Privacy Policy
1. Who we are
PRIMEX ("the Service") is operated by PRIMEX Study ABN 41 535 231 642, based in New South Wales, Australia. This policy explains what data we collect, why, and how we handle it. We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where you access the Service from outside Australia, additional regional rights may apply (see section 13).
Privacy Officer. Questions, access requests, complaints, and notifications under this policy can be directed to the PRIMEX Privacy Officer at primex.study.ai@gmail.com.
2. What we collect
Account information: your email address and name when you register. We need this to create your account and send you access codes or subscription confirmations.
Study data: answers you write for SAQs, MCQ responses, viva transcripts, flashcard progress, and study plan settings. This data is stored to provide the Service and track your progress.
Payment information: payments are processed by Stripe. We do not store your card number, CVC, or bank details. Stripe's privacy policy governs their handling of your payment data.
Usage data: basic analytics such as page views and feature usage to help us improve the Service. We use Plausible (privacy-friendly analytics that runs without third-party cookies) and Google Analytics 4 (uses cookies to measure aggregate site usage and conversions; Google may transfer this data to the United States). We do not use third-party advertising or marketing pixels.
3. How we use your data
We use your data to provide and improve the Service, send transactional emails (access codes, subscription updates), and generate anonymised, aggregated statistics about exam performance and usage patterns. We do not sell your personal data to anyone.
4. AI processing
Your written answers, voice transcripts, and Ask-PRIMEX questions are sent to AI language models (currently Anthropic's Claude; we may use other equivalent providers under no-training commercial terms) for grading, feedback, and answer generation. Anthropic does not use API inputs to train its models under our commercial API agreement. Inputs are processed in real time and are not retained by us beyond the duration needed to deliver the response.
Interview practice and your CV. If you use the Interview practice surface, the curriculum-vitae or biographical text you choose to upload or paste is sent to Anthropic each time you ask for a model answer to be generated or for a CAMP audit of your CV. The CV is used as context so the model answer is grounded in your actual experience instead of an invented persona; without it the model answer is framed hypothetically. Anthropic does not train on this input under our commercial API agreement. Your CV is stored only on the device you saved it on - it is not uploaded to PRIMEX servers in plain text. The generated model answers and CAMP audits are content-addressed cached on Cloudflare R2 so re-listening doesn't trigger a fresh API call; we index these cache entries against your account so that account deletion erases them. Your spoken-answer attempts in Interview practice are not sent to Anthropic for scoring - the engine receives only the typed-or-transcribed text form - and your saved-answer library entries do not include your spoken attempt unless you explicitly opt in by tapping "Save my attempt with this answer".
5. Microphone, voice and audio data
If you choose to use voice dictation in Ask PRIMEX or spoken-response mode in the viva simulator, the Service records short audio clips while you are actively holding the microphone. Audio is sent either to Deepgram (for transcription to text) or processed in the browser via the Web Speech API, depending on your platform. Audio clips are not stored by PRIMEX after transcription is complete. The microphone permission is only active while you tap the mic button; it is not continuously on. The viva simulator may also synthesise spoken examiner replies using a text-to-speech provider (currently ElevenLabs); the text sent for synthesis is the AI-generated response, not your personal data.
6. Community features
Study groups. You can create or join a private study group using an invite code. Other members of that group can see your display handle, your study statistics (such as your SAQ, MCQ and viva counts, your highest tier, and your last-active date), and any messages you post in the group chat. Your name and email address are never shown to other members. You can leave a study group at any time.
Question discussions. On practice questions you can post comments that are visible to other users preparing for the same exam. You post under a display handle of your choosing, or anonymously. Comments are checked by an automated moderation step and may be reviewed or removed by our moderators. Your name and email address are never shown.
Live peer practice. Viva Exchange and OSCE Hot Case Exchange let you book and run live practice sessions with another trainee. During a session your audio, and video if you turn on your camera, are streamed in real time to the other participant through our realtime infrastructure provider (LiveKit). After a session, you and your practice partner can each submit a rubric mark and written feedback on the other's performance, which is visible to the person it is about. In an OSCE Hot Case session, the host can choose to record the session audio so the participants can review it afterwards. When recording is enabled, an audio-only recording is stored in cloud storage and is available to the people who took part in that session. You can ask us to delete a recording at any time.
Cohort activity. Your study activity contributes to anonymised, aggregated statistics shown to other users preparing for the same exam, such as recent activity counts and the most-discussed questions. Individual users are not identified in these aggregates.
Saved answers and Interview session history. When you save a model answer in Interview practice, or complete an Interview practice session, those records are synced to your PRIMEX account so they appear across the devices you sign in on. They sit in your account's private partition and are not shown to other users, not surfaced in community features, and not used to train AI models. They are deleted when you delete your account. Your curriculum-vitae text remains stored only on the device you saved it from and is not part of this sync (see section 4).
Content you post in study groups or question discussions is stored on our servers so it can be shown to other members. You can ask us to remove community content you have posted at any time.
7. Push notifications (mobile app)
The PRIMEX iOS and Android apps may send you push notifications for flashcard review reminders, new features, or subscription updates if you opt in during first-run setup. Notification preferences can be changed at any time from the device Settings app or from PRIMEX account settings. Push tokens are stored only to deliver notifications to your device. Notifications are routed through Apple Push Notification service (iOS) and Google Firebase Cloud Messaging (Android); these providers receive the device token and the notification payload to deliver the message.
8. Data storage and overseas disclosure (APP 8)
Your data is stored on Vercel (hosting and serverless functions), Vercel KV (Redis), Neon (PostgreSQL), and Cloudflare R2 (object storage), with servers primarily in the United States. By using the Service, you consent to your personal information being transferred to, stored in, and processed in the country listed against each provider below.
