Privacy Policy
PRIVACY POLICY
AcroXeR NursingVR
Surgical Mind Inc.
- Version: v2.0
- Effective date: September 8, 2026
- Last updated: September 8, 2026
- Application: AcroXeR NursingVR (distributed on the Meta Horizon Store)
- Company: Surgical Mind Inc.
- Contact: cs@surgicalmind.com
Surgical Mind Inc. ("we", "us", "our", or the "Company") develops and operates AcroXeR NursingVR ("NursingVR" or the "App"), a VR nursing skills (medication administration) simulation application distributed on the Meta Horizon Store. This Privacy Policy explains what data we process, how and why we process it, and how any user can request deletion of their data.
This Privacy Policy applies to NursingVR as well as to our other applications (including AcroXeR), our website (acroxer.com), and related services. NursingVR is expressly covered by this policy throughout.
We process User Data received from Meta Platforms Technologies in accordance with Meta's Developer Data Use Policy and other applicable Meta terms. Nothing in this policy supersedes, modifies, or is less protective than those policies.
[At a glance]
- What do you collect?: Meta account identifier, entitlement and subscription status, your own-account details (email, password, nickname, first and last name, plus optional phone number, license acquisition date and country), simulation training and assessment records, device and app information, access and error logs
- What do you not collect?: Camera or passthrough images, photos, voice recordings, eye tracking, facial or expression data, spatial/room-scan data, precise GPS location, contacts, payment card details, real patient medical information
- Why do you collect it?: To identify your account, unlock purchased content, save and return your training progress and assessment results, set your language, diagnose errors, and comply with law
- Do you sell it?: No. We do not sell data, do not share it with data brokers or ad networks, and do not use it for advertising
- Can I delete it?: Yes. Any user, in any country, can request deletion at any time, free of charge -> see Section 7
- Who do I contact?: cs@surgicalmind.com
[1. Scope]
This policy applies when you:
- download AcroXeR NursingVR from the Meta Horizon Store and use it on a Meta Quest device;
- use NursingVR through an educational or healthcare institution;
- visit our website (https://acroxer.com) or contact us; or
- use any of our other applications and services.
NursingVR is simulation content for nursing (medication administration) education. It is not provided for clinical care of real patients and does not process real patient medical information.
[2. Data we process]
2.1 Data received from the Meta platform
The App uses the Meta XR Platform SDK. When you launch the App, we receive the following data from Meta Platforms Technologies so that we can confirm your app ownership and subscription status and deliver the content you own. Separately from this, the App also operates its own accounts that use an email address and password; the information handled in those accounts is described in Section 2.2.
- Meta App-scoped User ID
> Example / description: A unique numeric identifier issued for this App (e.g., 1000123456789012)
> How it is obtained: Platform SDK GetLoggedInUser
- User Proof (nonce)
> Example / description: A one-time value used to verify that the account is genuine
> How it is obtained: Platform SDK GetUserProof, validated server-to-server with Meta
- Entitlement (app ownership)
> Example / description: Owned / not owned
> How it is obtained: Entitlement check
- Subscription and purchase status
> Example / description: Whether a subscription is active, subscription SKU, start and expiry dates, free-trial status, cancellation status
> How it is obtained: Meta In-App Purchases and the server-to-server Subscriptions API
- Device language and region (locale)
> Example / description: e.g., ko-KR, ja-JP, en-US
> How it is obtained: Device operating system setting (CultureInfo) - obtained from the device itself, not the Meta Platform SDK
We do not collect payment details. All paid transactions in the App are processed through Meta's in-app purchase system. Credit card numbers, bank account details, and billing addresses are handled by Meta; we neither receive nor store them. We receive only whether a subscription is active, together with the subscription SKU and term.
The User Proof (nonce) is discarded immediately after our server verifies the account with Meta and is never stored.
2.2 Data you provide
The App can be used in two ways: with a full account or as a guest.
Guest use - using the App without a full account. Guests are not asked to enter any personal information such as a name, email address, or phone number; the App automatically generates a random, date-based identifier to distinguish usage records. This identifier is not linked to any identified individual. Please note, however, that guest use still involves the data described in Section 2.1: because the App runs on the Meta Horizon platform, your Meta App-scoped User ID and entitlement status are processed even in guest mode, and the guest identifier is associated with that Meta User ID on our servers so that your guest usage records can be located and deleted on request (see Section 7). Guest access is limited to part of the content (two general-medication scenarios and the controls tutorial).
