Privacy Policy

Effective: September 21, 2026 · Last updated: September 21, 2026

RT Image Matching Trainer is the name of an educational software product, not a separate business or legal entity. This Privacy Policy explains how Craig Utter, the individual provider and operator ("we", "us", or "our"), handles personal information when you use the website, trainer, account, and related services (the "Service"). It also explains your choices and rights.

Please do not send patient information. The Service does not provide a patient-image or medical-record upload feature and is not intended to collect PHI or identifiable patient data. Training imagery comes from publisher-released and openly licensed research collections, plus synthetic or modified teaching content; the collections, licences, changes, known research-participant conditions, and any source-specific privacy evidence we found are summarized in our Image & Data Credits. When no source-specific evidence is stated, privacy, consent, ethics, de-identification, and re-identification status remain unestablished. An open release or licence does not by itself establish any of those statuses. Do not attempt to re-identify or contact anyone represented in research imagery, and do not put patient information, diagnoses, medical details, or other sensitive data in account fields, instructor access applications, school names, classroom or curriculum text, announcements, rubrics, instructor feedback, live-lab station labels, access-adjustment reasons, or support email.

September 10 attendance correction. Earlier wording incorrectly said that Live Lab checkout deleted the check-in. Checkout ends live presence; the class retains attendance, including check-in and checkout times, for its authorized teaching staff. Section 1 explains the retained information and deletion controls. Contact support@rtimagematch.com with questions about an earlier session.

