Skip to content

Legal

Privacy Policy

How PlacementFlow collects, uses, shares and protects personal data — for students, clinicians and placement teams.

Last updated: 22 September 2026 · Version 1.0

1. Who we are

PlacementFlow is a clinical-placement management app used by medical students, clinicians and placement teams to run attendance, timetables, sign-offs, teaching content and notices. It is operated by PlacementFlow Limited (“PlacementFlow”, “we”, “us”), a company registered in England & Wales (company number 17142740), with its registered office at 3 Long Lane, Formby, Liverpool, England, L37 3QQ.

PlacementFlow Limited is the data controller where we decide what personal data is collected and how it is used, and we are responsible for looking after that data.

You may use PlacementFlow directly as an individual, or through a medical school or other institution. PlacementFlow is the controller for the accounts and service operations it determines. Where an institution determines how official educational or placement records are used, that institution may be the controller for those records and PlacementFlow acts on its instructions as a processor. Your institution may give you additional privacy information for that processing.

Questions about this policy or your data can be sent to our privacy contact at support@placementflow.co.uk.

2. What personal data we collect

We collect data needed to provide, secure, support and improve PlacementFlow. For App Store disclosure purposes, all categories below are treated as linked to identity, including through an account, user or device identifier, or an attributable educational record. None of these categories is used for tracking as Apple defines that term.

DataWhat it can includeApp Store category
Account & profileName, email address, optional phone number, optional profile photograph, Firebase user ID, student number or equivalent account identifier, institution or medical school, role, cohort, placement membership, preferences and settingsName; Email Address; Phone Number; Photos or Videos; User ID; Other Data Types
Educational & placement recordsTimetables and sessions, attendance and QR check-ins, sign-offs, assessments, assessor feedback, progress and completion, condition exposure, patient-anonymous casebook or logbook content, reflections and educational narrativesOther User Content; Product Interaction; Other Data Types
Health & sensitive educational informationEducational submissions may include clinical history or symptoms, examination findings, management, named conditions, and pregnancy or childbirth-related clinical contextHealth; Sensitive Info; Other User Content
Communications & engagementPrivate messages, notices and read status, session ratings and comments, and related message, notice and feature interactionsEmails or Text Messages; Other User Content; Product Interaction
Customer supportSupport subject and message, user ID, name, email, role, current page or URL, browser or user-agent information, and technical details needed to investigate an issueCustomer Support; User ID; Other Diagnostic Data
Device, notifications & diagnosticsAn application or device identifier such as IDFV, Firebase installation identifier, APNs or FCM notification token, device and app metadata, JavaScript error message, source and stack, current page, associated user ID, user agent, and Firebase Messaging or Installations transport diagnosticsDevice ID; Product Interaction; Other Diagnostic Data
Approximate location from resource requestsTechnical request information, including an IP address that may be used by a resource provider to infer an approximate locationCoarse Location
Optional usage analytics (students, only if you allow it)Your Firebase user ID as a pseudonymous identifier; which PlacementFlow features you open and a small fixed set of actions (for example opening a feature, starting or finishing an ECG lesson, running a search or saving an opportunity); broad categories such as your role, access state and institution; browser, operating system and device type; analytics session identifiers and timestampsUser ID; Product Interaction
Medical-school or pilot enquiriesWork email, institution, role, enquiry narrative, and contact preference or consentEmail Address; Other User Content; Other Data Types

The health and sensitive information above supports medical education, placement administration and assessment. A submission is associated with the student’s account, but it does not necessarily describe the student’s own health. PlacementFlow does not use HealthKit or Apple Clinical Health Records, and it is not intended for diagnosis, treatment, clinical decision-making or patient care.

Product interactions such as attendance, check-ins, sign-offs, completion and progress, ratings, comments, message and notice interactions, and relevant feature usage support app functionality, educational personalisation, reporting, service analysis and reliability.