Full account - the following information is processed when a full account is created. Currently, accounts are created by an administrator at the Company or your institution, who enters this information; a self-registration flow where you enter it directly may be added in the future.
- Email (ID)
> Required: Required
> Description: The email address used as your login ID
- Password
> Required: Required
> Description: For a full account, the password is currently set by a Company or institution administrator when the account is created; the App receives it at login for authentication purposes only. A self-service sign-up flow where you set your own password may be added in the future. Only if you tick the save option on the sign-in screen, your password is additionally stored on your device alone for sign-in convenience; this stored copy is never transmitted to or kept on our servers, and it is removed from the device when you untick the option or uninstall the App. For guest use, the App generates a password internally and never exposes it to or collects it from you
- Nickname
> Required: Required
> Description: A display name inside the App, entered by you and separate from your Meta username
- First and last name
> Required: Required
> Description: Collected when a full account is created. Guests are not asked to enter these
- Phone number
> Required: Optional
> Description: May be entered when a full account is created
- License acquisition date
> Required: Optional
> Description: A date field an administrator may enter manually when creating an account. It is internal account-management information unrelated to any real-world nursing license
- Country
> Required: Optional
> Description: Suggested automatically from your device language setting; you may change it or leave it blank
- Support enquiries
> Required: Optional
> Description: The email address and message content you send to cs@surgicalmind.com (the App has no separate in-app enquiry form or file-attachment feature)
2.3 Data generated automatically through use of the service
- Training and assessment records: Selected scenario ID, step-by-step progress, success or failure of each action, deduction items and reasons, 7R/6R assessment results, final score and grade, time taken, date and time of the session, number of retries
- Device and environment: Device model (e.g., Meta Quest 3), operating system and version, app version, language and region settings
- Access logs: IP address, access date and time, server API request records
- Diagnostics: App error and crash logs, and app state information at the time of the error
2.4 Data relating to institutional (B2B) users
If you use NursingVR through an educational or healthcare institution, in addition to the information described in Section 2.2, the following is also processed. Your connection to that institution may be established either by the institution or by you directly entering an institution code.
- Institution name or institution code.
In this case, your nickname and name (Section 2.2), together with your training progress and assessment results, are made available to administrators or instructors at your institution. This is done under our agreement with that institution and for its educational purposes; the institution's own data handling rules apply in addition to this policy.
2.5 Data we do not collect
For transparency, the App does not collect:
- camera images, passthrough imagery, or photographs;
- microphone audio or voice recordings;
- eye tracking, facial expressions, or physical characteristics other than an avatar;
- spatial data (room scans, spatial anchors, environment meshes, or other information about your surroundings captured by the headset);
- precise location data such as GPS;
- contacts, call or message logs, or the list of other apps installed on your device;
- payment card details or billing addresses;
- real patient medical or health information (all patient, medication, and order data in the App is fictional training data);
- age or date of birth.
Hand tracking and controller input are used in real time on the device to drive in-app interaction only; raw tracking data is never transmitted to our servers or stored.
[3. Purposes and legal bases for processing]
We process personal data only for the purposes below. If a purpose changes, we will notify you in advance and obtain consent where required.
