White Coat World (“we,” “us,” or “our”) operates a pre-health admissions guidance platform that is licensed to academic departments and provided to their students. The department funds it. Students are never charged for it and are never shown advertising on it.
Where a student is affiliated with a partner institution that has signed an agreement with us, that institution is the data controller and FERPA record owner, we act as a School Official under 34 CFR § 99.31(a)(1)(i)(B) of the Family Educational Rights and Privacy Act, and we process those records as a processor on its documented instructions. That designation takes effect only through such a signed agreement.
Until a student’s institution has signed such an agreement, that student holds their account directly with us: they create it themselves, they upload their own records, and we hold that information as the data controller under their own consent rather than a school’s. This is a transitional arrangement rather than the destination, and while it lasts the student alone controls who sees their work — no institution can reach it without a consent the student grants and can revoke. In every case we access student education records only for legitimate educational purposes, and we never sell or license student data to third parties.
You can create an account two ways, and what we collect differs slightly.
Google sign-in: we receive your email address and display name from Google. We do not receive or store your Google password. Your Google sub identifier is immediately hashed with SHA-256 into a deterministic UUID — preventing user enumeration if our records were ever disclosed.
Email and password: we store your email address and a password. We never store the password itself. It is converted to an Argon2id hash — a one-way transformation that cannot be reversed back into your password, even by us. We cannot tell you what your password is, and we will never send it to you. You must verify your email address before your first password sign-in.
If you turn on two-factor authentication, we store the secret your authenticator app uses, encrypted at rest with AES-256-GCM under a key held outside the database. Your ten backup recovery codes are stored only as SHA-256 hashes — we can verify one you enter, but we cannot read them back or re-display them, so keep your copy.
Email-verification and password-reset links contain a single-use token. We store only a SHA-256 hash of that token, and it expires quickly (24 hours for verification, 1 hour for password reset).
When you set or change a password, we check whether it appears in the public Have I Been Pwned breach corpus. This check is designed so that your password never leaves our servers: only the first five characters of its SHA-1 digest are sent, and the service cannot determine which password was checked.
If you choose to add a phone number during onboarding, we store it and use it only for account security — recovery and one-time verification codes. It is never used for marketing, never shown to other users, and never shared with your institution. One-time codes themselves are stored as SHA-256 hashes, expire after 5 minutes, and lock out after 5 failed attempts. You can leave this blank.
You can create a link that lets someone outside White Coat World read your personal statement and leave comments — a mentor, a professor, a family member who has no account here. Because it has to work for someone with no account, the link itself is the only credential: anyone who has the URL can open it, read the full copy of your essay saved at the moment you created the link, and see the comments other reviewers have left. There is no sign-in, and we cannot tell who opened it. Treat it like a door key, and send it only to people you mean to give it to.
You choose how long a link lasts (14 days by default, 60 at most), and you can revoke it at any time. Revoking is a real deletion, not a flag: the link, the saved copy of your essay, and every comment left on it are removed together.
If you leave a comment as a reviewer, we store the name you type and, if you provide one, your email address, so the student knows who the feedback is from. That information is deleted with the link.
GPA, test scores, clinical hours, volunteer hours, research hours, shadowing hours, experience descriptions, personal statement text, letters of recommendation metadata, and target school lists. This data is used exclusively to generate your gap analysis and admissions guidance.
Transcripts and other uploaded files (PDF, JPEG, PNG, WebP; max 10 MB) are validated against their magic bytes, passed through a PII scrubber that strips names, SSNs, student ID numbers, email addresses, and phone numbers, then stored in Supabase object storage with AES-256 encryption at rest.
When you accept a legal agreement, we record which document and version you accepted, when, a cryptographic digest of the published document, and — at the moment of acceptance only — your IP address and browser user-agent string. This is the record that establishes an agreement was formed. See section 7 for how long it is kept and what happens to it when you delete your account.
We use PostHog for privacy-respecting product analytics. Events are anonymized (e.g., “report generated,” “experience saved”). No PII is transmitted to PostHog.
We run surveys in the app, and so do partner institutions and organizations you are affiliated with. Your answers, and the fact that you were invited and whether you completed it, are stored and are visible to whoever published that survey.
