Legal
Privacy Policy
Controller: ObMob, LLC, a Connecticut limited liability company ("ObMob," "we," "us," or "our")
Service: The ObMob websites, web application, and any related application launched in the future (the "Service")
Contact: hello@obmob.ai
This Privacy Policy explains the information ObMob collects, how it is used, the providers that process it, the periods for which it is retained, and the choices available to you.
1. Key points
- ObMob is an educational exam-preparation service for physicians and physicians-in-training.
- Users may provide only case information de-identified under the HIPAA Safe Harbor method. ObMob does not want or authorize the submission of Protected Health Information ("PHI").
- ObMob stores session transcripts, scorecards, and study records. ObMob does not persist voice-session audio in its own storage.
- ObMob does not sell personal data, share it for cross-context behavioral advertising, or use third-party advertising trackers.
- ObMob uses identified providers for authentication, hosting, database, payments, voice transport, speech recognition, language-model processing, text-to-speech, retrieval, and email.
- You may request access, correction, export, or deletion by using available account controls or contacting hello@obmob.ai.
2. Information we collect
2.1 Account information
When you sign in with Google, ObMob receives your name, email address, and Google account identifier. ObMob uses this information to create, authenticate, secure, and support your account. ObMob's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
2.2 De-identified case content
ObMob processes case material you upload or enter, including case stems, context, medical categories, case-list fields, and generated examiner follow-ups. The launch workflow requires case information to be de-identified under the HIPAA Safe Harbor method.
The source case-list PDF is parsed in transient processing and is not stored as an uploaded file by ObMob. Structured case rows are stored after parsing.
2.3 Voice and transcript data
During a voice practice session, your microphone audio passes through four providers in sequence:
- a real-time transport provider carries the audio from your browser to the examiner bot;
- a speech-to-text provider transcribes your spoken answers;
- an AI model provider processes the running transcript and de-identified case context to produce examiner responses and grading; and
- a speech synthesis provider converts examiner text into synthetic speech.
ObMob stores the text transcript, scorecard, and related session results. ObMob does not write or persist the voice-session audio in its own storage. The providers may process or temporarily retain information under their account settings and terms.
ObMob does not create a voiceprint, identify a speaker, authenticate a user by voice, or clone a user's voice. Examiner voices are synthetic provider voices unrelated to the user.
2.4 Study and performance information
ObMob collects practice results, scores, progress, study-plan state, streaks, badges, topic performance, usage allotments, and related learning information to provide and personalize the Service.
2.5 Payment and subscription information
Stripe processes payment-card information and billing. ObMob receives transaction identifiers, plan and subscription status, purchase history, and limited card metadata such as brand and last four digits. ObMob does not store full payment-card numbers.
2.6 Usage, device, and security information
ObMob may collect IP address, browser and device type, access times, pages or features used, error events, diagnostic logs, and security signals. These records are used to operate, secure, debug, and improve the Service.
2.7 Communications
ObMob keeps emails and support messages you send, plus records of account, billing, lifecycle, legal, and security communications sent through Zoho Mail or Resend.
2.8 Agreement evidence
ObMob records agreement version, document hashes, timestamp, account email, IP address, user agent, and assent event to preserve evidence of acceptance. When an account is deleted, the direct user identifier may be removed or nulled while the acceptance record is retained.
2.9 Information ObMob does not request
Do not provide patient names, contact details, full dates, medical record numbers, facility names, or other HIPAA Safe Harbor identifiers. Do not speak them during a session. If ObMob discovers possible PHI, it may quarantine, delete, or restrict the affected content and cooperate in remediation.
3. How ObMob uses information
ObMob uses information to:
- authenticate accounts and provide the Service;
- parse de-identified case lists and generate practice materials;
- run voice and text sessions, grading, scorecards, feedback, and study plans;
- process payments, subscriptions, cancellations, refunds, and Credit Packs;
- provide support and transactional communications;
- secure, debug, monitor, and improve the Service;
- prevent fraud, abuse, and prohibited use;
- preserve agreement and transaction evidence;
- comply with law and enforce agreements; and
- protect users, ObMob, and third parties.
ObMob does not sell personal data. ObMob does not share personal data for targeted or cross-context behavioral advertising. ObMob does not authorize third-party foundation-model providers to train their general models on user content.
4. AI and automated processing
AI providers process the running transcript, de-identified case context, and physician-validated reference material to conduct the exam simulation, generate feedback, and grade performance. ObMob does not use AI to make a legal, employment, credit, insurance, licensing, or patient-care decision about you.
AI output may be incorrect or nonunique. The Terms and Educational Use Disclaimer require independent verification and prohibit patient-care reliance.
Voyage AI is reserved for embeddings and reranking of physician-validated knowledge-base text. The retrieval feature will remain inactive until ObMob completes the applicable training-data opt-out.
