Privacy policy

Last updated: 15 May 2026

Who we are

OET Prep is a study platform for healthcare professionals preparing for the Occupational English Test (OET). The service is operated by Bkdin App, registered in the United Kingdom. Contact: admin@bkdin.app.

We are the data controller for personal data you provide to us. Some processing is performed by third parties acting as data processors on our behalf, listed below.

What we collect

Account data

  • Your email address and display name (via Clerk, our authentication provider)
  • Your chosen profession (e.g. nursing, medicine), region, and OET test date
  • Self-reported current OET band scores

Practice data

  • Answers you submit to Reading, Listening, Writing, and Speaking tests
  • Transcripts of Speaking role-plays (text or voice-derived)
  • Letter text you write in the Writing sub-test
  • Messages you send to the AI tutor
  • Your computed scores and predicted bands

Technical data

  • Approximate location (derived from IP at session start, not stored long-term)
  • Browser type, operating system, device class
  • Pages visited and features used (via PostHog analytics — see below)
  • Error reports if something crashes (via Sentry)

We do not collect: your full name beyond your sign-up details, payment card data (handled by Stripe when activated), or any clinical data about real patients. Practice content uses fictional cases only.

Why we collect it (lawful basis)

Under UK and EU GDPR, we process your data on the following bases:

  • Contract: account data, practice data, and computed scores are necessary to provide the service you signed up for.
  • Legitimate interests: analytics, error monitoring, and product improvement, balanced against your reasonable expectations.
  • Consent: marketing emails and non-essential cookies. You can withdraw consent at any time.
  • Legal obligation: retention of records for tax purposes (only post-purchase, when Stripe is active).

Who we share it with

We use the following third-party processors. Each has been chosen for their security and GDPR posture.

  • Clerk — authentication and account management (US-based, GDPR-compliant)
  • Neon — database hosting in EU-West (London region)
  • Vercel — application hosting (EU-region functions)
  • Anthropic — Claude AI scoring + tutor (US-based; we do not include your name in prompts)
  • OpenAI — Realtime voice mode for Speaking (US-based; voice transcripts are not used for model training per our agreement)
  • Brevo — transactional + marketing emails (EU-based)
  • PostHog — product analytics, EU Cloud instance
  • Sentry — error monitoring (EU region)

We do not sell your personal data. We do not share it with advertisers.

How long we keep it

Account data is retained while your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is legally required (financial records for 7 years from the last transaction).

Practice data (your scores, transcripts, letters) is retained for as long as your account exists, so you can track progress over months and years. You can export or delete this data via the Account settings page at any time.

Your rights

Under UK and EU GDPR, you have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data (right to be forgotten)
  • Receive an export of your data in a portable format
  • Object to processing based on legitimate interests
  • Withdraw consent for marketing emails at any time (one-click unsubscribe)
  • Complain to the UK Information Commissioner's Office (ICO) at ico.org.uk

To exercise any of these rights, email admin@bkdin.app or visit the Account page. We respond within 30 days.

Cookies

We use a small number of essential cookies for authentication (set by Clerk) and session management. Analytics cookies (PostHog) and marketing cookies (Brevo tracking pixel, when enabled) require your consent — see the cookie banner on your first visit.

Children

The service is intended for adult healthcare professionals. We do not knowingly collect data from anyone under 16. If you believe we have, contact us and we will delete it.

Changes to this policy

We will email registered users about material changes. Minor wording changes will be reflected by the "last updated" date above.

This policy is provided in good faith and should not substitute for legal advice. For a precise legal review, consult a UK data-protection solicitor.