Most surveys are voluntary. An institution can also publish a survey marked required, which stays pinned in your feed until it is completed and which you cannot dismiss outright. Even in a required survey you may decline any individual question. A required survey does not lock you out of the platform and does not restrict any other feature. Marking a survey required is an institutional decision, and the institution attests when doing so that its own IRB and FERPA policies permit it.
When you use the free exam prep tools, we store your work: which practice tests and question sets you took, the answer you gave to each question and how long you spent on it, your raw score, the questions you flagged to revisit, and your progress through lessons and flashcards. This is what lets you pick up where you left off and see where you are improving.
Separately and entirely voluntarily, you may tell us the score you actually received on a real exam. We ask because it is the only way to know whether our practice material helps. Your individual score is never published, never shown to other students, and never attached to your name in anything an institution sees — it is used only inside aggregate statistics. If you delete your account, that record is hard-deleted along with the rest of your practice history; only aggregate figures already calculated remain, and they are never reconstructed back to you.
For students, we record how long you spend on the browsing surfaces of the community layer — the feed, Pills, and Explore — as a running daily total. It exists to enforce a wellbeing limit rather than to profile you: past a daily cap those browsing surfaces are paused for the rest of the day. Nothing you actually came here to do is affected — your application work, messages, and surveys are never capped and never counted.
We keep a per-day total only. This is not sold, not shared with your institution as an individual record, and not used for advertising.
White Coat Connect is our community layer, and we store what you create in it: your posts and the photos or video attached to them, your comments and replies, your Pills (short videos) and their transcripts, your Daily Doses, anything you write in a cohort or group, and your direct messages. We also store the actions that make a feed work — likes, saves, reposts, who you follow and who follows you, who you have blocked or muted, what you reported, and the notifications generated for you. Your community profile itself is stored too: display name, username, avatar, bio, interests, and an optional location if you add one.
Direct messages are stored, not end-to-end encrypted. They are encrypted in transit and at rest, and we do not read them in the ordinary course of running the platform, but we are technically able to and will where we must — to investigate a report, to comply with a legal obligation, or to act on a safety risk. Please do not treat a message here as a private channel for anything you would not want a platform operator to be capable of seeing. Mentoring is part of this: a mentoring request, the note attached to it, and any thank-you message are stored the same way, and a mentee’s identity stays hidden from the mentor until the mentee chooses otherwise.
We use this to operate the community — to show you a feed, deliver your messages and notifications, and enforce our Acceptable Use Policy. It is not used for advertising, never sold, and not used to train AI models. Your institution does not get a window into your posts or messages: what it can see is described in section 6. If you delete your account, all of it is hard-deleted — see section 7. One limitation worth stating plainly: the self-service data export in Settings does not yet include your posts, comments and messages, and section 8 explains how to ask us for them in the meantime.
White Coat World is 100% ad-free. We do not load Google AdSense, advertising networks, tracking pixels, retargeting scripts, or marketing cookies. Student browsing behavior and profile data are never shared with advertisers. This policy is permanent and a hard requirement for FERPA-aligned institutional deployments. The only third-party embeds anywhere on the site are video players: the introductory video on our public homepage, and the lesson videos in the Boards & Tests classroom, which load nothing until you press play. Both are hosted on YouTube — see section 9.
We never use student data to train or fine-tune AI models, sell data to third parties, or share data with advertisers.
We may study our own usage records to learn what actually helps students — for example, whether writing a more specific application plan predicts staying on track. This is analysis of information we already hold because the product needs it; we do not collect anything extra for it, and no student is assigned to a condition or given a different version of the product for research purposes.
Any such analysis is done on a pseudonymised extract, and anything we publish or share is aggregate only — we do not quote your notes, your essays, or anything else you wrote. Where review by an independent ethics board (an IRB) is required or appropriate, we obtain it before analysing, not after. Deleting your account removes your records from any future analysis.
Your academic profile text (capped at 3,000 characters per prompt) is passed through our PII scrubber before being sent to Google Gemini Flash for gap analysis. Google's API terms prohibit training on API inputs. We do not use student data to fine-tune models.
SOC 2 Type II and ISO 27001 certified. All environment secrets are stored in Vercel's encrypted vault — no credentials are committed to source code.
