Skip to content

Privacy

Privacy Notice

Last updated 2 September 2026

1. Overview

This Privacy Notice explains how Surgeon AI LLC, trading as SurgeonAI, collects and uses personal information when you visit our website, request early access, create an account, use the Service, attend a live session, contact us, or interact with us as an educator or institutional customer.

Our privacy contact is privacy@surgeon.ai. Our registered office is 1309 Coffeen Avenue STE 20245, Sheridan, Wyoming 82801, United States of America.

We have not appointed a Data Protection Officer or a UK/EU representative. For any data-protection query, contact privacy@surgeon.ai.

This Notice is written for a worldwide service, with particular attention to users in the United Kingdom and United States. It does not replace a written data-processing agreement with an institution.

2. Important boundaries: education, not patient care

SurgeonAI is not intended to receive patient records, PHI, or identifiable patient information. Do not enter, upload, or record such information. If you do so despite this instruction, we may restrict access, remove the material where feasible, and take proportionate steps to protect it and comply with law.

SurgeonAI is not a covered entity or business associate under HIPAA unless a separate written Business Associate Agreement expressly says otherwise. We do not knowingly seek to collect special-category health information about users. However, information a user voluntarily submits may occasionally contain sensitive personal information; we will handle it only as necessary to protect the Service, respond to the request, comply with law, or with a valid additional legal basis where required.

3. Personal information we collect

Depending on how you use the Service, we may collect:

CategoryExamplesPrimary purpose
Identity and contact dataname, email address, professional role, institution, country, login credentials, and — if you sign in with Google — the email address Google confirms for you (we do not request your Google profile name or picture)account creation, access, support, early-access communication
Professional and training datatraining stage, speciality interests, pathway selection, institution, educator/trainee rolepersonalise educational content and enable institutional features
Learning and assessment dataquestions attempted, answers, confidence ratings, scores, competency domains, learning plans, logbook entries, reflections, WBA drafts, portfolio informationprovide the Service, track progress, create reports and feedback
Voice, video, and transcript dataaudio responses, skills-video submissions, transcripts, captions, recordings of live sessions where enabledconduct simulations, assess learning, accessibility, moderation, support and user-requested review
Communicationsquestions, support requests, survey responses, feedback and correspondencerespond, improve support and manage our relationship
Technical and usage dataIP address, device and browser information, approximate location inferred from IP, log data, cookie identifiers, pages/features used, security eventsservice delivery, security, diagnostics, analytics and fraud prevention
Transaction datasubscription plan, payment status, invoices and limited payment-provider referencesbilling, accounting and fraud prevention

Payment-card details are handled by our payment provider; SurgeonAI should not store full card numbers or CVV data.

Where UK GDPR, EU GDPR, or similar law applies, we use personal information only where a valid legal basis applies. The main bases are:

PurposeTypical legal basis
create and administer an account; provide simulations, learning records and requested features; process paymentperformance of a contract or steps requested before a contract
maintain security, prevent fraud and abuse, troubleshoot, improve reliability, defend legal claims and manage the businesslegitimate interests, balanced against your rights
send optional marketing or non-essential-cookie analyticsconsent, where required; you may withdraw it at any time
meet tax, accounting, regulatory, safeguarding, law-enforcement, or other legal obligationslegal obligation or legitimate interests, as applicable
operate institutional accounts on documented customer instructionscontract and, where SurgeonAI is a processor, the institution’s instructions and the applicable data-processing agreement

We do not use learning profiles, AI classifications, or inferred performance to make solely automated decisions that produce legal or similarly significant effects about you. We do not permit institutions to use them as the sole basis for high-impact decisions.

5. Voice, video, AI, and model improvement

When you choose a voice, video, simulation, or transcription feature, we process the relevant media and transcript to provide that feature. We do not use voice recordings for biometric identification, authentication, or voiceprint profiling.

We do not use identifiable voice recordings, video, transcripts, reflections, logbook entries, portfolio information, or assessment content to train a general-purpose AI model unless you provide separate, affirmative, informed opt-in consent. Where we use de-identified and aggregated information to evaluate or improve the Service, we apply safeguards designed to reduce re-identification risk.

AI generated output may be incorrect. For information about our safeguards and your responsibilities, see our AI, Educational Use and Clinical Safety Policy.

6. Educators, institutions, and data roles

For a self-funded individual account, SurgeonAI normally acts as controller of the personal information described in this Notice.

For an institution-provided account, the institution may be the controller of trainee and educator personal information and SurgeonAI may act as its processor. The institution determines which users are invited, what educator access is granted, and how it uses training information. The institution’s own privacy notice also applies. Please contact the institution first for questions about its decisions; you may also contact us and we will assist as required by law and contract.

We design profile access to be transparent. Educator views of individual trainee profiles should be logged and visible to the trainee within the Service, except where limited access is necessary for security, fraud prevention, or a legitimate confidential investigation.

