Privacy Policy
Draft — last updated August 1, 2026.
Draft pending legal review
What we collect
Contact-form submissions (name, email, institution, role, and message). Account data for users we provision (name, email, institutional role). Within the product: institutional and program-level metrics, survey data, uploaded documents, and — on our roadmap, not yet enabled — individual-level trainee and demographic data (see our Data Processing stance).
How we use it
To respond to inquiries, provision and operate accounts, and run the product for the institutions that use it. We do not sell personal information, and we do not use it for advertising.
Who else sees it
Only the service providers required to run Empower GME — our hosting provider, database provider, email delivery provider, and error-monitoring provider — each bound to protect it, and only for the purpose of providing the service.
Security
Encryption in transit and at rest, tenant isolation between institutions, and role-based access control. Details on our Security page.
Sensitive data
Empower GME is aggregate-data-first by design. Individual-level trainee, demographic, and performance data is a separate, gated module with its own access controls, not enabled by default — see our Data Processing stance.
Retention & deletion
Institutions own their data. On request, we provide an export and honor deletion, subject to any retention period required by law or an active contract.
Your rights
You may request access to, correction of, or deletion of your personal information by contacting us. Depending on your location, additional rights may apply under state privacy law.
Changes
We'll update the date at the top of this page when this policy changes and, for material changes, notify institutional customers directly.
Contact
Questions or privacy requests: use our Contact page.