VerbalWars

Privacy notice

How VerbalWars handles your practice data, voice responses and administrator access.

Version 2026-09-09.5, updated . This is the same document shown inside the app at account setup; reading it here records nothing.

1. Administrator access

The VerbalWars owner and beta administrator can access all information recorded by the service: case requests, sets, attempts, submitted answers, voice transcripts, scores, coaching, feedback, timestamps and technical usage records. Where account information is collected, this access includes that information. Your recorded activity is not anonymous to the administrator.

The administrator may read and review this information to evaluate clinical accuracy, scoring fairness and coaching quality; investigate errors or misuse; provide support; and improve VerbalWars. Review may include individual attempts and comparisons across participants. Participation is not a confidential examination or an assessment protected from administrator review.

Administrator access means access to information the service actually holds. It does not give access to your device, unrelated conversations, account passwords or a library of voice recordings. The current app saves submitted transcripts, but does not keep replayable recordings of your microphone audio.

2. Scope and the current workspace

This notice describes the VerbalWars radiology oral-exam practice application. “We,” “us” and “our” refer to its operator. It also describes the planned invite-only beta where explicitly stated. A policy describes data handling; it does not itself create accounts, access controls or security protections.

This development version uses invitation-only accounts. Clerk verifies your approved email with a sign-in code. Your display name and practice history are stored on the machine running VerbalWars and associated with your account. Other participants cannot access your history through the application. The service administrator retains the access described above.

Clerk sign-in and account-specific histories are implemented in this development version. External hosting and launch arrangements are still being finalized. This notice and the operator details must be reviewed before external beta access begins.

3. Information collected and its sources

Information comes from what you submit, your use of the application, generated practice results, and communications you send to the operator.

  • Profile and contact. We save your approved email, account identifier, display name, account status and setup acknowledgments. Clerk processes email and sign-in information. Appearance preferences remain in your browser. An uninvited visitor can optionally ask us to save their email for an availability notification; that request does not create an account or verify ownership of the submitted email.
  • Practice records. Case-building prompts and settings; selected cases and images; attempt numbers, start and end times; examiner messages; submitted typed answers and voice transcripts; scoring judgments, rubric evidence, response examples, coaching and available feedback.
  • Voice input. Audio you choose to record for transcription, including anything audible in the recording. Recording is optional; text entry remains available.
  • Operational records. Request and job identifiers, provider and model names, prompt versions, input hashes, token counts, processing times, errors and timestamps. Error records may contain fragments of submitted or generated information. Servers and service providers may also process connection information such as IP addresses, browser details and request metadata when handling requests.

4. How information is used

We use information to generate and deliver cases, transcribe answers, conduct simulated examiner conversations, score attempts, provide coaching, save history and calculate progress. We also use it to respond to requests, troubleshoot failures, manage capacity and costs, investigate abuse and meet applicable legal obligations.

During the beta, the administrator may review identifiable activity to improve the library, answer keys, prompts, scoring criteria and application. We may compile aggregate results for internal product evaluation. We do not describe identifiable transcripts or small-group results as anonymous merely because a name has been removed.

This notice does not authorize publishing identifiable attempts, testimonials or performance results, selling response content, or sending it to an employer or examination board for evaluation. Any separate public use identifying you requires a separate basis and appropriate permission. These practice scores are not used by VerbalWars to make employment, licensing or credentialing decisions.

5. Voice, transcription and AI processing

When you activate recording and allow microphone access, your audio is sent through the application to OpenAI for speech-to-text processing. Transcribed text may be submitted automatically in live voice mode and saved with the attempt. Review the transcript when accuracy matters: medical terminology, accents, background noise and interruptions can cause mistakes.

Microphone recordings are processed temporarily and are not intentionally stored as replayable files in the application database. The examiner’s spoken replies are AI-generated audio produced through OpenAI. Temporary playback data can remain in browser memory while the feature is in use. The absence of an app recording archive does not mean providers retain no data.

Case-generation, examiner, scoring and coaching requests send the relevant prompts, selected source material, answer keys and conversation context to the provider configured for that case: OpenAI or Anthropic. A saved case can continue using its original provider. Mock case processing uses simulated responses; optional voice features can still use OpenAI when configured.

Providers apply their own contractual terms, retention periods, safety monitoring and technical controls. Our OpenAI text integration disables stored responses, but that does not eliminate all provider logs, safety retention or temporary processing. We do not promise zero retention, a particular processing country, or that every provider setting is the same. We do not operate a general-purpose model-training program using your submissions; ordinary AI processing and our internal review of product quality are described above.

You can use text instead of recording and revoke microphone access in your browser. Stopping recording does not recall information already submitted or remove an existing transcript. Contact the administrator if a transcript contains information that should be removed.

6. Who receives information

The owner and administrator have the access described above. AI providers receive information needed for requested features. People or service providers assisting with hosting, support or security may receive information needed for their work. Service providers may retain information for their own security or legal obligations under their applicable policies.

Clerk provides sign-in for this development version. External hosting is not yet active. No payment details are collected by the current application. A later paid offering will describe payment processing before checkout.

