Privacy Policy
Last updated 12 October 2026
This policy explains what personal data MSRA Practice collects, what we do with it and what your rights are. We collect as little as we can: no advertising, no tracking cookies, and no selling of data.
1. Who is responsible
The data controller is Techne Ltd, company number 14170011, registered office 82a James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE. Questions about this policy or your data go to support@msrapractice.co.uk.
2. What we collect and why
| Data | Why we use it | Lawful basis |
|---|---|---|
| Email address and a password you choose | To create your account, sign you in, and send you sign-in links and service emails such as password resets | Performance of our contract with you (the free tier is a contract too, even though no money changes hands) |
| Your practice attempts: which scenario, the order the options were shown in, your answer, the marks, and the time | To mark your answers, show your results and build your review dashboard, and to improve the scenarios | Contract |
| Feedback you send on a scenario | To review and correct answer keys and explanations | Legitimate interests (improving the Service) |
| Purchase record: the Stripe payment reference, the date, the amount and your access end date | To grant access, handle refunds and disputes, and keep accounting records | Contract; legal obligation (tax records) |
| Support emails you send us | To answer you | Legitimate interests (running the Service) |
| Anonymous page view counts (see section 3) | To understand which pages are used and whether the site works | Legitimate interests. Not personal data once hashed |
We do not ask for your name, address, date of birth, GMC number, the specialty you are applying to, or anything about your application, and we do not collect special category data. Stripe collects your card and billing details on its own payment page under its own privacy policy; we receive only the payment reference, the amount, and the email and name you give Stripe.
The free scenarios need no account. Your answers to them are stored in your browser, together with a server-signed record of each attempt that contains no personal data. If you later sign in, that record is sent to us and added to your account.
When you request a sign-in link, our system checks whether an account already exists for that email so that it can tell you the same login works on all of our sites. This tells whoever enters the address that an account exists; the link itself is only ever sent to that address.
3. Cookies and tracking
We set no advertising or analytics cookies and use no third-party analytics such as Google Analytics.
When you sign in, a session token is stored in your browser's local storage so that you stay signed in. It is strictly necessary for the Service and is removed when you sign out. While you are in the middle of a checkout, a small amount of state is kept in your browser's session storage and cleared when the tab closes.
We count page views ourselves. For each view, our server records the page, the date, the country and the type of device, plus a one-way hash made from the day, your IP address, your browser's identifying string and a secret. The hash lets us count one visitor once per day; it cannot be reversed to your IP address and cannot be linked across days. Your IP address itself is not stored. The hash is not personal data in our hands.
Two third-party services may set their own cookies on pages where they appear: Stripe on its checkout page, and Cloudflare's Turnstile verification widget on our sign-in and checkout forms, which checks that you are not an automated script. Each operates under its own privacy policy.
4. Who processes your data for us
We use these providers to run the Service. Each acts on our instructions under a written contract.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Hosts our database and sign-in system: your account, purchase record and attempts | EU (Ireland) |
| Vercel | Serves the website. Its request logs include IP addresses for a short period for security | USA, with servers worldwide |
| Stripe | Takes payment and holds your card details | EU and USA |
| Resend | Delivers our emails to you | USA |
| Cloudflare | Domain services, email forwarding for our support address, and the Turnstile verification widget | Worldwide |
Where a provider is outside the UK, transfers are covered by the UK's adequacy regulations (for the EU), the UK International Data Transfer Addendum to the EU standard contractual clauses, or the UK Extension to the EU-US Data Privacy Framework, as applicable.
MSRA Practice and our sister products STP Practice and Public Health ST1 Prep share one database and sign-in system, so your account record is the same on all three. Your attempts, results and purchases for each product are kept separately and are only shown on the site they belong to.
We do not sell your data or share it with anyone else, except if the law requires it, or to a buyer if the business is sold, in which case this policy continues to apply.
5. How long we keep it
- Account and attempts: for as long as your account exists. You can ask us to delete the whole account at any time.
- Scenario feedback: up to two years, with the account reference removed when the account is deleted.
- Purchase records: six years after the purchase, because tax law requires it, even if the account is deleted. These records hold your email address and the payment reference only.
- Page view counts: indefinitely, as they contain no personal data.
- Support emails: up to two years.
6. Your rights
Under UK data protection law you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or send it to you in a portable form. You can also withdraw consent where we rely on it, though we do not currently rely on consent for anything. Email us and we will respond within one month. There is no charge.
If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to resolve it first.
7. Security
Connections to the Service are encrypted. Passwords are stored only as hashes. Access to the database is limited to the systems that need it. No system is perfectly secure, so if we discover a breach that affects you we will tell you and the ICO as the law requires.
8. Children
The Service is for doctors applying to specialty training and is not aimed at anyone under 16. We do not knowingly collect data from children.
9. Changes
The date at the top shows when this policy was last changed. If we make a change that affects you materially, we will tell you by email or on the site before it takes effect.