Privacy & data · Private preview

Useful feedback needs careful data.

This page explains what Circuit currently handles, why it is needed and the controls built around it. Your mock organiser should also provide the formal privacy information that applies to their event.

At a glance

Only what the circuit needs.

01

Account

Google display name, verified email and optional profile image so Circuit can identify your signed-in account.

02

Event access

Organisation membership, role, invitations, pre-registration, attendance and assigned circuit slots.

03

Assessment

Examiner-selected criteria, rating, written feedback, replay moments and submission timestamps.

04

Operations

Event settings, schedule changes and a limited audit trail needed to run and reconcile the mock.

Purpose

Human-run educational mocks only.

Circuit uses this information to authenticate participants, deliver the correct schedule and candidate prompt, record human examiner feedback, release results and help organisers reconcile their event.

Do not enter real patient names, NHS numbers, dates of birth, addresses, copied clinical records or candidate health and reasonable-adjustment information. Station cases must be fictional, synthetic or properly de-identified.

Who sees what

Access follows organisation, role and assignment.

  • Owners and organisersManage their organisation’s participants, events, schedules, marks and released reports.
  • ExaminersSee their assigned candidates, station content and submitted marks needed to examine.
  • StudentsSee their own schedule. A candidate prompt unlocks only after the assigned examiner starts; results unlock only after organiser release.

Firestore Security Rules enforce these boundaries. Matching a pre-filled email is accepted only when Firebase reports that Google email as verified.

Storage & providers

Firebase holds live event data. Cloudflare delivers the app.

Firebase Authentication provides Google sign-in and Cloud Firestore stores Circuit records. Cloudflare Workers and static assets deliver the web interface at this domain. Circuit currently has no advertising network or behavioural analytics integration.

The browser stores a small device preference for default station duration and venue. It contains no candidate, mark or participant record. Firebase also uses browser storage needed to maintain your signed-in session and resilient data connection.

Retention

The pilot baseline is review, export, then remove.

Circuit recommends that organisers review identifiable mock data for deletion within 90 days of result release, and remove unused invitations or unmatched pre-registration rows within 30 days of the event unless they document a necessary reason to keep them.

Deletion is not automatic in the private preview.The organiser and Circuit operator must complete and verify approved deletion requests. Deleting a Firestore parent without its subcollections is not sufficient.

Your choices

Start with the organisation that invited you.

Ask your mock organiser if you need to access, correct, export or request deletion of event information. They can identify the event and verify your relationship to it before escalating an operator request.

For account-level deletion, the organiser should ask the Circuit operator to remove the Circuit profile and, where requested, the linked Firebase Authentication account. Some information may need to remain temporarily when an incident, complaint or other documented obligation is still open.

Contact

Know who to ask.

Your mock organiser is the first contact for event attendance, assignments, marks and feedback. The service is operated by the Circuit service operator.

During private preview, ask your organiser to escalate verified account-level requests to the Circuit service operator.

Using Circuit today?

Keep prompts protected and exports controlled.

Use the exact invited Google account, never share sign-in access, and store any downloaded cohort CSV in an organisation-approved location.

Read the user guide