Privacy Policy

Effective: July 19, 2026 · Last updated: July 25, 2026

RT Image Matching Trainer is the name of an educational software product, not a separate business or legal entity. This Privacy Policy explains how Craig Utter, the individual provider and operator ("we", "us", or "our"), handles personal information when you use the website, trainer, account, and related services (the "Service"). It also explains your choices and rights.

Please do not send patient information. The Service does not provide a patient-image or medical-record upload feature and is not intended to collect PHI or identifiable patient data. Training imagery comes from research collections described by their publishers as de-identified, plus synthetic or modified teaching content. Do not put patient information or other sensitive data in account fields, feedback, or support email.

1. Personal information we collect

CategoryWhat it includes and how we receive it
Account and authenticationName, username (if used), email address, internal Clerk user ID, account settings, verification state, sign-in/session events, policy version and acceptance time, confirmation that you meet the minimum age of 18, and related device or security information. We do not ask for or store your date of birth. Clerk handles credentials; we do not receive your raw password.
Training profileCases attempted or cleared, times, residual-error scores, recent activity, XP/level, streaks, achievements, and preferences. The trainer stores working data locally in your browser and may copy it into your signed-in account so progress follows you across devices.
Public challenge leaderboardsLeaderboard participation is on by default for new training profiles and can be turned off at any time in Settings. Only Daily and Weekly Challenge clears are published; each board combines Standard, Advanced and Expert and ranks by fastest verified completion time, with difficulty shown only as context. A separate all-time standing is derived on request from those daily and weekly placements and shows points, ranked-clear counts and best placing for the current calendar half-year; no additional per-user record is stored for it, though the computed ordering is cached briefly. Regular case personal bests remain in your private training profile. Upstash stores your internal Clerk user ID, best server-derived challenge time and maximum translation/rotation residuals, challenge period and tier, rank data, and timestamps. A short-lived ranked-run record also stores the server-issued simulated setup and start time for up to four hours; your final simulated couch correction is used to verify the result and is not retained as a leaderboard field. Public results show a stable pseudonymous alias such as "Trainee-8F3A". If you separately enable name display, they show your first name and last initial, or your username if no first name is available. Anyone can read the public top results; the raw account ID is not returned publicly. Turning participation off requests removal of your stored leaderboard rows and active ranked runs.
Legacy billingWe do not currently offer or accept new purchases, donations, tips, subscriptions, crowdfunding, or recurring support payments. An existing account may retain historical information or controls for a legacy supporter subscription. For legacy billing administration, we may retain limited details such as contact or receipt email, amount, currency, transaction date and status, and card brand and last four digits. We do not receive or store the full card number.
Technical, usage, and security dataIP address, request time, requested URL or path, response status, browser/user-agent and device type, approximate region inferred from network information, authentication diagnostics, rate-limit events, and Content Security Policy violation details such as affected page, blocked resource, directive, source file, and line number. We strip query strings and fragments from URL-like CSP report fields before logging them.
Support and feedbackYour email address and name, message contents, attachments, and standard email metadata when you contact us or send a suggestion. Messages open in your own email application; do not include patient or other sensitive information.
Optional microphone useLive microphone audio used only when you grant permission for the DIBH voice-coaching feature. We do not record, store, or receive that audio; depending on your browser, its speech-recognition provider may process it.
Cookies and local device dataStrictly necessary authentication and security cookies, local browser storage for progress and preferences, and a service-worker cache for app files. Stripe may set necessary or fraud-prevention cookies if you use controls associated with a legacy supporter subscription.

2. How and why we use personal information

3. Legal bases where GDPR or UK GDPR applies

4. When and with whom we disclose information

We disclose only what is reasonably needed for the purposes above:

We may also disclose information when reasonably necessary to comply with law or valid legal process; protect a person, rights, or the Service; investigate fraud or security incidents; or complete a merger, financing, reorganization, asset sale, or similar transaction. In a transaction, the recipient must handle personal information consistently with applicable law and any notice we provide.

Public disclosure: while leaderboard participation is on, the alias or separately selected display name, best challenge time, maximum residuals, rank, challenge period, tier, and case sequence are publicly available. Regular-case personal bests are not published. Turn participation off in Settings if you do not want challenge results posted, and do not enable name display if you do not want that name connected with your results.