Before disclosing personal information overseas, we take reasonable steps to ensure each recipient handles your data consistently with the Australian Privacy Principles, including by relying on the recipient's published data-protection commitments, contractual terms accepted as part of using each service, and (where offered) standard contractual clauses or equivalent transfer mechanisms.
We use the following third-party processors to deliver the Service. Each is bound by its own privacy and data-processing terms.
- Anthropic (United States) - AI language model provider (grading, viva, Ask PRIMEX). No-training commercial API agreement. Inputs are processed in real time and are not used to train Anthropic's models.
- Vercel (United States) - application hosting, serverless functions, and Vercel KV database.
- Neon (United States; may replicate to the European Union for performance) - PostgreSQL database for community features (study groups, question discussions, cohort activity).
- LiveKit (United States, with regional edge nodes in the European Union, United Kingdom, and Asia-Pacific) - realtime audio and video infrastructure for live peer practice sessions (Viva Exchange and OSCE Hot Case Exchange).
- Cloudflare R2 (global object-storage network; data primarily held in the United States) - storage for opt-in audio recordings of OSCE Hot Case practice sessions.
- Stripe (United States, Australia) - payment processing. Card details go directly to Stripe; we never receive or store them.
- Resend (United States) - transactional email delivery (access codes, subscription confirmations, account emails).
- Deepgram (United States) - speech-to-text transcription of viva and Ask-PRIMEX voice clips.
- ElevenLabs (United States) - text-to-speech for spoken examiner replies in the viva simulator.
- Plausible (European Union - Germany) - privacy-friendly analytics (page views and feature usage; runs without third-party cookies).
- Google Analytics 4 (Google LLC) (United States, with global processing) - measurement of aggregate site usage, conversions, and feature engagement. Uses cookies.
- Sentry (United States) - application error monitoring; receives stack traces and minimal request metadata when something breaks. We avoid sending personal information to Sentry.
- Internal context-retrieval service (Railway, United States) - a PRIMEX-operated retrieval server that supplies background reference passages to ground AI answers on certain exam sections. Receives the question text only, not your account identity. No personal data is retained by this service beyond the request lifetime.
- Apple Push Notification service (Apple Inc., United States) and Google Firebase Cloud Messaging (Google LLC, United States) - delivery of mobile push notifications.
9. Data retention
We retain your account and study data for as long as your account is active. If you cancel your subscription, your data is kept for 12 months in case you return, then deleted. You can request earlier deletion at any time.
10. Your rights and account deletion
Under the Australian Privacy Act 1988, you have the right to access the personal information we hold about you (APP 12), request correction of inaccurate information (APP 13), make an anonymous or pseudonymous enquiry where practicable (APP 2), and ask us how we handle your information. You can also export your study data and request deletion of your account and all associated data.
In the PRIMEX mobile apps, account deletion is available from Settings → Account → Delete Account. On the web, account deletion is available from the Account page or by emailing primex.study.ai@gmail.com. Deletion requests are actioned within 7 business days.
How to complain. If you believe we have mishandled your personal information, please email primex.study.ai@gmail.com so we can investigate. We will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
Notifiable data breaches. We comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If we become aware of an eligible data breach that is likely to result in serious harm to individuals whose personal information is involved, we will notify those individuals and the OAIC as soon as practicable.
11. Cookies
We use a small number of cookies and similar identifiers on the website:
- Strictly necessary: a session cookie to keep you signed in.
- Analytics (Plausible): aggregated, privacy-friendly site usage. No third-party cookies.
- Analytics (Google Analytics 4): measurement of aggregate site usage, conversions, and feature engagement.
We do not use advertising or marketing pixels. To opt out of Google Analytics across all sites, you can install Google's official browser opt-out add-on or enable "Do Not Track" / "Global Privacy Control" in your browser. The PRIMEX iOS and Android apps do not use advertising SDKs or third-party tracking identifiers.
12. Children
The Service is intended for users aged 16 and over (medical trainees and medical students). We do not knowingly collect personal information from children under 16. If you become aware that a child under 16 has provided personal information to us, please contact us at primex.study.ai@gmail.com so we can delete it.
13. International users
PRIMEX is designed for Australia and New Zealand. International Medical Graduates and other users may access the Service from outside Australasia. Depending on where you are located, additional data-protection law may apply. We address this on a good-faith basis as follows:
- European Economic Area and United Kingdom (GDPR / UK GDPR). Our lawful bases for processing are: performance of a contract with you (delivering the Service); your consent (community features, push notifications, optional analytics cookies); and our legitimate interests in operating, securing, and improving the Service. You have rights to access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your national supervisory authority. To exercise these rights, email primex.study.ai@gmail.com. PRIMEX has not appointed an EU representative at this time; if you are in the EU or UK and need to escalate, please contact us first.
- India (Digital Personal Data Protection Act 2023). If you are accessing the Service from India, you may exercise the rights of access, correction, erasure, grievance redressal, and consent withdrawal by emailing primex.study.ai@gmail.com.
- Other jurisdictions. Where local law gives you rights additional to those in this policy, we will give effect to those rights to the extent we are legally required to. Contact us with the details of your request.
Note that the Service is hosted in the United States; using the Service from any country means your personal information will be transferred to and processed there. See section 8 for the list of overseas recipients and the countries in which they are located.
14. Changes
If we make material changes to this policy, we will notify you by email at least 14 days before the changes take effect. The "last updated" date at the top of the page reflects the most recent revision.
15. Contact
Questions about privacy, or to make a request under Australia's Privacy Act 1988, the GDPR, or any other applicable data-protection law? Email the PRIMEX Privacy Officer at primex.study.ai@gmail.com.