Privacy
How Reps Labs LLC handles your information. These sections are taken from our Terms & Conditions, which govern if anything here differs.
Waitlist
When you join the waitlist we collect only your email address. We use it to tell you when your spot opens and for nothing else. Waitlist sign-ups are stored with our form provider, Formspree. To be removed, email support@reps.care.
This website
reps.care sets no cookies and runs no analytics or advertising trackers. Our host keeps standard server logs (time, request path, IP address) for security and debugging.
Contact
Questions about your data: support@reps.care. Security reports: security@reps.care.
6. Voice data and how Practice Sessions are processed
This section describes actual system behavior, in plain terms:
- Your voice audio is processed transiently, not retained. When you speak during a Practice Session, audio is streamed to our server, held in memory only for the duration of transcription, forwarded to a speech-to-text provider, and discarded when the turn completes. Raw audio is not written to a database or file storage.
- Transcripts are retained. The text of the conversation — your transcribed utterances and the Simulated Patient's replies — is stored, along with the structured feedback generated about it.
- LLM processing. Conversation text is sent to our LLM inference provider to generate Simulated Patient replies and feedback. The Simulated Patient's replies are converted to audio by a text-to-speech provider.
- Provider selection. We strive to work with LLM and speech providers that offer zero-data-retention API processing, and all traffic between our servers and these providers is encrypted in transit.
- Safety guardrails. Automated rules screen Simulated Patient output before it is voiced; triggered rules are logged for quality review.
7. Data we collect and how we use it
7.1 What we collect
- Account data: name, email address, organization membership and role.
- Practice data: Practice Session transcripts, structured feedback, ratings, quiz attempts and answers, written reflections, module completions.
- Technical records: LLM request/response records (for quality, cost, and latency monitoring), safety-guardrail trigger logs, server logs including timestamps and request paths, and voice-turn latency measurements.
- Cookies: a single signed session cookie used for authentication. We do not use advertising cookies or third-party analytics trackers.
7.2 How we use it
- To operate the Service: run Practice Sessions, generate feedback, track course progress, and enforce usage limits (currently 10 Practice Sessions per day and 50 per month on the Craft plan; Community limits are set by your cohort's terms).
- To give your Organization visibility (Section 8).
- To maintain quality and safety: our team, and clinical experts under contract with us, may review Practice Session transcripts and generated feedback to audit and improve feedback quality. When transcripts are exported into our offline evaluation tooling, they pass through an automated scrubbing step that masks names, email addresses, and phone numbers, and each export requires sign-off by a named administrator.
- To secure and debug the Service.
7.3 What we do not do
- We do not sell User Content or personal information, and we do not share it with third parties except the service providers we use to operate the Service.
- We will never use User Content to train an AI or machine-learning model to provide therapy or mental-health support.
- We do not serve advertising.
8. Organizational visibility
If your account belongs to an Organization, that Organization's administrators can see your practice activity, including which modules you have practiced, session-level feedback and ratings, and progress against practice requirements the Organization configures. If your participation is part of an academic program or research study, your Organization — not Reps — is responsible for any required program-level notices, ethics approvals, or consents governing its use of that visibility.
13. Data retention and deletion
- Practice data and account data are retained while your account is active so that you and your Organization can review practice history.
- Deletion on request. You (or your Organization, for accounts it manages) may request deletion of your account and associated personal data by emailing support@reps.care. We will delete the data of verified requesters, except for records we must retain for security, legal, or audit reasons, which we will retain only as long as necessary for those purposes.
- Copies in provider-managed database backups, where applicable, expire on the provider's rolling schedule following deletion.
14. Security
- Encryption in transit. All client–server traffic is served over HTTPS/TLS, and all traffic between our servers and our service providers is encrypted in transit.
- Encryption at rest. Database storage is encrypted at rest by our managed database provider.
- Access control. Registration is invitation-only; public self-registration is disabled in production. Access is role-based: clinicians see only their own practice data, Organization administrators see data for their Organization's members, and internal review surfaces are restricted to a small, explicitly allowlisted set of accounts.
- Voice data. Raw audio is never written to persistent storage (Section 6).
- Provider posture. We strive to work with zero-data-retention API providers for LLM and speech processing.
- Secrets. Service credentials are managed as environment secrets and are never committed to source code.
- Incident notice. If we confirm a breach of personal data, we will notify affected users and affected Organizations without undue delay.