5. Service providers and disclosures
ObMob shares information with providers acting for the functions identified below:
| Provider | Function | Information processed |
|---|---|---|
| OAuth sign-in | Name, email, account identifier | |
| Supabase | Database, authentication, and storage | Account data, structured de-identified cases, transcripts, study data, agreement records |
| Vercel | Web hosting and serverless processing | Account and request data; uploaded case files in transient processing |
| Daily and Pipecat Cloud | WebRTC transport and examiner-bot hosting | Session audio in transit, transcript, de-identified case context, session metadata |
| Deepgram | Speech-to-text | Streaming and prerecorded session audio, transcript |
| Anthropic | Examiner language-model processing and grading | Transcript, de-identified case context, physician-validated reference context |
| Cartesia | Text-to-speech | Examiner response text and session metadata needed to synthesize audio |
| Voyage AI | Embeddings and reranking, when activated | Short physician-validated reference passages |
| Stripe | Checkout, recurring billing, Credit Packs, and customer portal | Name, email, payment information, subscription and purchase status |
| Zoho Mail | Human and support email | Name, email, message content |
| Resend | Automated transactional and lifecycle email | Name, email, account and transaction message content |
ObMob may also disclose information:
- when required by law, subpoena, court order, or valid legal process;
- to protect rights, safety, security, or property;
- to investigate fraud or enforce agreements;
- to professional advisers under confidentiality duties; or
- in a merger, financing, reorganization, acquisition, or sale of assets, with notice where required.
6. Cookies and tracking
ObMob uses essential authentication, security, and preference technologies. ObMob does not use third-party advertising cookies or cross-site behavioral advertising trackers. If this practice changes, ObMob will update this Policy and provide any legally required choices before the change takes effect.
7. Retention and deletion
7.1 Account and service records
Account data, structured case content, transcripts, scorecards, and study records are generally retained while the account is active and as needed to provide the Service.
7.2 Account deletion
You may request deletion through account settings or by emailing hello@obmob.ai. The current deletion route first attempts to cancel an active Stripe subscription and then deletes the authenticated user and associated user tables through the application database cascade.
ObMob may retain or de-associate limited records needed for:
- billing, tax, and accounting;
- agreement and consent evidence;
- security, fraud prevention, and audit;
- legal claims, disputes, and regulatory obligations; and
- routine backups until they age out.
Provider-side deletion and backup timing may differ. ObMob does not state a fixed number of days until the provider deletion calls and backup-purge schedule are verified.
7.3 Uploaded files
Case-list source PDFs are processed transiently and are not stored as uploaded files by ObMob after parsing.
7.4 Payment records
Stripe and ObMob retain transaction and accounting records for the periods required by law, fraud controls, and legitimate business needs.
8. Security
ObMob uses safeguards designed for the nature of the information, including encrypted transport, authentication, tenant-level row controls, least-privilege access, logging, backups, incident response, and review of administrative access. No system is perfectly secure.
The launch workflow reduces healthcare privacy risk by accepting only de-identified case information. That design does not eliminate the need to protect account, transcript, payment, and usage information.
Report a suspected security issue to justin@obmob.ai with subject "Security."
9. Your rights and choices
Regardless of statutory coverage, you may request:
- access to account information;
- correction of inaccurate information;
- export of available account data;
- deletion of the account and associated content; and
- review of a denied privacy request by a different reviewer.
Send a request from your account email to hello@obmob.ai. ObMob may verify identity and authority before responding. ObMob aims to respond within 45 days and will notify you if additional time is reasonably necessary.
ObMob does not sell personal data, use it for targeted advertising, or make legal or similarly significant decisions by profiling, so those statutory opt-outs are not currently applicable.
The Connecticut Data Privacy Act is not currently expected to apply based on ObMob's fewer-than-ten-user pilot and its current practices. ObMob nonetheless provides the choices above as a voluntary baseline. Coverage will be reassessed as user volume, data categories, or business practices change.
10. Health-information boundary and breach response
ObMob is not a HIPAA covered entity or business associate for the de-identified-only consumer Service. If a future institutional workflow requires PHI, ObMob will not activate it unless a separate BAA and PHI Activation Schedule are signed and all applicable vendor, security, and operational conditions are satisfied.
ObMob maintains an incident-response process and will provide legally required notices. Depending on the information and product function, a non-HIPAA health technology may be subject to the Federal Trade Commission's Health Breach Notification Rule or state breach laws. ObMob will assess the applicable rule based on the affected information and event.
11. Children
The Service is intended for adults who are physicians or physicians-in-training. It is not directed to children under 18, and ObMob does not knowingly collect information from them. Contact hello@obmob.ai if you believe a child submitted information.
12. United States service
The Service is operated in the United States and intended for United States users. ObMob does not target the European Union, United Kingdom, or another non-U.S. market. If you access from another country, your information will be processed in the United States.
13. Changes to this Policy
For a material change to data collection, use, disclosure, or user rights, ObMob will provide advance notice and, where required or where the change materially reduces a user's rights, obtain affirmative re-acceptance before the change applies.
For other prospective changes, ObMob may provide notice by email, in the Service, or on this page and identify the effective date. Prior versions and acceptance evidence may be retained.
14. Contact
Privacy requests and questions:
ObMob, LLC
Attn: Justin Leonetti
Email: hello@obmob.ai
Security incidents: justin@obmob.ai