SOC 2 Type II certified. PostgreSQL with AES-256 encryption at rest, point-in-time recovery, and geographic redundancy.
Faculty notification emails and account emails (verification, password reset). No student PII is included in email bodies beyond first name and the section a review was requested for; account emails carry a single-use, short-lived link.
Redis service used to enforce rate limits and cache session-revocation state. The keys it holds are derived from IP addresses, account identifiers, and — for the one-time-code limiter — phone numbers. No academic profile content, application materials, or uploaded documents are stored there, and entries expire automatically after a short window.
SMS delivery of one-time security codes is built against Twilio. It is not active today — no Twilio credentials are configured, so no text messages are sent and no phone number is transmitted to Twilio. We disclose it because turning SMS delivery on would engage Twilio as a sub-processor of your phone number, and you should know that in advance rather than after the fact.
Application error reporting, configured with personal-information collection disabled and an additional scrubbing pass on every event before it is sent. Like SMS, this is currently inactive — no Sentry connection is configured, so no error data leaves the application today.
Server-side product analytics — which features are used and how often — captured without personally identifiable information, as described under “Usage Analytics” above. It receives product events, never your academic content: no transcript, GPA, personal statement, experience, or advising material is sent to PostHog. It is named here as well so that this list, the Security page and our Data Processing Agreement describe exactly the same set of sub-processors.
Consulted when you set or change a password, to warn you if that password has appeared in a known public breach. Only the first five characters of the password's SHA-1 digest are sent — the password never leaves our servers, your identity is not transmitted, and the service cannot determine which password was checked.
Powers autocomplete in the optional location field in the social layer. When you type in that field, the text you type is sent from your browser to Google. It is used only for that field and is not part of your academic profile or advising workflow.
Our public marketing homepage embeds an introductory video hosted on YouTube, which loads with the page and sets Google cookies for visitors — including visitors who do not have an account.
Video lessons in the Boards & Tests classroom are also hosted on YouTube, on signed-in pages. The lesson player does not load until you press play. A lesson you have not started is a placeholder card drawn entirely by us, with no YouTube frame, no YouTube script and no thumbnail, so opening a chapter sends Google nothing. When you press play, the video loads through youtube-nocookie.com and Google may set cookies. The only information that reaches Google is the identifier of the video you chose to watch — never your name, your practice answers, your scores, your progress, or anything else from your account. How far through a lesson you are is recorded by us, on our own servers, and is not shared with Google.
Neither embed is an advertising or tracking integration.
By default, no faculty member can see your profile. You must explicitly opt in to share your data with a specific institution. Consent is:
This section is about sharing with an institution. It is not the only way your work can leave your account: a personal-statement review link is a separate choice you make yourself, it is not institution-scoped, and it does not require the reader to have an account or to sign in. See “Personal Statement Review Links” in section 2.
| Data Type | Retention Period | Disposal Method |
|---|---|---|
| Academic profile, experiences, schools | Until account deletion | Hard delete on erasure request |
| AI gap analysis reports | Until account deletion | Hard delete on erasure request |
| Uploaded documents (transcripts) | Until account deletion | Hard delete from object storage |
| Practice test attempts, individual answers, and study progress | Until account deletion | Hard delete on erasure request |
| Self-reported real exam scores (voluntary) | Until account deletion | Individual record hard-deleted on erasure; only aggregate statistics already calculated remain, and the aggregate is never reconstructed back to an individual |
| Application plan (Planner) — terms, planned courses, milestones, notes, and the saved history of your edits | Until account deletion | Hard delete on erasure request; included in your data export |
| Faculty comments and personal-statement annotations about you | Until account deletion, or 30 days after the faculty member deletes one | Deleted comments and annotations are hard-deleted by the nightly purge; the rest are hard-deleted on erasure request |
| Personal-statement review links — the saved copy of your essay, plus each external reviewer’s name and optional email | Until the link expires (14 days by default, 60 maximum), you revoke it, or your account is deleted | Revoking hard-deletes the link, the saved essay copy, and every comment on it together; anyone holding the URL can read it until then |