Optional usage analytics: Students can choose whether PlacementFlow records how its features are used. Nothing is recorded unless you select Allow, and saying no does not limit anything in PlacementFlow. If you allow it, PlacementFlow sends a limited, predefined set of feature and action events to PostHog (EU Cloud), linked to your Firebase user ID. This is pseudonymous, not anonymous: it is linked to your account. It does not include your name, email address or phone number; the content of messages or discussions; the text of anything you search for; clinical or patient information; ECG answers, scores or interpretations; page addresses, query strings or referrers; or precise location. Session replay, click and keystroke capture, heatmaps and surveys are switched off. You can turn usage analytics off at any time in Settings › Privacy & data, and recording stops immediately. Your choice is stored on the device you made it on.

Daily Diagnosis: If you allow usage analytics, we record the fictional case identifier and version, whether it comes from your placement specialty or Year 6 Mix, clue reveals, whether an attempt is correct, whether you completed the case, how many clues you used and whether you made a guess. We also record when case selection fails. We do not send the diagnosis you type, reviewer notes or patient information to usage analytics. These interactions are used to improve the activity, not to assess clinical competence. You can play if you decline analytics. Typed guesses and progress are kept in this browser for resuming the activity, separately for your account; they are not stored as cloud learning records.

Coarse location: PlacementFlow does not request GPS access and does not collect precise location. Some screens load destination images from Unsplash and map tiles from OpenStreetMap. When these resources load, those providers receive technical request information such as an IP address, browser or device information and the requested resource. An IP address may be used to infer an approximate location. This is not attendance-location collection or GPS tracking.

Pilot enquiries: An optional medical-school or pilot enquiry is used to answer the enquiry, discuss or arrange a pilot and provide related first-party communications. This is not third-party advertising.

3. Why we use it, and our lawful basis

We use personal data to create and secure accounts; provide attendance, timetables, sign-offs, teaching, messaging and notices; personalise educational progress; deliver service emails and push notifications; maintain attributable educational records; answer support and pilot enquiries; produce reports and service analysis; and protect, diagnose and improve the service.

Our lawful bases under UK GDPR are:

  • Contract — to create your account and provide the core service you signed up for.
  • Legitimate interests — to keep attributable educational records, answer enquiries and keep the service secure, reliable and improving. Where we rely on legitimate interests we balance them against your rights, and you may object where that right applies.
  • Consent — for optional features such as push notifications and optional usage analytics, which you can turn off at any time.

Where information qualifies as special-category data, we process it only where an additional condition under data-protection law applies. An institution that controls an official record may rely on a different lawful basis and will provide information about its processing.

4. Patient anonymity

PlacementFlow is for educational record-keeping, not clinical documentation. Records must remain patient-anonymous, and no patient-identifiable information should ever be recorded. Do not enter patient names, NHS or hospital numbers, dates of birth, addresses, photographs or other information that could identify a patient in a logbook, reflection, message, support report or anywhere else in the service.

5. Who we share it with

We do not sell personal data. We share it only with:

  • Authorised users and institutions — assessors, supervisors, placement staff and authorised medical-school staff can see the records and functions relevant to their role.
  • Google Firebase and Google Cloud — Firebase Authentication, Cloud Firestore, Cloud Functions and Firebase Storage provide account, database, server and file services; Firebase Cloud Messaging and Firebase Installations support notifications and app installations.
  • Apple Push Notification service — delivers notifications to Apple devices when notifications are enabled.
  • Our configured email delivery provider — delivers account, invitation, support and service messages.
  • PostHog (EU Cloud) — processes optional usage analytics on our behalf, only for students who have allowed it (see Optional usage analytics in section 2). We do not permit it to be used for advertising.
  • Unsplash and OpenStreetMap or its tile infrastructure — receive the technical request information described under Coarse location when their images or map tiles load.

Our contracted service providers process data under applicable data-processing terms. Unsplash, OpenStreetMap, Apple and Google also apply their own terms to relevant services. We may disclose data where required by law.