1. Personal information we collect

CategoryWhat it includes and how we receive it
Account and authenticationYour required email address; optional first and last name or username if present on your account; internal Clerk user ID; account settings; verification state; sign-in and session events; the accepted policy version and time; SHA-256 fingerprints identifying the canonical Terms and Privacy Policy source documents presented for acceptance; confirmation that you meet the minimum age of 18; and related browser, device, and security information. We do not ask for or store your date of birth. Clerk handles credentials; we do not receive your raw password.
Instructor access applicationsIf you request instructor access, we store the verified email address already attached to your Clerk account, the school you selected or named, educational role, optional program name and expected student count, intended-use description, request status and timestamps, the application notice version you acknowledged, the school label the site owner records if the application is approved, and the internal account identifiers needed to review and apply the role. You can view your own request details and status. Only the site owner can review applications across accounts or see the stored verified email; other instructors and students cannot see them, and application email addresses never appear on a class roster. Do not include student, patient, or other sensitive information in an application.
School affiliationWhen the site owner approves an instructor application, they may record the instructor's school as a label. We then store the school name, status, and email domains; the affiliation status; the instructor's internal Clerk user ID and verified-email snapshot; who recorded, changed, or ended the affiliation; durable site-owner instructor-access denial state; and relevant dates and internal record identifiers. A school is a label, not a permission: it authorizes nothing, and there are no institution administrators, member lists, or institution invitations. An instructor has at most one active school at a time. Changing it moves the school label on the classes that instructor owns to the new school, and removing it clears those labels; teaching access, rosters, join codes, staff roles, modules, and results are unchanged. Only the site owner can record, change, or remove a school or see which instructors are affiliated with it and their verified-email snapshots. An instructor sees their own school on the instructor dashboard; other instructors and students cannot see affiliations or verified-email snapshots. A school name or an email domain alone never creates affiliation or instructor access, and a school change never lifts a site-owner denial. When you apply, we derive the domain of your verified email (the part after the @) to show you the listed schools recorded with that domain or a parent of it; the domain only narrows that list, and you can always name a school instead. A school's email domains are recorded by the site owner or seeded from the approving applicant's verified email domain, never from a public mail provider, and are stored with the school, not with you. School affiliation does not give anyone access to a class, roster, assignment, attempt, or student record; each class remains separately controlled by its owner and scoped teaching-staff roles.
Training profileCases attempted or cleared, times, residual-error scores, compact lifetime per-axis residual summaries, recent-weighted per-axis summaries for up to eight recently scored cases, recent activity, XP/level, streaks, achievements, preferences, and up to three compact Full Treatment replay timelines. A replay includes the case and outcome, time, summary workflow measures, a short outcome reason, and up to ten timestamped simulator events; it does not contain patient data, audio, or review conversations. The trainer stores working data locally in your browser and, when you are signed in, saves it through an authenticated API to a training-profile record in our Neon database, keyed by your internal Clerk user ID, so progress follows you across devices. Your leaderboard participation and name-display choices are also kept on your Clerk account record so the leaderboard service can honor them. This synced profile is written by your browser, is readable only by your own signed-in session, and is not independently verified as a competency or assignment record. Match review may read scored-history and replay summaries to explain scored 2D/2D, CBCT, and Full Treatment results, identify lifetime and recent matching patterns, and fit a small temporary case-ranking network in browser memory. After you open a review, it may compare that focus with the next comparable scored residual; this session-only suggestion outcome modestly adjusts later suggestions in the same page session. This is temporary, individual personalization, not training a shared or general-purpose AI model. Its temporary weights are discarded when the page reloads, as is all session-only outcome feedback; it does not save another attempt timeline, Practice reviews, review questions, or review answers. Room command help does not read the training profile. Its typed commands, previews, and replies remain only in page memory and are discarded when you leave Machine Room or reload the page.
Public challenge leaderboardsLeaderboard participation is on by default for new training profiles and can be turned off at any time under Account > Trainer preferences. Only Daily and Weekly Challenge clears are published; each board combines Standard, Advanced and Expert and ranks by fastest verified completion time, with difficulty shown only as context. A separate all-time standing is derived on request from those daily and weekly placements and shows points, ranked-clear counts and best placing for the current calendar half-year; no additional per-user record is stored for it, though the computed ordering is cached briefly. Regular case personal bests remain in your private training profile. Upstash stores your internal Clerk user ID, best server-derived challenge time and maximum translation/rotation residuals, challenge period and tier, rank data, and timestamps. A short-lived ranked-run record also stores the server-issued simulated setup and start time for up to four hours; your final simulated couch correction is used to verify the result and is not retained as a leaderboard field. A per-account ranked-attempt count for each challenge period and difficulty enforces the attempt limit and automatically expires eight days after that challenge period resets. Public results show a stable pseudonymous alias such as "Trainee-8F3A". If you separately enable name display, they show your first name and last initial, or your username if no first name is available. Anyone can read the public top results; the raw account ID and attempt count are not returned publicly. Turning participation off requests removal of your stored leaderboard rows and active ranked runs; the attempt-limit counter may remain until its scheduled expiry.
