in the EU, which the UK recognises as providing adequate protection. The following providers may process your data outside the UK and EU:

  • Meta Pixel - data may be transferred to Meta Platforms Inc. in the United States. This transfer is covered by Meta's adoption of the EU-US Data Privacy Framework and Standard Contractual Clauses.
  • Stripe - payment data may briefly be processed by Stripe's US infrastructure, also under SCCs.
  • Anam, Anthropic, AssemblyAI, ElevenLabs, LiveAvatar (HeyGen) and LiveKit - our AI interview, OSCE and personal-statement providers may process data in the United States. See section 4.1 for the details and safeguards each provider publishes.
  • Twilio - handles messages in its default United States region.

For any other provider in section 4 not described as EU-hosted, you should assume your data may be processed outside the UK and EU.

6. How long we keep your data

  • Account data - while your account is active, plus 6 years after closure (HMRC requirement for any associated payment records)
  • Free guide download records - 24 months
  • Analytics events (PostHog) - 12 months at full detail, then indefinite at aggregate level
  • Marketing pixel data - per Meta's retention policies (we don't control this directly)
  • Email + booking confirmations - 6 years (HMRC)
  • AI mock interview and OSCE data - recordings (only if you chose to be recorded) are available for 7 days and then deleted automatically; transcripts, scores and feedback reports are kept while your account exists. See section 4.1.

7. Your rights

Under UK GDPR you have the right to:

  • Access - get a copy of what we hold about you
  • Rectification - correct anything that's wrong
  • Erasure - ask us to delete your data (we'll honour this unless we're legally required to keep it, e.g. for HMRC)
  • Restriction - ask us to stop processing your data
  • Portability - receive your data in a machine-readable format
  • Object - object to processing based on legitimate interest
  • Withdraw consent - change your mind about analytics or marketing at any time (see section 8)
  • Complain - to the Information Commissioner's Office at ico.org.uk

To exercise any of these, email contact@nextgenmedprep.com. We'll respond within one calendar month.

8. Change your consent

You can update your analytics and marketing preferences at any time. Click below to reset your consent - the cookie banner will reappear on your next page view, and you can re-decide.

You haven't set preferences yet - the cookie banner will appear when you visit any page on the site.

9. Children

Our service is for secondary-school students and applicants preparing for medicine and dentistry, and some of it (such as GCSE tutoring and our planning guides from Year 9) is aimed at students under 16. We don't ask for your date of birth or check your age when you sign up. Our services are not intended for children under 13; if you believe a child under 13 has given us personal data, email us and we'll delete it promptly.

10. Security

We use HTTPS for all traffic, store passwords using industry-standard hashing (Supabase Auth), and limit access to personal data to staff who need it. We don't store card numbers or full IP addresses. No system is perfectly secure, but we take reasonable steps to protect what we hold.

11. Changes to this policy

We'll update the Effective Date above when we change this policy. For material changes (e.g., adding a new analytics tool), we'll prompt you to re-consent via the banner. For minor clarifications, we'll just update the text.

12. Contact

Questions, complaints, or requests: contact@nextgenmedprep.com