top of page

Privacy Policy

 

Effective date: 24 August 2026 Version 1

 

This policy explains what Simicad collects when you use the AI-OSATS mobile application and the simicad.com website, why we collect it, and what control you have over it.

Simicad is operated by SİMİCAD MEDİKAL TEKNOLOJİLER ANONİM ŞİRKETİ, Dudullu OSB Mah DES 2. Caddesi, 34776 Ümraniye/İstanbul ("Simicad", "we", "us"). For any privacy question, or to exercise any right described below, contact simicadsurgical@gmail.com.

1. In short

  • AI-OSATS records your surgical-training practice on a peg-transfer training board, uploads those recordings to our servers, and analyses them to produce a technique score.

  • We collect your name, email address and your recordings. That is substantially all of it.

  • No other user can see your recordings or results. Inside the app they are private to you.

  • We do use recordings to improve our analysis models, and our staff and trained annotators watch them to do it. This is how the scoring gets better. Section 5 explains exactly who sees what, and how to object.

  • We do not sell your data, we do not show advertising, we do not use third-party analytics or tracking SDKs, and we do not send your recordings to any third-party AI service.

  • You can delete your account and all of your data from inside the app, at any time.
     

2. What we collect


2.1 Account information

  • Your name — given by you at sign-up, or taken from your Google or Apple account. Used to identify your account and to address you in the app.

  • Your email address — given by you, or taken from your Google or Apple account. Used for sign-in, account recovery and essential service messages.

  • An account identifier — generated by Firebase Authentication. Used to link your recordings and results to your account.

  • Your sign-in method — Google, Apple, or email and password.

If you sign in with Google or Apple we receive only the name and email address those services release to us. We never receive your password for those accounts. If you use Apple's "Hide My Email", we only ever see the relay address.
 

2.2 Consent records


When you accept these terms, or change your research-participation choice, we record an entry containing: the version of the terms shown to you, your choice, the server timestamp, your platform (iOS/Android) and the app version. We keep this log because data-protection law requires us to be able to demonstrate that consent was given, and when. Withdrawing consent adds a new entry rather than erasing the old one — the log is the history of your decisions.
 

2.3 Training session data


When you record a session, we collect:

  • The video recording of your training session, made with your device camera.

  • Detection data produced on your device while recording — the positions and states of the rings and instruments over time, as numbers. No images.

  • Session metadata — the task performed, timestamps, upload status, and device camera calibration values needed to interpret the geometry.

  • The results we compute — timings, event counts, technique scores and the written feedback shown to you.

What is in the video. The camera is pointed at the training board and is intended to capture the board, the rings and the instrument tips. In practice it will also capture your hands, and it may incidentally capture whatever else is in shot — your surroundings, and potentially other people or their voices if they are nearby. Please record in a setting where that is acceptable to you, bearing in mind that recordings are reviewed by people as described in section 5.2.
 

Never record real patients. AI-OSATS is for practice on a training board. Do not use it to record any clinical procedure, patient, or patient-identifiable information. See the Terms of Service.
 

2.4 Technical and operational data

  • Standard server logs from our hosting providers (IP address, timestamps, error diagnostics), kept for security, abuse prevention and debugging.

  • Counters used to enforce per-user rate limits on uploads.

  • An app-integrity token (Firebase App Check) that tells us a request came from a genuine copy of our app rather than a script.
     

2.5 What we do NOT collect


We do not collect your location, your contacts, your photo library, your health records, advertising identifiers, or any biometric identifier. We include no third-party analytics, advertising or tracking software in the app.
 

3. Why we use it, and our legal basis


For users in the EU, EEA, UK and Switzerland, the lawful bases under the GDPR are as follows.

  • Creating and running your account — performance of a contract with you.

  • Storing, analysing and returning your recordings and scores — performance of a contract with you.

  • Keeping the consent log — legal obligation (GDPR Art. 7(1)).

  • Security, abuse prevention, rate limiting and debugging — our legitimate interests in keeping the Service available and not paying for someone else's misuse of it.

  • Essential service emails, such as security or account notices — performance of a contract, and our legitimate interests.

  • Keeping your recordings for model improvement after you delete your account — your explicit consent (GDPR Art. 6(1)(a)). This is opt-in, and you can withdraw it at any time.

  • Using recordings from active accounts to develop, train, test and correct our analysis models, including human review of the video (section 5.2) — our legitimate interests in building a scoring system that works. You can object at any time, and we will exclude your recordings; see section 5.2.

You are never required to consent to research retention. It is off by default, it does not gate any feature, and you can change it in Settings whenever you like.
 

4. How your data is processed and where it goes

  1. Your device records the session and runs the ring/instrument detector locally on the phone.

  2. The recording and the detection data are uploaded over an encrypted connection to our storage.

  3. Our analysis software downloads the session onto computing hardware we operate and control, produces your score, and writes the result back to your account.

  4. You see the result in the app.

  5. No third-party AI service is involved. Every model that analyses your recording — including the language model used in part of the analysis — runs on our own hardware. Your recordings are not sent to OpenAI, Google, Anthropic, or any other AI provider, and are not used to train anyone else's models.

  6. Sub-processors. We rely on:

  7. Google (Firebase and Google Cloud Platform) — authentication, database, file storage and serverless functions. Your data is stored in Google's infrastructure, and our functions run in the United States.