Private classes and assignmentsIf you create, staff, or join a class, we store the class name, term label, bounded description, instructor and teaching-staff display-name snapshots and scoped roles, hashed join or one-time staff-invite codes and expiration, membership and end state, the last classroom revisions displayed to a student, curriculum plans and objectives, ordered module settings and directions, immutable deployed-course snapshots, assigned cases, announcements and teaching-author display-name snapshots, and live-lab session state, including the required module linked to a session and optional instructions and location. A student appears in Live Lab only after explicitly joining. We then store the check-in time, optional station label, selected working/waiting/help/finished status, help-request and staff-acknowledgement state, and latest presence time. While that joined trainer tab is visible, it refreshes only the latest presence time about every 30 seconds; we do not store a heartbeat history. Explicit checkout ends live presence but retains the first check-in time, checkout time, station, and latest activity/help information as class attendance. After a session ends, the class owner and its authorized co-instructors, graders, and observers can view this attendance; school affiliation alone does not grant access. Ended-session attendance is kept with the class until class or account deletion, subject to earlier rolling-history removal and the backup limits below. Starting a new lab removes ended sessions beyond the newest 96, together with their attendance. Leaving or being removed from a class removes check-ins for its active or paused labs; earlier ended-session attendance and other retained class records remain. Archiving a class ends its live labs without erasing that history. The private instructor view can show online/away/disconnected state, module progress, and the current assigned case. Live Lab does not monitor ordinary Practice or general trainer browsing. For a 2D/2D or CBCT/MR class attempt, we store the server-issued simulated setup, idempotent start request identifier, start and expiration times, each submitted Check Match correction, the server-derived residual and acceptance result for that check, the final status, and elapsed time. These server-recorded check points form a bounded private replay. For a Full Treatment attempt, we instead store a bounded terminal summary reported by the browser simulator, including whether its imaging and delivery stages completed, fields and fictional monitor units delivered, collision count, selected setup residuals, pass/fail outcome, server timer, and a simulator_reported source label. The server validates the summary's type, bounds, and internal pass consistency but cannot independently reconstruct or regrade every in-browser machine action. The Service does not record the screen, keystrokes, continuous pointer movement, camera, microphone, or patient image. Private teaching records may also include instructor feedback, a fixed observation rubric and note that do not alter the automated result, separate staff choices to release that rubric or replay to the student, a retry grant, targeted follow-up, or an additive access adjustment such as extra time or attempts, earlier opening, later due date, and a short instructor-entered reason. A student sees their own modules, announcements, live-lab state, effective adjustment, feedback, results, and read-only history for classes they left or were removed from or that were archived; a rubric or replay is shown only after authorized staff releases it. A student does not see the private adjustment reason or another student's activity. The class owner and authorized co-instructors, graders, or observers receive only the class access their role permits; email addresses and stable account identifiers are not shown. Personal training history, independent Practice, and Challenges are not shared with Classroom. The former optional personal-summary sharing feature has been retired; its active shares were revoked and its copied summaries deleted from the active database. Revoked consent records retain class and account references, the consent version, and dates, without training content, until the membership, class, or account is deleted. These records are not public and are educational records only, not evidence of clinical competency or certification.
PaymentsIf you choose to make a voluntary one-time support payment, PayPal collects the contact, device, fraud-prevention, transaction, and payment information needed for its hosted checkout. PayPal provides us transaction details such as payer name and email, amount, currency, date and time, status, transaction ID, payment-method type, fees, net amount, and refund or dispute information. We do not receive or store your full card number, bank-account number, security code, or PayPal credentials. The support payment is not linked to your Clerk account. An existing account may separately retain historical information or controls for a legacy supporter subscription handled by Clerk Billing through Stripe.
Technical, usage, and security dataIP address, request time, requested URL or path, response status, browser/user-agent and device type, approximate region inferred from network information, authentication diagnostics, rate-limit events, and Content Security Policy violation details such as affected page, blocked resource, directive, source file, and line number. An authentication security challenge may also process connection and anti-bot signals such as a TLS fingerprint, site key, page origin, and challenge result. We strip query strings and fragments from URL-like CSP report fields before logging them.
Support and feedbackYour email address and name, message contents, attachments, and standard email metadata when you contact us or send a suggestion. Messages open in your own email application; do not include patient or other sensitive information.
Optional microphone useTwo optional DIBH exercises can recognize short coaching commands through the browser's Web Speech API. They prefer on-device recognition when the browser reports it available; otherwise the browser vendor or its speech provider may process audio. CT Simulation also uses a separate local Web Audio level meter only to show whether the microphone hears sound. Our servers do not receive microphone audio or recognized text, and we do not record or store either, create a voiceprint, or use voice for identification. CT Simulation can keep matched command identifiers, such as “hold” or “abort,” in its fictional in-page examination record, but not the spoken transcript.
Local-only simulation records and downloadsFictional CT Simulation setup notes, accessories, measurements, comments, simulator-rendered setup views, DIBH rehearsal/gate metrics, interrupted-attempt reasons, educational source/morph comparison images, and report state remain in the current page's memory. The setup and DIBH comparison views are rendered from simulator data in the browser; they do not use a webcam, camera capture, patient photograph, image upload, or OIS connection, and the rendered output is not uploaded by the Service. The DIBH comparison is a labeled deterministic teaching deformation of the same released source image, not true paired patient data. CT Simulation HTML reports, training-progress JSON exports, classroom calendar files, personal classroom-history CSV files, and instructor cohort-progress CSV files are generated in your browser and downloaded directly to your device; we do not receive those files. Do not replace fictional fields with real patient information. Once downloaded, a file remains under your device's and chosen application's control until you delete it.
Cookies and local device dataStrictly necessary authentication and security cookies; local browser storage for progress and preferences; a service-worker cache for public app files; and a tab-scoped marker containing the policy version and time when legal acceptance is pending. That marker expires within 30 minutes. The support page does not embed PayPal code, but PayPal may use cookies and similar technologies on its own hosted checkout after you follow the link. Stripe may set necessary or fraud-prevention cookies if you use controls associated with a legacy supporter subscription.

