Road to NHS
Privacy
This describes what the system does today. It has not yet been reviewed by a solicitor, and it will be before anything is charged for.
What we hold
Your email address
It is how you sign in. There is no password.
What you told us at setup
Which exam, which sitting date, and any accessibility preferences you set.
Every question you answer
What you chose and whether it was right. This is what makes the selection and the revision schedule work; without it the product is a list of questions in a random order.
A two-letter country code
When you look at prices or buy something. We do not store your IP address — the country is worked out at the edge and the address is never written down.
What we do not hold
Your card details. Those go to Stripe, our payment processor, and we see the last four digits and the country the card was issued in. We use the country to work out whether a regional price applies, and nothing else.
We do not record your screen, and we do not use session replay. A recording of a doctor working through clinical reasoning is not error monitoring.
Analytics
Nothing is loaded and nothing is stored on your device for analytics until you say yes. Not a banner you can scroll past, not consent implied by continuing: the analytics code is not initialised at all, so it makes no requests. If you say no, the product works identically.
Where analytics do run, they run on PostHog’s EU cloud. Errors go to Sentry’s EU region. All data stays in the UK or the EU, including logs and error traces.
Getting a copy
Everything we hold that is about you is downloadable as a single JSON file from your account, immediately, without asking anybody. It is a real export rather than a summary: your answers, your schedule, your subscription and every pricing decision made about a purchase you attempted.
Erasing your account
You can erase your account from the same page, and it happens immediately.
Here is exactly what happens, because the honest version is not the simple one
Your sign-in credentials and your sessions are deleted outright. Your email address, your name and your profile picture are removed from your account record.
Your answers are not deleted, and neither is the metered usage ledger or the governance audit trail. Those tables cannot be deleted from — that is enforced by the database, not by policy — because a question bank whose performance history can be edited cannot make honest claims about its questions, and an audit trail that can be edited is not an audit trail.
What happens instead is that the link between those rows and you is destroyed. The account record survives so the rows still point somewhere, and it holds nothing that identifies a person. What is left is a pile of answers belonging to nobody. That is the erasure, and it is permanent: it cannot be reversed, by us or by anybody, because there is nothing left to reverse it to.
Who else handles it
Everything below is in the UK or the EU, including logs and error traces. That is a rule this product is built to rather than a preference, and it is checked in code: the analytics host is validated against an allowlist of EU endpoints and the application refuses to start if it is pointed anywhere else.
Neon
The database. Everything in the paragraphs above lives here. London (eu-west-2).
Vercel
Hosting. Serves every page and holds request logs, which contain IP addresses for a short period. London.
Mailjet
Sends the sign-in email, and therefore sees your address and the fact that you asked to sign in. Mailjet is a Sinch company; the sending infrastructure is in the EU.
Upstash
The rate limits that stop somebody using our forms to send mail to a stranger. It holds a one-way hash of an address, never the address. EU region.
Sentry
Error reports, so a fault is found before somebody has to tell us about it. No session replay and no personal data attached by default. EU region.
PostHog
Analytics, and only after you say yes. Nothing is loaded until then. EU cloud.
Stripe is named above as the card processor. Nothing is for sale yet, so at the moment nothing reaches it.
Asking us about any of this
Write to privacy@roadtonhs.co.uk. You do not need an account to ask, and you do not need to explain why. If you are on the mailing list and want to come off it without writing to anybody, the removal page does it immediately.
If we get it wrong you can complain to the Information Commissioner’s Office, at ico.org.uk. Doing that does not require asking us first.
Who we are not
Road to NHS is not affiliated with, endorsed by, or part of the NHS, the General Medical Council, or any Royal College. Nothing here is clinical advice.