7. Who we share information with

We may share personal information only with:

  • vetted service providers that help us host, secure, support, analyse, deliver speech/video or AI functions, process payments, send communications, or provide live teaching functionality;
  • an institution, educator, or programme administrator authorised under the relevant account configuration and agreement;
  • professional advisers, auditors, insurers, and corporate affiliates under confidentiality obligations;
  • competent authorities, courts, or other parties where required by law or reasonably necessary to protect rights, safety, security, or prevent fraud; and
  • a buyer, successor, or prospective purchaser in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality protections.

We do not sell personal information. We do not “share” personal information for cross-context behavioural advertising as those terms are defined under certain US state privacy laws. If this changes, we will update this Notice and provide any required opt-out mechanism before the change takes effect.

A current sub-processor list, including the provider name, function, and processing location, is published as our Sub-processors notice at https://surgeon.ai/subprocessors.

8. International transfers

SurgeonAI may process information in the United Kingdom, United States, and other countries in which we or our service providers operate. Those countries may have privacy laws that differ from the country in which you live.

When UK or EU law requires transfer safeguards, we use an adequacy decision where available or appropriate contractual safeguards, such as the UK International Data Transfer Addendum/Agreement or the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate. You may request information about relevant transfer safeguards at privacy@surgeon.ai.

9. Retention

We retain personal information only for as long as reasonably necessary for the purpose collected, including service provision, security, disputes, accounting, legal obligations, and legitimate business records. We describe below what the Service actually does today rather than a target we have not yet implemented: we do not currently run automated deletion timers. Information is kept for the life of the account and removed when the account is deleted or when you ask us to delete it.

DataRetention in practice today
account, profile, and learning data (questions attempted, scores, competency profiles, learning plans, logbook entries, reflections, portfolio information)kept for the life of the account; deleted when the account is deleted or on a verified deletion request
early-access and marketing-list contacts without an accountkept until you unsubscribe or ask us to remove you; you can unsubscribe from any marketing email
audio, video, transcripts, and tutor conversation historykept for the life of the account so you can revisit them; deleted with the account or on request. Voice audio sent for transcription or speech synthesis is processed by the provider and not retained by us beyond the request
security, access, and application logsshort-lived operational logs held by our hosting and platform providers under their standard log-retention settings
payment, invoicing, and tax recordsretained by us and our payment provider for as long as tax and accounting law requires, normally 7 years — these survive account deletion
database backupsheld by our database provider on a rolling cycle and overwritten in the ordinary course; deleted data can persist in a backup until that cycle completes
account-deletion requeststhe request record itself (who asked, when, and its outcome) is kept as evidence that we honoured the request

We may retain de-identified or aggregated information for longer where it no longer identifies you and law permits. Where a longer or shorter period is agreed with an institution, that agreement governs the data it controls.

10. Security

We use technical and organisational measures designed to protect personal information, including access controls, encryption in transit, appropriate encryption at rest where supported, least-privilege access, logging, vendor review, and security testing proportionate to the Service. No online system is completely secure. Please use a unique, strong password and contact us immediately about suspected unauthorised access.

11. Your rights and choices

Depending on where you live and applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or information about how your personal information is used. You may also manage marketing preferences or cookies through the relevant controls.

For users in the UK or European Economic Area, you may complain to the UK Information Commissioner’s Office or your local supervisory authority. You can exercise rights by contacting privacy@surgeon.ai. We may need to verify your identity, and we respond within one month of the request, as data-protection law requires.

To ask us to delete your account, use Settings → Delete my account while signed in, or email privacy@surgeon.ai. Submitting the request records it and opens a case; erasure itself is carried out by our team rather than instantly by the software, and we will confirm when it is complete. Records we must keep by law — for example payment and tax records — are retained as described above.

For US residents, applicable state law may provide additional privacy rights. California residents may request access to, correction of, or deletion of personal information, and may receive information about categories of collection, use, and disclosure. We do not sell or share personal information as described above. You will not be discriminated against for exercising applicable privacy rights. An authorised agent may submit a request where permitted by law; we may verify both the request and the agent’s authority.

12. Cookies and similar technologies

We use strictly necessary technologies to make the website and Service work. We use optional analytics, functionality, or marketing technologies only in accordance with applicable law and your choices. See our Cookie Notice for details and controls.

Where you consent to analytics cookies, our website uses Google Analytics 4, provided by Google Ireland Limited, to measure aggregate use — visits, pages read, and where the site performs poorly. The tag is not requested and no analytics cookie is set until you consent; IP addresses are anonymised by Google Analytics 4, advertising features and ad personalisation are switched off, and we do not use the data for advertising. Google Ireland Limited is listed on our Sub-processors page, and the cookies involved are itemised in our Cookie Notice. You can withdraw consent at any time from the Cookie settings link in the footer.

13. Children

The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18. If you believe a minor has provided us personal information, contact privacy@surgeon.ai so that we can take appropriate action.

14. Changes and contact

We may update this Notice as the Service or law changes. For material changes, we will provide appropriate notice before they take effect. Questions, requests, or concerns should be sent to privacy@surgeon.ai.