Former-student history boundary. When a student leaves or is removed, or when a class is archived, we freeze the learner-visible class name, term, description, instructor, and teaching-staff list. The read-only view contains only modules first published before that boundary, plus any module on which the student already has an attempt. Later class activity and announcements are not disclosed through that past-class view.

Where this information comes from. We receive information directly from you or your class instructor, from the verified account email maintained by Clerk when you request instructor access, automatically from your browser and use of the Service, and from providers that operate the account, security, payment, hosting, classroom, leaderboard, legacy billing, and support-email functions described below. We infer only limited information needed for those functions, such as approximate region from network data and matching patterns from your private scored-history summaries. We do not buy student profiles from data brokers.

What is required and what is optional. An email address, a password handled by Clerk, necessary session and security data, acceptance of the current Terms and Privacy Policy, and confirmation that you are at least 18 are required to create an account and use authenticated trainer features. If you do not provide them, you can still read the public website and guides but cannot use authenticated features. Joining or staffing a class, joining a particular Live Lab, requesting instructor access, and labelling a class with a school are optional. An instructor request requires the school, educational role, intended use, application acknowledgement, and a verified account email; the program name and expected student count are optional. If you join or staff a class, the display-name snapshot and classroom records described above are shared with the class owner and authorized staff according to their roles. A live-lab station label is optional. Your name, leaderboard name display, microphone access, support messages, and any one-time support payment are otherwise optional. Challenge leaderboard participation starts on for new profiles but can be turned off at any time in Settings.

2. How and why we use personal information

3. Legal bases where GDPR or UK GDPR applies

4. When and with whom we disclose information

We disclose only what is reasonably needed for the purposes above:

We may also disclose information when reasonably necessary to comply with law or valid legal process; protect a person, rights, or the Service; investigate fraud or security incidents; or complete a merger, financing, reorganization, asset sale, or similar transaction. In a transaction, the recipient must handle personal information consistently with applicable law and any notice we provide.

Public disclosure: while leaderboard participation is on, the alias or separately selected display name, best challenge time, maximum residuals, rank, challenge period, tier, and case sequence are publicly available. Regular-case personal bests are not published. Turn participation off in Settings if you do not want challenge results posted, and do not enable name display if you do not want that name connected with your results.

Full Treatment in Live Labs: joining a direct Full Treatment lab allows the simulator to save each run’s start and end times, completion or early-exit status, and simulator-reported imaging, delivery, treatment-field, monitor-unit, collision, residual, scan, hold, and re-image summary. Repeats are retained separately. These ungraded records are visible only to you and authorized teaching staff for that class, follow the existing Live Lab retention and deletion rules, and may be included in a private instructor report. A disconnect without a saved outcome is not recorded as a failed treatment. Shared class displays do not show individual treatment outcomes.

