Information

Privacy

You can use U Tiger without an account. Cloud saving is optional and can be deleted from the account page.

Who is responsible for the data

U Tiger is the data controller for account and training information stored by this service. Privacy enquiries can be sent through the contact and requests form.

Progress stored in your browser

The reasoning and SJT labs store completed sessions, answers, timings, clues, adaptive targets, settings, recent mistakes and daily-practice dates in local browser storage. Clearing site data removes that local copy.

Optional cloud account

Signing in with Google creates a U Tiger account. Google supplies a stable account identifier, verified email address and may supply a display name. U Tiger does not receive your Google password and does not request access to Gmail, Drive, Calendar or other Google services.

The cloud copy contains the progress already stored by the training labs. It is used to restore progress, combine sessions from different devices, prevent duplicate uploads and show account controls. When a browser already contains anonymous sessions, U Tiger asks whether to add them to the account or keep them separate.

First-play measurement

U Tiger records a small set of first-party events such as a page view, a training start and a completed session. The current visit uses a temporary random identifier held in page memory. U Tiger does not place an analytics cookie or analytics identifier in local storage, and the event record does not contain an account ID, IP address, full referrer URL or raw browser user-agent string. Aggregate results are used to check whether visitors can begin useful practice quickly.

Question and service analysis

Signed-in training records may be used to find broken questions, unusually attractive distractors, slow-loading features and patterns of clue use. Routine reports should use question and session statistics rather than names or email addresses. U Tiger does not use training data to decide whether someone is suitable for medicine, and does not sell it or use it for advertising.

Legal basis

Account and synchronisation processing is carried out to provide the cloud-progress service requested by the account holder. Security logging, aggregated question-quality analysis and anonymous first-play funnel measurement are carried out for the legitimate interests of protecting and improving the service. These purposes should be reviewed if U Tiger adds paid accounts, research projects, marketing or broader profiling.

How long information is kept

Account information and cloud progress are kept while the account remains open. The account page provides immediate deletion of the account and its linked training records. Short-lived security and synchronisation records may remain in hosting backups until those backups expire.

Your controls

The account page provides manual synchronisation, a JSON progress download, sign-out and account deletion. The progress download contains account dates, settings, session results, timings, clues used, selected answers and question identifiers. It excludes question wording, answer keys, explanations, coaching text and internal synchronisation logs.

Need a fuller copy?

You can request access to personal information, correction, restriction or deletion through the contact form. A request may require identity checks. Some rights depend on the legal basis and circumstances.

Contact messages

The contact form stores the name supplied, reply email address, message type, subject, message, optional page reference and submission time. Signed-in users may have the request linked to their account. Messages are retained while they are being handled and for a reasonable record-keeping period afterwards. The unfinished form draft remains only in the sender's browser and is removed after successful submission.

Young users

Many UCAT candidates are 16 or 17. The account remains optional, U Tiger collects no date of birth, school, medical information or university choices, and public leaderboards are not used. A data-protection impact assessment should be reviewed before adding behavioural profiling, marketing, social features or information beyond training progress.

Security and processors

Account sessions use secure HTTP-only cookies. Database access is handled on the server. Hosting providers and Google process limited technical or identity information under their own terms. Routine server logs may include IP address, requested page, browser information and time of access for security and operation.

Changes

This notice will be updated when the service or its data use changes. Last reviewed 17 July 2026. First-play measurement wording added for v1.8.1.