Legal
Privacy Policy
Who we are
SmartST is an independent preparation tool for UK doctors applying to specialty training. We are not affiliated with, endorsed by, or connected to NHS England, Oriel, the GMC, or any Royal College. This policy explains what personal data we collect when you use SmartST, how we use it, and the rights you have over it.
If you have any questions about this policy or how we handle your data, you can contact us at hello@smartst.co.uk.
What we collect
We collect only the data we need to provide the service:
- Account and profile. Your email address and name, used to create and identify your account.
- Your training stage and where you qualified. Before you can use SmartST we ask whether you are a medical student or a doctor, and then which year you are in or which stage you have reached — foundation, core or specialty training, a SAS or specialty doctor post, working outside the UK, or a break from practice. We also ask where you qualified in medicine: the UK or Ireland, one of Norway, Iceland, Liechtenstein or Switzerland, or elsewhere. Two further questions — the medical school you go to or graduated from, and where you work — are optional, and you can leave them blank. You can change any of these answers later.
- Plan and specialty selections. The specialties and plan choices you make as you use the guidance and planning tools.
- Portfolio content. The sections and evidence entries you create in the Portfolio Builder.
- Uploaded documents. The evidence files you upload to support your portfolio.
- Referral source.If you reach SmartST through a partner's referral link and accept the referral-attribution cookie, we record which partner introduced you and a few milestones afterwards (that you signed up, created a portfolio, and completed an export), so we can credit the referral. We only ever set that cookie after you accept it.
How we use your data
We use your data to:
- provide and operate the service — building and exporting your portfolio, and delivering the application guidance;
- read the evidence documents you upload and score your portfolio against your specialty's published self-assessment domains, which means sending those documents to a model provider outside SmartST;
- fit that guidance to where you are in your training, so what you see matches your stage rather than assuming everyone is applying in the next cycle;
- authenticate you and manage your account;
- email you — both the messages your account depends on, such as confirming your email address and resetting your password, and the email you can stop at any time: a welcome message when you join, guidance on getting the most out of SmartST, and occasional updates relevant to your specialty and the application cycle;
- credit the partner who referred you, where you reached us through a referral link and accepted the referral-attribution cookie.
Your permission for the second of those — the email you can stop — is part of the Terms of Use you accept when you create an account; it is set out in the section headed Email from SmartST. You can withdraw it at any time by following the unsubscribe link in any of those messages. It takes one click, needs no sign-in and no reason, and leaves your account and everything you have built exactly as they were.
Fitting the guidance to your stage is the whole point of the training questions. Every specialty plan we publish is written for someone applying in the next cycle, which makes it close to useless if you are a first-year medical student or two years out from applying — knowing your stage is what lets us stop doing that. Where you qualified in medicine is used for one thing only: showing you the parts of the process that apply to your route, such as the extra steps for doctors who qualified outside the UK. It plays no part in determining your eligibility for anything. SmartST does not assess who can apply for a training post — the organisations that run recruitment do that — and we do not use your answer to limit what you can see or do here.
Scoring your portfolio is the one thing we do with your data that sends it to a company whose business is reading documents, so it is worth being plain about it. When you upload an evidence file, we send that file — the document itself, as a PDF or an image, not a summary we made first — to a model provider. It reads the document and returns a structured description of it: what kind of document it is, what it says you did, the name it is issued to, the date it carries, and the events, courses or organisations it mentions. We then compare those descriptions against your specialty's self-assessment domains to work out a score. This happens automatically when the upload finishes; there is no separate button to press, and there is currently no way to use the Portfolio Builder's scoring without it. Every company that receives your documents is named individually under “Where your data is stored” below, together with how long it keeps them and whether it may use them to train its models.
A score SmartST gives you decides nothing about you. It is our reading of your own evidence against published criteria, meant to show you the gaps while you can still do something about them. Nobody involved in real recruitment sees it, it carries no weight in any actual application, and no part of your access to SmartST depends on it.
We do not sell your data, and we do not use it for advertising.
Legal bases for processing
Under the UK GDPR, we rely on the following legal bases to process your personal data:
- Performance of a contract — to provide the service you have signed up for, including reading the documents you upload in order to score your portfolio.
- Consent — where applicable, for example where you choose to provide optional information.
- Legitimate interests — in operating, securing, and improving the service, and in knowing where you are in your training so the guidance we give you fits it.
That last basis covers the answers you give us about your training: your stage, where you qualified in medicine, and the medical school or workplace you tell us about. Our interest in them is a plain one — the guidance only works if it is pitched at the right point in the pathway, and we cannot pitch it without knowing yours. We rely on legitimate interests rather than consent because you have to answer before you can use SmartST, and an answer you cannot decline is not freely given. Calling that consent would be describing it as something it is not.