Class disclosure: class rosters, curricula, modules, announcements, live-lab check-ins, rubrics, adjustments, replays, and assignment results are not public. Students can see only their own assigned records, effective adjustment, and personal history, not the instructor-entered reason or another student's activity; an observation rubric or replay is shown to the student only after authorized staff separately releases it. A student who leaves or is removed, or whose class is archived, retains a read-only view of the frozen class context and work first published before the relationship ended, plus modules with their own attempt, while those records are retained. Later class activity and announcements are excluded. The class owner and authorized co-instructors, graders, or observers can see or manage only the class information permitted by their role. One-time staff codes must be shared only with the intended authorized educator.

Personal training history: your own training profile remains private to your account and is not shared with Classroom. The optional personal-summary sharing feature has been removed. Previously copied summaries have been deleted from the active database and cannot be refreshed or restored by an older app tab. Assigned-module results and authorized Live Lab attendance remain separate classroom records.

Instructor application disclosure: instructor access applications are not public. Application details and verified account emails are available only to the applicant and the site owner, except that the applicant view does not repeat the stored email address.

School disclosure: school affiliations are not public. Only the site owner can see which instructors are affiliated with a school and their verified-email snapshots, record or change a school, or globally revoke an instructor; a durable denial prevents a later application or school change from undoing that decision until a later site-owner approval. An instructor sees their own school, not other instructors' affiliations or any email list. A class's school label is visible to that class's members as part of the class information they already see; it names no person. School affiliation alone reveals no student, roster, class, assignment, or attempt information and grants no class-level access.

5. Cookies, local storage, and tracking choices

On our site, we use Clerk cookies and similar storage that are necessary for sign-in, sessions, fraud prevention, and security. The trainer uses local storage for progress and preferences, a short-lived tab marker for pending legal acceptance, and a service worker that may cache public app files for faster or offline-tolerant loading. CT Simulation's fictional documentation workspace remains in page memory rather than being synced or uploaded. Files you choose to download are controlled through your device and chosen applications, not browser site-data controls. You can remove browser-held data through site-data controls, but blocking essential cookies can prevent sign-in or protected cases from working.

Clerk's session cookies are first-party or same-site, strictly necessary, and are not used by Clerk for cross-site tracking. Clerk may process authentication events and browser, device, IP-address, and security signals to operate and protect accounts, and may summarize production sign-in, sign-up, and retention activity in its authentication dashboard. PayPal may process cookies, device data, IP addresses, transaction activity, and payment details on its hosted checkout for payment administration, fraud prevention, and legal compliance. Stripe may do the same for legacy billing controls. We do not embed PayPal advertising code or ask these providers to target advertising to you.

We do not currently use an advertising network, behavioral-advertising pixel, or a general audience-analytics product, and we do not set advertising cookies. We do not respond differently to browser "Do Not Track" signals because we do not engage in cross-site behavioral tracking. See Section 9 for Global Privacy Control.

6. Microphone and browser speech recognition

The optional standalone DIBH coaching case can use the Web Speech API to recognize short commands. The browser asks for permission before microphone access. We do not record, store, or transmit the audio to our servers, create a voiceprint, or use voice for identification. Recognized text is used only in the current page to display and run the matched coaching command; it is not added to your account or sent to our servers. The browser may perform recognition on the device or send audio to the browser vendor or its speech provider; that provider's policy and retention practices apply. You can decline permission and use the on-screen controls instead, revoke permission in browser settings, or stop the case to release the microphone.

The optional CT Simulation DIBH exercise reuses the same short-command vocabulary with a required Push-to-talk workflow. It requests on-device recognition first when the browser supports it and labels browser-service recognition when an on-device language pack is unavailable. Recognized text is displayed only in the current page and is not retained in the fictional examination result; that result may keep only the matched command identifier and whether it occurred during acquisition. A separate Web Audio meter analyzes a live level locally and is not connected to an output, recorder, or network sender. We do not record, store, receive, or upload audio, transcripts, or sound-level samples. Microphone and speech access are required only for that optional CT Simulation breath-hold branch; if you decline them, choose another CT Simulation scan exercise or leave CT Simulation. Leaving, completing, losing focus, or disconnecting releases the microphone.