  8. Google and Apple — sign-in providers, and only if you choose to use them.

  9. Our own servers — video analysis and scoring.

  10. International transfers. If you are in the EEA, UK or Switzerland, your data is transferred to and stored in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which form part of our agreement with Google Cloud.
     

5. Who can see your recordings

  • No other user of AI-OSATS can see your recordings or your results. Access rules enforce that at the storage and database layer, not just in the app.

  • Within SimiCAD, your recordings are seen by people in two situations.
     

5.1 Running the service

  • Authorised SimiCAD personnel access recordings where necessary to operate the Service, investigate a fault, or respond to a support request from you.
     

5.2 Improving our analysis models — including human review

We use recordings uploaded to AI-OSATS to develop, train, test and correct the models that score your technique, and doing that involves people watching them. We want to be specific about what that means, because it is easy to describe vaguely:

  • Recordings are reviewed by SimiCAD staff and by trained annotators working under confidentiality obligations.

  • They mark up what happens in the video — the positions of the rings and the instrument tips, when a ring is grasped, placed or dropped — frame by frame. This corrected annotation is what the models learn from, and it is also how we measure whether a change made the scoring better or worse.

  • The result is used to improve the Service for everyone, not to evaluate you as an individual, and never to report on you to anyone.

  • This applies to recordings from active accounts, not only to recordings kept after an account is deleted (section 6 covers that separate case).

  • How to object. If you would rather your recordings were not used this way, email simicadsurgical@gmail.com and we will exclude them. You keep full use of the Service; nothing about your scores or features changes.

5.3 Others

  • Our infrastructure provider (Google) stores the files, subject to its own security controls.

  • We will disclose data if legally compelled to do so by a valid legal process, and will tell you where we are permitted to.

  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising. 
     

6. How long we keep it

  • Account details — until you delete your account.

  • Recordings, detection data and results — until you delete the session or your account.

  • The consent log — for the life of the account, and for a limited period afterwards as evidence that consent was given.

  • Server logs — a short rolling window, typically no more than 90 days.

  • Recordings retained under research consent — indefinitely, in pseudonymised form. See below.
     

Deleting your account


Settings → Delete account. This is immediate and irreversible. It removes your profile, your name and email, your session records, your results, and your authentication record.

Your recordings are the one thing whose fate depends on your choice:

  • If you did not opt in to research retention (the default), your recordings are permanently deleted along with everything else.

  • If you did opt in, your recordings are moved out of your account and re-filed under a random identifier that is not linked to your name, email or user ID, and are kept so that we can keep improving the analysis models.


One limit on deletion, stated plainly. Deleting your account removes your recordings as described above. It cannot reach back into a model that has already been trained: where a recording of yours was used to improve a model before you deleted it, the model keeps the general capability it learned. The model does not store your video, and your recording cannot be recovered from it, but we cannot honestly claim that deletion undoes past training. The same is true of annotations already merged into a training set.


We describe the research-retention outcome honestly: it is pseudonymised, not anonymised. Sessions from one person stay grouped under a single random identifier, because studying how technique improves over time requires knowing which sessions came from the same trainee. Grouped data of that kind remains personal data under the GDPR, and it remains covered by this policy. It rests entirely on the consent you gave. You are asked to confirm the choice again at the moment you delete your account, and that answer is the one we honour.
 

7. Your rights


Wherever you live, you may ask us to:

  • Access the personal data we hold about you, and get a copy.

  • Correct anything inaccurate.

  • Delete your data (you can do this yourself, in Settings).

  • Restrict or object to processing based on legitimate interests — including objecting to your recordings being used to improve our models (section 5.2).

  • Port your data to another provider in a machine-readable format.

  • Withdraw consent at any time, including research-retention consent (Settings), without affecting the lawfulness of processing before withdrawal.

If you are in the EEA or the UK you also have the right to complain to your national data-protection authority. If you are in California, you have the rights to know, delete, correct, and to opt out of sale or sharing — we do not sell or share, so there is nothing to opt out of — and we will not discriminate against you for exercising any right.

To exercise a right, email simicadsurgical@gmail.com. We will respond within 30 days. We may need to verify that the request comes from the account holder before we act on it.
 

8. Security

  • All traffic between the app and our servers is encrypted in transit (TLS).

  • Files and databases are encrypted at rest by our infrastructure provider.

  • Access rules enforce, at the database and storage layer, that a signed-in user can only read and write their own data.

  • Uploads must carry a valid app-integrity token, and are subject to size, type and rate limits.

  • Consent records are append-only and cannot be altered by the app.
     

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority as required by law.
 

9. Children


AI-OSATS is a professional surgical-training tool intended for adults. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact simicadsurgical@gmail.com and we will delete it.
 

10. Changes to this policy


If we change this policy materially we will update the version and effective date above, and — because the app checks which version you accepted — you will be asked to review and accept the new version before continuing to use AI-OSATS.
 

11. Contact


SİMİCAD MEDİKAL TEKNOLOJİLER ANONİM ŞİRKETİ, Dudullu OSB Mah DES 2. Caddesi, 34776 Ümraniye/İstanbul, simicadsurgical@gmail.com

bottom of page