6. How long we keep it

We keep data only for as long as it is needed for the purposes described above, including to provide the service, preserve the integrity of educational records, meet legal or institutional requirements, resolve disputes and protect the service. The period depends on the type of record and who controls it:

  • Account and private profile data is normally kept while the account is active. Account deletion removes the authentication account and the private records handled by the deletion workflow. Separately stored profile files are not guaranteed to be removed automatically; contact us if you need help with a remaining file.
  • Official educational, assessment and consent records may need to remain attributable after account deletion to preserve record integrity or meet an institution’s retention requirements. An institution’s schedule applies to records it controls.
  • Support reports, pilot enquiries and content shared with others may be retained where needed to answer the request, maintain a shared record, meet legal obligations, handle disputes or protect the service.
  • Optional usage analytics is kept in PostHog for 12 months and then deleted. Turning analytics off stops new events; it does not by itself delete events already sent. You can ask us to delete the analytics linked to your account at any time using section 13, including when you delete your account.
  • Device tokens and diagnostics are retained only while needed for notifications, security, investigation and service reliability; notification registrations are removed when they are no longer authorised or required.

7. Your rights

Under UK data-protection law you can ask for access to your data and correction of inaccurate data. Depending on the circumstances, you may also have rights to erasure, restriction, objection and data portability, and you can withdraw consent at any time without affecting earlier lawful processing. The app’s Settings include tools to export your data and request account deletion; as explained in section 6, deletion does not require every official, consent, support or shared record to be removed.

To exercise a right, contact us using section 13. If an institution controls the relevant record, we may direct the request to it. You can also complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.

8. How we protect it

Access is role-based and assigned server-side, so each person sees only their slice of a placement. Data is encrypted in transit, access rules are enforced by our database security rules, and sensitive operations run through server-side functions rather than the browser. Accounts require email verification, and elevated roles are assigned by the platform rather than self-claimed. No system is perfectly secure, but we design with the guardrails on by default.

9. Tracking, cookies & local storage

PlacementFlow uses cookies and local or session storage to keep you signed in, remember preferences and provide the service. Embedded providers may measure technical requests made to their resources, so we do not claim that no request measurement occurs.

If you allow optional usage analytics, PlacementFlow also stores a small analytics identifier and session state in your browser’s local storage. If you decline or later turn analytics off, that storage is removed. Your analytics choice itself is remembered on the device so you are not asked again.

PlacementFlow does not display third-party advertising, use IDFA, request App Tracking Transparency permission, use the data described in this policy (including optional usage analytics) to track users across unrelated apps or websites for targeted advertising, or sell personal data. First-party communications sent in response to a requested pilot enquiry are not third-party advertising.

10. Age of users

PlacementFlow is intended for medical students, clinicians and authorised placement staff. Users must be at least 16 years old to create an account. Medical students aged 16 or 17 may use PlacementFlow where their medical programme or institution permits this and must comply with any applicable institutional requirements.

Users under 18 retain their applicable privacy rights, and their information should be handled with particular care. PlacementFlow does not currently use automated age assurance or age-verification technology, and we do not verify parental consent.

11. International transfers

Some service providers may process personal data outside the United Kingdom. Optional usage analytics is sent to PostHog’s EU Cloud, which is hosted in the European Union. The protections that apply depend on the provider, destination and legal role, and may include a UK adequacy regulation or approved contractual safeguards. Contact us if you would like more information about an international transfer.

12. Changes to this policy

We may update this policy from time to time. We will change the “last updated” date above and, for material changes, tell you in the app or by email.

13. Contact us

For any privacy question or to exercise your rights, contact support@placementflow.co.uk. This contact handles data-protection queries. PlacementFlow Limited is registered with the UK Information Commissioner’s Office (ICO).

This policy is governed by the laws of England & Wales.

Questions about this policy?

For any privacy question, or to exercise your rights, use the privacy contact. If an institution controls the relevant record, we may direct the request to it.