Privacy Policy

Last updated: September 2026

1. Who is responsible for your data

Clinical CME Group LLC, a Delaware limited liability company, of 2140 South Dupont Highway, Camden, Delaware, 19934, USA, operating as Titrate. Privacy enquiries: Office@clinicalcmegroup.com.

2. What we collect

You give us:

We generate:

We collect automatically:

We do not collect: payment card details. Those go directly to Stripe.

3. Google Sign-In data

If you choose "Continue with Google" instead of setting a password, this is what happens with your Google Account data:

Our use of Google user data across Titrate complies with the Google API Services User Data Policy, including its Limited Use requirements.

4. Why we use it

5. AI processing

When you request a feedback report, a revision timetable or a tutor answer, we send the relevant information to our AI provider (OpenRouter, which routes to the underlying model provider) to generate the response.

What is sent: your performance figures by domain, your exam date and study hours, the question concerned and your answer to it, and your message to the tutor.

What is not sent: your name, your email address or your payment details.

6. Who we share it with

We use these sub-processors:

ProviderPurposeData involved
RailwayHosting and databaseAll application data
StripePayment processingEmail, name, payment details (held by Stripe)
OpenRouterAI generationPerformance figures, question content, tutor messages
ResendTransactional emailEmail address, name
GoogleOptional sign-inGoogle account email and name

Titrate is operated from the United States, and our sub-processors are located in the United States and other countries. If you are in Australia, the UK or the EU, this means your data is transferred outside your country and processed in the United States and elsewhere. We take reasonable steps to ensure it is handled consistently with this policy.

We do not sell your personal information.

7. How long we keep it

We keep your account data while your account is open. If you delete your account, we delete your personal data and all of your study history promptly.

We keep transaction records for as long as tax and accounting law requires, and we may keep anonymised, aggregated statistics (such as how often a given question is answered correctly) that cannot identify you.

8. Your rights

You can, at any time:

If you are in the UK or EU, you have additional rights under the UK GDPR / GDPR, including the right to object to processing and to data portability. Contact us to exercise them.

9. Security

Passwords are hashed with bcrypt. Sessions use signed, httpOnly cookies. Data is encrypted in transit. Access to production data is limited to those who need it.

No system is perfectly secure. If a breach occurs that is likely to cause you serious harm, we will notify you and the relevant regulator as the law requires.

10. Cookies

We use a single essential cookie to keep you signed in. We do not use advertising or third-party tracking cookies.

11. Changes

We will post any changes here and, if they are material — including any change to how we access, use, store or share Google user data — tell you by email before the change takes effect.