FPA Future Physician Academy
How it works Coverage Languages Methodology Pricing
Join the waitlist

Legal · Privacy

Privacy Policy

Effective date: August 30, 2026 Last updated: July 22, 2026

Future Physician Academy (“FPA,” “we,” “us,” or “our”) is operated by Future Physicians, LLC, a Delaware limited liability company. This Privacy Policy explains how we collect, use, share, and protect information when you use our website (futurephysicianacademy.com), our subscription platform, and our AI study tutor (together, the “Service”).


1. Introduction and Scope

Plain English This policy covers anyone who visits our site, joins our waitlist, subscribes as an individual learner, or accesses FPA through an institutional (residency program) account. It does not apply to third-party sites we link to.

This Policy applies to:

  • Visitors to futurephysicianacademy.com
  • Waitlist signups
  • Individual subscribers (medical students, residents, IMGs, fellows, and attendings)
  • Users accessing FPA through an institutional subscription (e.g., a residency program)
  • Anyone interacting with our AI study tutor

This Policy does not apply to third-party websites, tools, or services we may link to, including payment, email, or AI infrastructure providers, each of which maintains its own privacy policy (see Section 5).

By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.


2. Information We Collect

Plain English We collect what you give us (account info, billing info, waitlist answers), what your use of the product generates (which cases you study, how you use the AI tutor), and a small amount of information collected automatically (IP address, device type, cookies). We do not collect patient health information of any kind.

2.1 Information You Give Us

Account information: email address, name (optional), and a hashed password (we never store your password in plain text).

Waitlist information: email address, role (student, resident, attending, or institution), primary specialty of interest, language preference, country/region, and how you heard about FPA.

Subscription and billing information: name, billing address, and payment method. Payment card details are tokenized and processed directly by our payment processor, Stripe. FPA never stores or has access to your full card number.

Institutional account information (for residency programs): program name, program director name and email address, seat count, and billing contact information.

AI tutor conversations: the prompts you type and the responses generated by the AI tutor.

2.2 Information Generated By Your Use of the Service

Usage analytics: which training cases you open, answers you submit, time spent per case, and error/response patterns. We use this to improve case calibration and difficulty across our library of clinical training cases.

2.3 Information Collected Automatically

Server logs: IP address, browser user-agent, and device type, retained for 30 days for security and troubleshooting purposes.

Cookies: see Section 6 for full detail.

2.4 Information From Third Parties

We may receive limited information from third parties, such as:

  • Payment confirmation and fraud-risk signals from Stripe
  • Email deliverability and engagement data (opens, clicks) from our email service provider
  • Aggregate, anonymized analytics from our analytics provider

2.5 What We Do NOT Collect

  • We do not use third-party advertising cookies.
  • We do not engage in cross-site tracking.
  • We do not sell your personal data to anyone, ever.
  • We do not knowingly collect Protected Health Information (“PHI”) about real patients. FPA is an educational platform, not a clinical or patient-care tool. See Section 12.

3. How We Use Information

We use the information described above to:

  1. Fulfill your subscription: create and manage your account, process payments, provision institutional seats, and deliver the case library and AI tutor.
  2. Improve the product: analyze usage patterns and error trends to recalibrate case difficulty, identify confusing content, and improve the AI tutor’s helpfulness.
  3. Communicate with you: send transactional emails (receipts, password resets), respond to support requests, and, if you’ve opted in, send product updates or waitlist notifications.
  4. Comply with legal obligations: maintain records required for tax, accounting, and legal compliance, and respond to lawful requests from authorities.
  5. Maintain security: detect and prevent fraud, abuse, and unauthorized access.

We do not use your data for third-party advertising, and we do not build advertising profiles.


4. Legal Basis for Processing (GDPR)

Plain English If you’re in the EU or UK, we rely on your contract with us, our legitimate business interests, or your consent: depending on what we’re doing with your data.