| Community content — posts, comments, Pills and their transcripts, Daily Doses, cohort and group messages, and uploaded photos and video | Until account deletion | Hard deleted on erasure request, including the underlying files in object storage |
| Direct messages, and the conversations they belong to | Until account deletion | Hard deleted on erasure request. Stored, not end-to-end encrypted — see section 2 |
| Community engagement and graph — likes, saves, reposts, views, follows, blocks, mutes, reports, notifications, and your community profile | Until account deletion | Hard deleted on erasure request |
| Mentoring requests, the note attached to them, and thank-you messages | Until account deletion | Hard deleted on erasure request; a mentee is anonymous to the mentor unless the mentee chooses otherwise |
| Soft-deleted records (experiences, reports) | 30 days after soft-delete | Automatic purge via cron |
| Audit log entries | 1 year | Automated rolling deletion after 12 months |
| Legal acceptance record (which document, which version, when, digest of the published document) | Retained after account deletion | IP address and browser details erased on deletion; the acceptance itself is retained as proof that an agreement was formed |
| Account-closure audit entry (account identifier + closure timestamp) | 1 year after deletion | Automated rolling deletion after 12 months |
| Encrypted database backups (point-in-time recovery) | Up to 7 days | Deleted records age out of the recovery window automatically; backups are never restored to bring back a deleted account |
| Verifying supervisor’s IP address (hour verification only) | Until you delete the experience or your account | Recorded only when a supervisor confirms your hours, to detect self-verification; deleted with the experience record |
| Anonymous benchmark contributions | Indefinite (no PII) | PII stripped at contribution time; aggregate data retained |
| Session tokens (JWT) | 7 days | Expire automatically; revoked early on password reset or 2FA change |
| Password hash, 2FA secret, recovery codes | Until account deletion | Hard delete on erasure request |
| Phone number (if provided) | Until removed or account deletion | Hard delete on erasure request |
| One-time codes (email, password reset, SMS) | 1–24 hours depending on type | Stored hashed; expire and are purged automatically |
What survives deletion, and why. Two records outlive your account, and we would rather name them than let you discover them: the acceptance record described in section 2, and a single audit entry noting that an account with your identifier was closed and when. Neither contains your academic work, your writing, your documents, your credentials, or your contact details. We keep the first because obligations in the Terms survive termination and a record of agreement is worthless if it vanishes the moment a dispute becomes likely; we keep the second because an institution auditing us needs to be able to see that a deletion actually happened. The closure entry is purged on the normal one-year audit-log schedule.
Backups are a lag, not an exception. Deletion removes your data from our live systems immediately. Encrypted disaster-recovery backups still contain a copy until they age out of the recovery window — currently up to seven days — after which no copy remains anywhere. We never restore a backup to bring back a deleted account, and nobody queries backups to answer a question about you. We name this because “deleted instantly and everywhere” would not be true, and a school's privacy reviewer will ask.
Inside the application we set only strictly necessary cookies: a session cookie for authentication (HttpOnly, Secure, SameSite=Lax), a CSRF-protection cookie for the sign-in flow, and a small number of cookies that remember interface preferences. Our product analytics (PostHog) runs entirely server-side — there is no in-browser analytics script, so no analytics cookie is set on your device.
Two exceptions, both YouTube video players. The introductory video on our public marketing homepage loads with the page and sets Google cookies for anyone who visits it. Lesson videos in the Boards & Tests classroom sit on signed-in pages, but load nothing until you press play — if you never press play, no YouTube cookie is ever set on a signed-in page. Beyond those two players, no advertising cookies, tracking pixels, or third-party marketing scripts are loaded anywhere on the site. See our Cookie Policy for the full breakdown.
We may update this policy to reflect changes in our practices or legal requirements. This policy is versioned, and material changes require you to accept the updated version in the app before continuing to use the Platform. For minor, non-material changes, continued use after the effective date constitutes acceptance.
Privacy questions, data export requests, or institutional Data Processing Agreement inquiries: our contact form or privacy@whitecoatworld.org
Security vulnerability reports: our contact form or security@whitecoatworld.org
Institutional Partners
If you represent a university and need a HECVAT questionnaire (in preparation), a Data Processing Agreement (DPA), or a FERPA addendum, please use our contact form or write to security@whitecoatworld.org. See also our Security & Data Privacy statement.