Legitimate interests brings a right that consent does not: you can object. Email us at hello@smartst.co.uk and tell us you object to us holding your training answers, and we will stop using them and delete them from your account unless there is a compelling reason we cannot — and on these fields we do not expect there ever to be. Nothing else changes if you do: your account, your portfolio, and everything you have built stay exactly as they are.
Where your data is stored
We use a small number of trusted processors to run the service, and your data is handled by them under their own terms:
- Supabase provides our managed Postgres database, authentication, and file storage.
- Googledoes three things for us. It provides the optional “Continue with Google” sign-in: if you choose it, Google confirms your identity and shares your name and email address with us so we can create or sign you into your account; we do not receive your Google password. Google also hosts the mailbox behind our
hello@smartst.co.ukaddress, so anything you send us there, and our own internal notes about accounts — including a short note to ourselves when someone signs up, giving their name and email address — are stored in that mailbox. Third, Google's Gemini models read the evidence documents you upload. When an upload finishes, the background worker sends the document to Google's Gemini API — the file itself, as a PDF or an image, along with the name you gave it — and Gemini returns a structured description of it: what kind of document it is, what it says you did, the name it is issued to, the date it carries, and the events, courses, journals or organisations it mentions. Those descriptions are then sent to the same API a second time, without the documents, to be grouped and scored against your specialty's self-assessment domains; sent with them are the titles of the evidence items already in your portfolio, including any you have retitled yourself, so that a later upload adds to what you have instead of duplicating it. This is a point at which your portfolio evidence leaves SmartST, and what goes with it is whatever the document itself contains — for a typical certificate or reference, your name, and often your GMC number, your employer, and the names of supervisors or co-authors. Beyond those titles we send Google nothing from your account: no email address, no account identifier, and nothing else you have written in SmartST. Google does not use your documents to train or improve its models. We use the Gemini API on Google's paid tier, and its terms for that tier state that Google does not use your prompts, the files you send, or the responses to improve its products or models. Separately from that, and regardless of tier, Google keeps the documents, the information sent with them and the responses for 55 days in logs it holds to detect and prevent abuse of the API; content its safety systems flag may be reviewed by authorised Google staff, who use it only to enforce those policies and not to train any other model. For the documents themselves and the descriptions Gemini returns, Google acts as our data processor; for the operational records of our use of the API — billing, request counts and the like — it acts as its own controller under separate terms. Google publishes no UK or EU data-residency option for this Gemini API, and its terms allow the data to be stored or cached in any country where Google or its agents operate, so your documents may be processed outside the UK and the EU. - Vercel hosts the SmartST web application.
- Railway hosts the background worker that does the heavy work on your portfolio: turning it into a PDF export, and preparing your uploaded documents to be read.
- Anthropicis the model provider the document reading and grouping above can be configured to use instead of Google, and is the one that read every uploaded document before we moved to Gemini. When it is in use, the evidence documents you upload are sent to Anthropic's Claude API in the same way — the file itself, as a PDF or an image, along with the name you gave the file — and Anthropic returns the same kind of structured description, then groups and scores those descriptions against your specialty's self-assessment domains. What goes with them is whatever the document itself contains — for a typical certificate or reference, your name, and often your GMC number, your employer, and the names of supervisors or co-authors — and nothing else from your account: no email address, no account identifier, and nothing else you have written in SmartST. Anthropic is contractually barred from training its models on what we send it: its commercial terms say it may not, and that covers both the documents and what it returns. It deletes what it receives through its API within 30 days. Two exceptions to that are worth knowing, because they are the ones you cannot opt out of: if Anthropic's automated systems flag something as breaking its usage policy, it keeps that content for up to two years and its own classification of it for up to seven; and it may keep anything longer where the law requires. There is an arrangement under which Anthropic stores nothing at all, and we do not have one, so the 30 days is what would apply to your documents. Anthropic contracts with UK customers through its Irish company and publishes a data processing agreement covering UK transfers, but the reading itself is not pinned to a region — by default it runs wherever Anthropic has capacity, so your documents may be processed outside the UK and the EU.