For users in the European Union and United Kingdom, we process personal data under the following legal bases:

  • Contract: processing necessary to provide the Service you signed up for (account creation, billing, case delivery).
  • Legitimate interests: product improvement, security monitoring, and fraud prevention, balanced against your privacy rights.
  • Consent: marketing communications, optional cookies/analytics where required by local law, and any AI-related processing that requires opt-in. You may withdraw consent at any time (see Section 9).
  • Legal obligation: retaining records required by tax or accounting law.

5. How We Share Information

Plain English We only share data with the specific service providers needed to run FPA: payments, email, AI infrastructure, hosting, and analytics. We never sell your data.

We share personal data only with the following categories of service providers, each acting under contractual confidentiality and data protection obligations:

Provider Purpose Data Involved
Stripe Payment processing Billing name, address, tokenized payment method
Email service provider (Loops.so or ConvertKit) Waitlist and transactional email Email address, name, engagement data
OpenAI and/or Anthropic (API) Powers the AI study tutor Tutor prompts and responses: processed under enterprise API terms with a zero data retention / no-training flag enabled
Vercel or Netlify Website and application hosting Server logs, encrypted application data
Plausible or PostHog Privacy-preserving product analytics Aggregated usage data: no personal identifiers, no cross-site tracking
Google Workspace Internal company email and document collaboration only Not used to store user/customer data

We may also disclose information if required by law, subpoena, or court order, or to protect the rights, property, or safety of FPA, our users, or the public.

We do not sell personal data. We never have, and we never will.

If Future Physicians, LLC is involved in a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction, subject to this Policy’s protections.


6. Cookies and Tracking Technologies

Plain English We use one cookie to keep you logged in, and privacy-preserving analytics that don’t track you across other websites. No ad trackers, ever.

Cookie Type Purpose Third-Party? Can You Opt Out?
Essential (session/auth) Keeps you logged in and secures your session No No: required for the Service to function
Analytics (Plausible or similar) Understand aggregate usage (e.g., page views, feature usage): privacy-preserving, no cross-site tracking, no cookies used for individual profiling in some configurations Limited (analytics vendor only) Yes: see below

Opting out of analytics: You can opt out of analytics tracking through your browser’s “Do Not Track” setting or ad-blocking/privacy extensions. Because our analytics tools do not use cross-site identifiers or third-party advertising networks, there is no advertising opt-out to manage: we simply don’t have one.

We do not use third-party advertising cookies or retargeting pixels of any kind.


7. Data Security

Plain English We encrypt your data, limit who can access it internally, and have a plan for responding if something goes wrong.

We implement industry-standard technical and organizational safeguards, including:

  • Encryption in transit: all data transmitted between your device and our servers uses TLS/HTTPS encryption.
  • Encryption at rest: stored data, including account and billing metadata, is encrypted at rest by our infrastructure and database providers.
  • Access controls: internal access to user data is limited to personnel who need it to operate the Service, using role-based permissions.
  • Payment isolation: we never store raw payment card numbers: Stripe handles and tokenizes all card data.
  • Incident response: in the event of a data security incident affecting your personal data, we will notify affected users and relevant authorities as required by applicable law, without undue delay.

No system is 100% secure, and we cannot guarantee absolute security, but we are committed to promptly addressing vulnerabilities and incidents.


8. Data Retention Periods

Plain English We keep data only as long as we need it. AI tutor conversations are deleted (in identifiable form) after 90 days. Server logs are deleted after 30 days.

Data Type Retention Period
Account information (email, name, password hash) For the life of your account, plus a limited period after closure for legal/accounting purposes
Waitlist data Until you unsubscribe or convert to a subscriber, or up to 24 months of inactivity
Billing and subscription records As required by tax and accounting law (typically up to 7 years)
Usage analytics (case-level activity) Retained in identifiable form for the life of your account; may be retained in aggregated/de-identified form indefinitely for product improvement
AI tutor conversations Retained in identifiable form for 90 days for quality review and safety monitoring, then aggregated and anonymized
Server logs (IP, user-agent, device type) 30 days
Institutional account data (program contacts, seat counts) For the duration of the institutional agreement, plus a limited retention period for billing records

Upon account deletion, we delete or anonymize your personal data within a reasonable period, except where retention is required by law (e.g., financial records).