7. Data retention

8. Your choices and privacy rights

You can correct account information, export training progress, export your personal classroom-attempt history, reset progress, control leaderboard participation and name display, manage browser permissions, and delete the account through the account page and Classroom workspace where those controls are available. The personal classroom export is generated in your browser from your own history; historical personal training-share consent records and other classroom, school-affiliation, and instructor-application records are not part of the local training-progress export, so contact us for a verified access, correction, portability, or deletion request involving those records.

Depending on where you live, you may have rights to know or access personal information; correct it; delete it; obtain a portable copy; restrict or object to processing; withdraw consent; and appeal a denied privacy request. You may also use an authorized agent where law permits. We may ask for information reasonably needed to verify identity, authority, and account ownership. We will respond within the time required by applicable law and will not discriminate against you for exercising a right.

If you are in the EEA, United Kingdom, or Switzerland, you may complain to your local data-protection authority. You may also object to legitimate-interest processing and request information about transfer safeguards.

9. Sales, targeted advertising, and Global Privacy Control

We do not sell personal information for money. We also do not "sell" or "share" it for cross-context behavioral advertising, use it for targeted advertising, or knowingly sell or share personal information of users under 18 as those terms are used in applicable U.S. state laws. Because we do not conduct that processing, there is currently no sale/share opt-out for a Global Privacy Control signal to activate. If our practices change, we will update this policy and honor applicable opt-out signals.

10. International data transfers

We operate from the United States, and providers may process information in the United States and other countries whose laws may differ from yours. Where required, transfers rely on a lawful mechanism such as an adequacy decision, approved contractual clauses, a provider's recognized certification framework, or another safeguard. Contact us to request more information about safeguards relevant to your information.

11. Children's privacy

The Service is intended only for adults age 18 and older and is not directed to children or minors. We do not knowingly allow anyone under 18 to create or maintain an account or use a leaderboard, and we do not knowingly collect personal information from anyone under 18. We ask only for confirmation that an account holder is at least 18; we do not collect a date of birth. If you believe someone under 18 provided personal information, contact us so we can investigate and delete it.

12. Security

We use reasonable safeguards designed for the nature of the Service, including HTTPS/HSTS in transit, provider-managed authentication, private case-file storage, access controls, rate limiting, restrictive browser security headers, limited logging, and removal of session credentials and query strings from the diagnostic URLs we control. No system is completely secure. Protect your account, use a unique password, and notify us promptly about suspected unauthorized access.

13. Automated scoring

The trainer automatically calculates educational scores, class-assignment results, pass/fail feedback, progress, achievements, and leaderboard rank from simulated activity. The instructor dashboard also applies simple rules to label whether a stored class attempt was within tolerance, timed out, or ended with translation or rotation outside tolerance, and presents the server-recorded check sequence as a replay. Instructor rubric ratings, notes, presence labels, and feedback are human-entered teaching observations; they do not change the recorded correction, residual, result, tolerance, or grading version. Match review's temporary local ranking network ranks which suggestion to show using lifetime and recent-weighted scored summaries, compact Full Treatment replay summaries, and temporary same-session outcome feedback; it does not change scores, access, leaderboard validity, outcomes, or safety controls. These outputs do not make decisions that produce legal or similarly significant effects and must not be used as evidence of clinical competency, employment qualification, certification, or licensure.

14. Changes to this policy

We may update this policy as the Service or law changes. We will post the new effective date. For a material change, we will provide reasonable advance notice by email, an in-product message, a site notice, or another appropriate method, except when an immediate change is needed for law, security, or abuse prevention. If consent is legally required for a new use, we will request it.

15. Contact

The controller responsible for this policy is Craig Utter. For privacy questions, requests, complaints, or appeals, email support@rtimagematch.com. Please use the subject "Privacy request" and do not include patient information or unnecessary sensitive data.