- Resenddelivers our email. That covers the emails your account depends on — confirming your address, resetting your password — and, unless you have told us not to, occasional ST1 guidance and SmartST updates. Resend receives your email address and your name so it can address and deliver the message. Every guidance email carries an unsubscribe link, and unsubscribing stops those without affecting the emails your account depends on. Using Resend takes your email address and your name outside the UK and the EU. Our email is dispatched from Resend's Ireland region, but Resend stores its account data, email metadata, logs and API records in the United States, so those details are held there. Resend is SOC 2 certified, publishes a data processing agreement, and is certified under the EU–US Data Privacy Framework. Resend also records when the email it sends is opened and which links in it you click: each message carries a tiny invisible image that loads when the message is opened, and the links in the body are routed through Resend before they redirect on to their destination. This applies to every email we send you — the emails your account depends on, such as password resets and sign-up confirmations, carry the same tracking as the guidance and update email, because it is switched on for the whole sending domain and every message leaves through it. We use it to see whether our email is arriving and being read. If you would rather it did not record you, most email clients can be set to block remote images, which stops the open from being recorded, and you can choose not to click the links in the message.
- Sentryprovides error monitoring that alerts us when the app, the render worker, or the service that sends your account emails hits a technical fault, so we can fix it. We send Sentry only technical error diagnostics, identified by your account's internal ID; we deliberately strip out personal data, portfolio content, and credentials before anything is sent, and we do not enable Sentry's session recording or performance tracking. (That is a statement about Sentry's error monitoring only; it does not describe our email, whose tracking is covered under Resend above.)
- PostHogcounts visits to the site, so we can see how many people are reading the guidance and, when you arrive through a partner's link, how many people that partner introduced. Without it we cannot tell a campaign nobody responded to from a link that was simply broken. PostHog holds that data in its European cloud, so it stays in the EU. Unlike Sentry above, which does receive your account's internal ID, PostHog receives no identifier for you at all: we never send it your name, your email address, or any account ID, so it cannot work out who you are, and nothing it records affects your account, the email we send you, or what you have access to on SmartST. What we ask it to record is the pages you visit and, if you came through a referral link, which partner it was. Alongside that, PostHog collects what any analytics tool collects about a visit without being asked: the site you arrived from, your browser, device and screen size, your time zone, and an approximate location worked out from your IP address. Where a page's address contains an identifier — the address of one of your portfolios, say — we strip it out before the visit is recorded, so what PostHog stores is that someone opened a portfolio, not which one. We do not enable PostHog's session recording, and we leave its automatic capture of clicks and form contents switched off, so it never sees what you type or what your portfolio says. If you accept cookies, PostHog stores a small identifier on your device so it can tell a repeat visit from a new one. If you reject them, we still count the visit, but nothing is stored on your device at all: PostHog works out a scrambled code on its own servers instead, from details such as your IP address and browser, and changes the scrambling every day — so a visit can be counted without anything being written to your browser, and yesterday's visit cannot be tied to today's. Until you make a choice, nothing is sent to PostHog and its code is not even loaded. When we do send something to PostHog, the request goes to our own address,
smartst.co.uk/ingest, and we pass it on to PostHog from there, rather than your browser contacting PostHog directly. We do that because privacy tools and ad blockers block requests sent straight to analytics companies, and when that happens the visit goes uncounted. It changes the route the request takes, not what is in it or where it ends up.
How long we keep it
We keep your data for as long as your account is active. You can delete your account at any time — everything in it, including every document you have uploaded — from your account settings, and you can also ask us to delete it by email. Either way, it is gone. There is one exception, and it is deliberate.
If you unsubscribe from our guidance and update emails, we add your email address to a list of addresses SmartST must not send marketing to, and we keep it there indefinitely — including after you delete your account. That is what makes the refusal stick. The record is stored against the address itself rather than against your account, so if that account is deleted and the same address signs up again, we still recognise it and still do not email you. Erasing it along with everything else would quietly make you mailable again, and the Terms acceptance on the new account would look like permission you had never given.
Two other things put an address on that list, and both mean the same thing in practice — stop sending. If email to an address permanently fails to arrive, or if someone reports one of our emails as spam, we record it and stop the guidance and update emails to that address. A spam report does not stop the emails your account depends on: we deliberately keep those working, so reporting us never costs you access to your own account.
We use that record for nothing else. It holds your email address, why it was added, and when — nothing else about you, and no link back to the account — and it is only ever read to decide not to send you something. If you change your mind, email us at hello@smartst.co.uk; there is no self-serve way back, so starting those emails again is something a person here has to do.
Your rights
Under the UK GDPR, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected (rectification);
- have your data erased;
- restrict how we process your data;
- receive your data in a portable format (data portability);
- object to our processing of your data.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator, at ico.org.uk.
Cookies
We set essential authentication and session cookies, which keep you signed in. With your consent, we may also set non-essential cookies for analytics and referral attribution; we never set these before you accept them, and you can reject or withdraw consent at any time. We do not use advertising cookies. For more detail, and to change your choice, see our Cookie Notice.
Contact
To ask a privacy question or to exercise any of your rights, contact us at hello@smartst.co.uk.
Related
See also our Terms of Use.