Ophthalmic Academy

Privacy policy

What the platform collects, why, who can see it and how long it is kept. Written from what the software actually does.

Effective September 27, 2026.

Who we are

Ophthalmic Academy ("we") is an independent training platform based in Washington. Most accounts are created by a practice or health system that subscribes to the platform ("your organization"). For those accounts, your organization decides who is invited and what they are assigned, and we process your information to provide the service to them.

What we collect

Your account

  • Name, username, email address, job title, role, organization and location or team.
  • Your password, stored only as a one-way hash, and the answers to your security questions, also stored only as hashes.
  • If you turn on two-step sign-in, the key your authenticator app uses, stored encrypted, and your recovery codes, stored only as hashes.
  • If you sign in with Google Workspace or Microsoft Entra ID, the provider, your account identifier with that provider, and the name and email address it shares.
  • If your organization turns on exclusion screening, your date of birth and National Provider Identifier (NPI), used only to check the federal exclusion lists (the OIG exclusion list and SAM.gov).
  • Licenses, certifications and registrations your organization records for you: the type, number, issuing body and state, issue, expiry and continuing-education dates, any notes, and who recorded and verified each one.

Your learning

  • Lesson progress, answers to practice questions and exams, scores and when each activity happened.
  • During a timed practice exam, how many times the exam window lost focus or you left the exam screen, and for how long. It is shown on your result and to your supervisor beside the score. Nothing about what you did elsewhere is recorded.
  • Points, badges and certificates of completion.
  • Competency ratings and sign-offs recorded by your supervisors, the sign-off requests you make, and any note a supervisor adds when closing one. If a supervisor uses the chairside checklist while observing you, it is kept with the sign-off: which steps were done, missed or not applicable, how long the observation took, and any note.
  • Results of certification exams (COA, COT or COMT) that your supervisor or administrator records: the exam date, whether you passed, the score if they enter one, and the readiness forecast the platform showed for you when the result was recorded.
  • Policy acknowledgments and signed attestations. The IP address and browser type at the moment of signing are kept with each one, as a record of the signature.

Requests and reports

  • Requests sent from the sign-in page or this website: your name, email, organization and message, with the IP address and browser type they came from.
  • Reports filed without signing in are not linked to any account. Their IP address is not stored. A one-way code made from it, which changes every day, is kept only to stop floods of spam, along with any contact details you choose to give.

Technical information

  • The IP address and browser type of each signed-in session, and the IP address behind each administrative action in the audit log.
  • Error reports when something breaks, so we can fix it.
  • If you turn on notifications for a device, the address your browser gives us for delivering them, with the device's encryption key and browser type. Turning them off, or removing the app, deletes it.

Cookies and browser storage

  • One session cookie keeps you signed in. It cannot be read by scripts, is sent only over secure connections, and ends when you close the browser. You are signed out after 30 minutes without activity.
  • Browser storage keeps a copy of your progress and settings on your device so the app works smoothly, and an exercise in progress for half an hour so that refreshing the page returns you to it.
  • If you install the app on a phone or computer, the browser keeps one more page, shown when you have no connection. It contains no information about you, and nothing else of the app is stored.

We do not record sessions, we do not use advertising cookies or advertising trackers, and we do not sell personal information.

Services we use

  • NFOservers hosts the platform and its database.
  • Sentry for error reports.
  • Google and Microsoft when you use single sign-on.
  • Google Workspace to send email notifications.
  • Google Fonts serves the typefaces on this website, the sign-in page and the Control Panel, and jsDelivr serves a few open-source code libraries the app and the Control Panel use. Your browser fetches these directly, so those services see your IP address and browser type, as any website you load does.
  • Your browser's push service (Google, Apple, Mozilla or Microsoft, depending on the device) delivers notifications if you turn them on. Each notification is encrypted for your device before it leaves us, so the push service passes it on without being able to read it.
  • Puter powers the AI study assistant and the read-aloud feature. What you type into the assistant, and text you ask to have read aloud, is sent to Puter, which passes it to third-party AI models to produce the answer or the audio.
  • Cloudinary stores images and uploaded videos, and some lessons embed YouTube or Vimeo videos, which load from those services when you play them.

Who can see your information

  • Your organization's administrators, and supervisors for the teams they supervise. Supervisors do not see people outside their teams, and one organization never sees another's data.
  • Our staff, to provide support. Support staff can view the platform as you see it to fix a problem; when they do, it is recorded.
  • The services listed above, only as needed to do their job for us.
  • Anyone the law requires us to share with.

Patient information

The platform is built for training and never asks for information about your patients. Please do not type patient health information into notes, reports, support requests or the AI study assistant.

How long we keep it

  • When an account is deleted, it is removed permanently after 14 days.
  • Signed attestations, policy acknowledgments and certificates are kept as your organization's records until your organization's data is removed, because they are evidence of training that was completed.
  • When an organization leaves the platform, its data is removed as its agreement with us sets out.

Your choices

To see, correct or delete your information, ask your organization's administrator, or contact us at info@ophthalmicacademy.us. If the law where you live gives you further rights over your information, we will honor them.

Children

The platform is for working adults and is not intended for children.

Changes

If we change this policy in a way that matters, we will say so in the platform before the change takes effect.

Contact

Ophthalmic Academy, info@ophthalmicacademy.us