9. Your Rights

Plain English Depending on where you live, you have rights to access, correct, delete, or restrict use of your data. Email privacy@futurephysicianacademy.com and we’ll respond within 30 days, wherever you’re located.

9.1 GDPR Rights (EU / UK Users)

If you are located in the European Union or United Kingdom, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data (“right to be forgotten”), subject to legal retention requirements
  • Restrict processing in certain circumstances
  • Port your data to another provider in a machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time, where processing is based on consent
  • Lodge a complaint with your local data protection supervisory authority

9.2 CCPA/CPRA Rights (California Users)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Delete personal information we hold about you, subject to exceptions
  • Correct inaccurate personal information
  • Opt out of “sale” or “sharing” of personal information: note: we do not sell or share personal information, so there is nothing to opt out of
  • Non-discrimination: we will not deny service, charge different prices, or provide a different quality of service because you exercised a privacy right

9.3 Other US State Privacy Laws

Residents of Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws have similar rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising and certain profiling (which we do not engage in). Contact us to exercise these rights, and we will honor them consistent with applicable state law.

9.4 Global: Right to Close Your Account

Regardless of your location, you may close your account and request deletion of your personal data at any time by emailing privacy@futurephysicianacademy.com.


10. Children’s Privacy

FPA is designed for users 18 years of age and older (medical students, residents, IMGs, fellows, and attendings). A limited pre-med educational tier may be available to users 13 years of age and older with verifiable parental or guardian consent.

We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected data from a child under 13 without appropriate consent, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact us at privacy@futurephysicianacademy.com.


11. International Data Transfers

FPA’s infrastructure and personnel are primarily located in the United States, and personal data is processed and stored in the United States.

If you are located outside the United States, your data will be transferred to, stored in, and processed in the United States. For users in the European Union and United Kingdom, we rely on appropriate safeguards for such transfers, including Standard Contractual Clauses (SCCs) with our service providers where applicable.


12. HIPAA Statement

This is important. Please read carefully.

Future Physicians, LLC is not a HIPAA covered entity or business associate. FPA is an educational platform, not a clinical care, diagnostic, or patient-record tool.

  • All training cases in our library are fictional or de-identified educational scenarios. No real patient data is used to construct our content.
  • Users must not enter real Protected Health Information (“PHI”): including real patient names, identifiers, or clinical details: into the platform, including the AI study tutor. Doing so is a violation of our Terms of Service.
  • Because FPA does not knowingly collect, store, or process PHI, HIPAA’s requirements for covered entities and business associates do not apply to our handling of platform data.
  • If you are a healthcare professional using FPA, please treat it strictly as a study and training tool: not a system for recording, storing, or discussing identifiable patient information.

13. AI-Specific Disclosures

Plain English Your conversations with the AI tutor are used to make sure the tutor is working well, then anonymized. We do not use your conversations to train the underlying AI models, because our API agreements have a no-training, zero-retention flag enabled.

  • What we collect: the prompts you send to the AI study tutor and the responses it generates.
  • How we use it: to power the tutoring feature in real time, and to review conversation quality (e.g., accuracy, safety, calibration) for up to 90 days, after which conversations are aggregated and anonymized.
  • Do we use your conversations to train AI models? No. We use enterprise API access to our AI providers (OpenAI and/or Anthropic) with a zero data retention and no-model-training flag enabled under their business/enterprise terms. Your conversations are not used to train or fine-tune the underlying foundation models.
  • Opt-out: if you would like to limit use of your AI tutor conversations for internal quality review, contact privacy@futurephysicianacademy.com. Note that the AI tutor requires processing your prompts in real time to function; full opt-out from processing means not using that feature.
  • Accuracy caveat: the AI tutor is a study aid, not a source of clinical or medical advice for real patients. Do not input real patient information (see Section 12).