We do not sell your personal information or share it for cross-context behavioral advertising. We do not give library publishers routine access to your individual answers or results. Authorized access to shared case material does not, by itself, authorize access to another participant’s practice history.

We may preserve or disclose relevant information when reasonably necessary to comply with applicable law or valid legal process, address fraud or security incidents, investigate infringement, enforce valid agreements, or protect people’s rights and safety. We may disclose information at your direction. A merger, acquisition or transfer of the service may involve transferring records subject to applicable law and the privacy commitments governing them; material changes will be disclosed.

7. Browser storage and tracking

The application uses browser storage for your theme, a cookie for sidebar preferences, and account-specific session storage for the last practice location. Clerk uses cookies and session information to support sign-in. Clearing site data removes browser preferences, but does not delete practice records stored on the server or machine running the app.

The current app does not integrate advertising trackers, cross-site advertising, third-party product analytics or social advertising pixels. We do not track your activity across unrelated websites for advertising. There is no separate application response to Do Not Track signals because this tracking is not performed. Service-provider websites linked from these pages have their own policies. New nonessential tracking would require an updated disclosure and any legally required choice before activation.

8. Retention and deletion

Local practice records currently have no automatic expiry. They remain on the machine running the app until deleted or removed by its operator. Browser preferences remain until cleared or replaced. We have not yet adopted the hosted beta’s retention schedule; a defined schedule for practice records, support records, operational logs and backups must be set before launch.

Deleting a case removes that case and its attempts, messages, scores and associated jobs from the active application database. Deleting a set removes its cases and their associated practice records. It does not delete the shared source library, records already held by an AI provider, independent support correspondence or every operational record. In particular, existing AI usage records can remain after case or set deletion.

There is no automatic account-deletion or all-data-erasure workflow in this local version. Contact the administrator for a broader request. We will explain what can be removed, what must be kept, and any applicable time limits. Requesting deletion can remove the history needed to reproduce a score or investigate a problem.

When backups or provider logs exist, deletion from the active app may not immediately erase those copies. Records may also need to be retained for a specific legal obligation, security investigation or dispute. Any exception must have a legitimate basis and does not permit unrelated reuse. The beta’s final policy will specify its applicable retention arrangements rather than imply instant deletion everywhere.

9. Your choices and privacy requests

You can choose text instead of voice, adjust browser permissions, clear local preferences, delete cases or sets using the available controls, stop using the service, and contact the administrator about your information. You may request access, a copy, correction or deletion of information relating to you.

Depending on your location and applicable law, you may also have rights to portability, restriction, objection, withdrawal of consent where consent is the legal basis, an authorized agent, an appeal of a request decision, or a complaint to a regulator. These rights may have exceptions. We will evaluate requests under applicable law, reasonably verify identity, and respond within the required period. We will explain a refusal and available recourse. We do not retaliate for exercising applicable privacy rights.

Do not send passwords, identity documents or patient information with an initial request. Provide enough context for us to find the relevant records. A display name alone does not establish ownership of a particular record; account identity must be verified. Additional verification may be necessary to avoid disclosing someone else’s information.

Providing access to new jurisdictions can require further notices, lawful processing bases, transfer safeguards or local representatives. This notice does not claim those requirements have already been met. The operator must confirm the beta’s supported locations before admitting testers.

10. Security and sensitive information

No storage or transmission system can be guaranteed completely secure. This development version uses individual sign-in and account access checks. Protect access to the machine and browser; deployment and operational safeguards still require review before external launch. A policy or a private invitation does not substitute for technical access controls.

Use only the educational case material supplied or authorized for the service. Do not enter real patient names, dates of birth, medical-record numbers, identifiable images, protected health information, confidential employer information or other people’s private information. Recording in a quiet, private setting helps avoid capturing bystanders. VerbalWars is not offered as a patient-record system and does not provide a business associate agreement through these terms.

If information is submitted accidentally or you suspect unauthorized access, contact the administrator promptly with the case or attempt reference. We will assess the issue and provide notifications when required by applicable law. Do not include the sensitive material again in the report.

11. Age limits and international processing

VerbalWars is intended for adult radiology professionals and trainees aged 18 or over, not children. We do not knowingly seek information from children. If you believe a child has provided information, contact the administrator so it can be investigated and appropriately removed.

AI requests leave the local machine. Providers may process information in the United States and other countries whose privacy laws differ from those where you live. We do not claim a particular data-residency arrangement. Before a hosted beta launches, its supported regions and any required transfer arrangements must be confirmed; accepting these terms is not a substitute for safeguards required by law.

12. Changes and contact

We will date and version updates to this notice. Before a material change to how information is collected, used or disclosed, we will provide an appropriate notice in the application or through an established contact channel, and obtain consent where required. A rewritten policy does not retroactively authorize a materially incompatible use of previously collected information.

For privacy requests, contact the operator using the details below. Until the public contact is confirmed, use your existing contact with the person who supplied this local workspace or reply to a beta invitation if you have received one. Formal legal-operator and contact details must be completed before external launch.

Operator details

Legal operator
Awaiting confirmation before beta launch
Contact
Use your existing contact with the workspace administrator.
Location
Awaiting confirmation before beta launch