5. Cookies, local storage, and tracking choices

On our site, we use Clerk cookies and similar storage that are necessary for sign-in, sessions, fraud prevention, and security. The trainer uses local storage for progress and preferences, and a service worker may cache app files for faster or offline-tolerant loading. You can remove these through browser site-data controls, but blocking essential cookies can prevent sign-in or protected cases from working.

Clerk and Stripe may collect and process cookies, device identifiers, IP addresses, and activity from your interactions with their services, including activity over time and across sites or services that use them, for authentication, account security, payment processing, fraud prevention, and legal compliance as described in their own privacy policies. We do not ask them to use this information to target advertising to you.

We do not currently use an advertising network, behavioral-advertising pixel, or a general audience-analytics product, and we do not set advertising cookies. We do not respond differently to browser "Do Not Track" signals because we do not engage in cross-site behavioral tracking. See Section 9 for Global Privacy Control.

6. Microphone and browser speech recognition

The optional DIBH coaching case can use the Web Speech API to recognize short commands. The browser asks for permission before microphone access. We do not record, store, or transmit the audio to our servers. Some browsers send audio to the browser vendor or its speech provider; that provider's policy and retention practices apply. You can decline permission and use the on-screen controls instead, revoke permission in browser settings, or stop the case to release the microphone.

7. Data retention

8. Your choices and privacy rights

You can correct account information, export training progress, reset progress, control leaderboard participation and name display, manage browser permissions, and delete the account through the account page where those controls are available. You may also contact us.

Depending on where you live, you may have rights to know or access personal information; correct it; delete it; obtain a portable copy; restrict or object to processing; withdraw consent; and appeal a denied privacy request. You may also use an authorized agent where law permits. We may ask for information reasonably needed to verify identity, authority, and account ownership. We will respond within the time required by applicable law and will not discriminate against you for exercising a right.

If you are in the EEA, United Kingdom, or Switzerland, you may complain to your local data-protection authority. You may also object to legitimate-interest processing and request information about transfer safeguards.

9. Sales, targeted advertising, and Global Privacy Control

We do not sell personal information for money. We also do not "sell" or "share" it for cross-context behavioral advertising, use it for targeted advertising, or knowingly sell or share personal information of users under 18 as those terms are used in applicable U.S. state laws. Because we do not conduct that processing, there is currently no sale/share opt-out for a Global Privacy Control signal to activate. If our practices change, we will update this policy and honor applicable opt-out signals.

10. International data transfers

We operate from the United States, and providers may process information in the United States and other countries whose laws may differ from yours. Where required, transfers rely on a lawful mechanism such as an adequacy decision, approved contractual clauses, a provider's recognized certification framework, or another safeguard. Contact us to request more information about safeguards relevant to your information.

11. Children's privacy

The Service is intended only for adults age 18 and older and is not directed to children or minors. We do not knowingly allow anyone under 18 to create or maintain an account or use a leaderboard, and we do not knowingly collect personal information from anyone under 18. We ask only for confirmation that an account holder is at least 18; we do not collect a date of birth. If you believe someone under 18 provided personal information, contact us so we can investigate and delete it.

12. Security

We use reasonable safeguards designed for the nature of the Service, including HTTPS/HSTS in transit, provider-managed authentication, private case-file storage, access controls, rate limiting, restrictive browser security headers, limited logging, and removal of session credentials and query strings from the diagnostic URLs we control. No system is completely secure. Protect your account, use a unique password, and notify us promptly about suspected unauthorized access.

13. Automated scoring

The trainer automatically calculates educational scores, pass/fail feedback, progress, achievements, and leaderboard rank from simulated activity. These outputs do not make decisions that produce legal or similarly significant effects and must not be used as evidence of clinical competency, employment qualification, certification, or licensure.

14. Changes to this policy

We may update this policy as the Service or law changes. We will post the new effective date. For a material change, we will provide reasonable advance notice by email, an in-product message, a site notice, or another appropriate method, except when an immediate change is needed for law, security, or abuse prevention. If consent is legally required for a new use, we will request it.

15. Contact

The controller responsible for this policy is Craig Utter. For privacy questions, requests, complaints, or appeals, email support@rtimagematch.com. Please use the subject "Privacy request" and do not include patient information or unnecessary sensitive data.