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. If we make material changes, we will notify you by email (to the address associated with your account) and/or through a prominent notice on the Service prior to the change taking effect. The “Last Updated” date at the top of this Policy reflects the most recent revision.


15. How to Contact Us / Exercise Your Rights

To exercise any of the rights described in this Policy, or if you have questions about our privacy practices, contact us at:

Email: privacy@futurephysicianacademy.com General inquiries: hello@futurephysicianacademy.com

Future Physicians, LLC
Attn: Privacy Officer
c/o Legalinc Corporate Services Inc. (Registered Agent)
131 Continental Dr, Suite 305
Newark, DE 19713
Email: hello@futurephysicianacademy.com

We will respond to verified privacy requests within 30 days.


Attorney Review Checklist

The following items should be specifically scrutinized by a licensed attorney (ideally with digital health, EdTech, and international privacy experience) before this policy is published:

  1. Verify that the Standard Contractual Clauses (SCC) language for EU/UK data transfers reflects the current, legally valid mechanism (including any UK International Data Transfer Agreement addendum requirements).
  2. Confirm state-by-state US privacy law coverage is complete and current: additional state comprehensive privacy laws are taking effect through 2026–2027 and may require additional disclosures or rights not listed here.
  3. Delaware LLC formation via Stripe Atlas completed on 2026-07-20 and EIN 42-3972153 issued on 2026-07-21. Attorney should still confirm “Future Physicians, LLC” is the correct data controller/processor entity name throughout and that Trevor Turner is properly identified as an authorized signer.
  4. Review the HIPAA disclaimer language with health-law counsel: confirm FPA’s actual practices (e.g., handling of any user-submitted content in the AI tutor) don’t inadvertently create PHI exposure or covered-entity/business-associate risk.
  5. Review the AI-specific disclosures against emerging AI regulation (e.g., EU AI Act obligations, state-level AI transparency laws) and confirm the “no training / zero data retention” claims are accurately reflected in the actual OpenAI/Anthropic enterprise agreements in place.
  6. Confirm whether any users may be minors under 13 in the “pre-med educational tier,” and if so, whether COPPA-compliant parental consent mechanisms are actually implemented (not just described).
  7. Confirm the data retention schedule (90 days for AI conversations, 30 days for server logs, etc.) matches actual technical implementation: policy commitments must match engineering reality.
  8. Confirm whether “aggregated/anonymized” AI conversation data meets the legal standard for anonymization under GDPR and CCPA (true anonymization vs. pseudonymization has different legal consequences).
  9. Review institutional (residency program) data-sharing arrangements: determine if a separate Data Processing Agreement (DPA) or institutional agreement is needed, especially if programs are treated as independent controllers of trainee data.
  10. Confirm the CCPA/CPRA “opt-out of sale/sharing” language properly addresses the CPRA’s broader “sharing” definition (which can include some analytics/advertising integrations) and that current analytics tools (Plausible/PostHog) don’t trigger “sharing” status.
  11. Confirm breach notification timelines and procedures in Section 7 align with specific state and international breach notification law requirements (which vary by jurisdiction).
  12. Review whether a separate Cookie Policy / consent banner is required for EU/UK users under ePrivacy rules, beyond what is described in Section 6.

Questions about this document? Email legal@futurephysicianacademy.com.

Back to Future Physician Academy

Future Physician Academy

The complete ABMS case library, taught with faculty-governed AI.

Product

  • How it works
  • Coverage
  • Methodology
  • Pricing

For institutions

  • Residency programs
  • Request a demo

Company

  • Contact
  • Terms of Service
  • Privacy Policy
  • Refund Policy
© 2026 Future Physicians, LLC · Atlanta, GA An educational resource. Not medical advice. Not affiliated with the ABMS.