- Creating and identifying your account, restoring it when you return, and preventing account spoofing and fraudulent use
> Data used: Meta User ID, User Proof, nickname, email, first and last name, phone number, password, license acquisition date
> Legal basis: Performance of a contract / legitimate interests
- Confirming purchase and subscription status, unlocking paid content, and restoring purchases after reinstallation
> Data used: Entitlement, subscription status, Meta User ID
> Legal basis: Performance of a contract
- Saving simulation progress and providing assessment results, scores, feedback, and resume functionality
> Data used: Training and assessment records
> Legal basis: Performance of a contract
- Supporting institutional training by making results available to administrators and instructors (institutional users only)
> Data used: Institutional identifier, nickname, name, training and assessment records
> Legal basis: Performance of a contract / consent
- Presenting content and pricing appropriate to your language and region
> Data used: Device locale, country
> Legal basis: Performance of a contract
- Diagnosing errors, improving performance, and maintaining service stability
> Data used: Device and environment data, diagnostics, access logs
> Legal basis: Legitimate interests
- Improving content and producing statistical analysis (aggregated and de-identified so individuals cannot be identified)
> Data used: Training and assessment records
> Legal basis: Legitimate interests
- Responding to enquiries and sending necessary service notices
> Data used: Support enquiry data, nickname
> Legal basis: Performance of a contract
- Meeting legal obligations and handling disputes
> Data used: Subscription and transaction status records received from Meta (never card or billing details - see Section 2.1), access logs
> Legal basis: Legal obligation
We do not use user data for targeted advertising, ad profiling, or automated decision-making that produces legal or similarly significant effects.
[4. Sharing and processors]
4.1 What we do not do
- We do not sell personal data.
- We do not share or provide personal data to data brokers, information resellers, or advertising networks.
- We do not use User Data received from the Meta platform for advertising, credit scoring, insurance or lending decisions, employment screening, or any other eligibility determination that could disadvantage a user.
- We do not disclose personal data to third parties without your consent, other than the processors listed below and disclosures required by law.
4.2 Recipients and processors
- Meta Platforms Technologies
> Purpose: Account verification (nonce validation), in-app purchase and subscription status management
> Data shared: Meta User ID, User Proof, subscription SKU
> Retention: Per Meta's own policies
- Microsoft Corporation (Microsoft Azure)
> Purpose: Server and database hosting and operation
> Data shared: The data stored as described in Section 2
> Retention: Until the processing agreement ends or a deletion request is fulfilled
- Your educational or healthcare institution (institutional users only)
> Purpose: Training administration and performance management
> Data shared: Institutional identifier, nickname, name, training and assessment records
> Retention: For the term of the agreement with the institution
We may also disclose personal data where:
- required by law, or requested by law enforcement through lawful process such as a warrant or court order;
- necessary to prevent an imminent risk to the life, health, or property of a user or another person; or
- we are involved in a merger or transfer of business. In that case we will give prior notice, and you may request deletion if you do not want your data transferred.
We enter into written processing agreements with our processors covering restrictions on use, security obligations, limits on sub-processing, and liability, and we monitor their compliance.
[5. International transfers]
Our servers are located in the Republic of Korea. Personal data may be transferred internationally as follows.
- Meta Platforms Technologies
> Country: United States and other countries where Meta operates servers
> Data: Meta User ID, User Proof, subscription SKU
> Purpose: Account verification, payment and subscription processing
> Method: API transmission over the network
> Retention: Per Meta's own policies
If you use the App outside the Republic of Korea, your data will be transferred to and processed in the Republic of Korea in order to provide the service. For transfers of data belonging to users in the European Economic Area or the United Kingdom, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses, and we maintain the protections described in this policy regardless of where data is processed. Your country or region never changes your rights under this policy: every user, wherever located, can request deletion (Section 7) and exercise the rights in Section 8 on identical terms.
[6. Retention and deletion]
We delete personal data without delay once the purpose of collection has been fulfilled. We retain data beyond that point only where a law requires it, and during that period we use it solely for that legally required purpose.
- Account data (Meta User ID mapping, nickname, email, first and last name, phone number, password, license acquisition date, country): Until account deletion or a deletion request -> destroyed, including backups, within 30 days of the request
- Training and assessment records: Until account deletion or a deletion request -> destroyed. De-identified statistics that cannot be linked to an individual may be retained
- Subscription and entitlement status: One year after the subscription ends, or upon a deletion request (for dispute handling and purchase restoration)
- Access logs and diagnostics: Up to 90 days from collection
- Support enquiry records: Three years after resolution (for consumer dispute handling)
- Institutional (B2B) user data: Until the agreement with the institution ends or the institution requests deletion. Individual institutional users may also request deletion of their own data directly at any time through the process in Section 7
Retention required by law. Applicable law requires us to keep a small, specific set of records for a fixed period even after a deletion request. These retention obligations arise from the laws that govern our company, not from where you live, and they are applied in exactly the same way to every user in every country. They never limit who may request deletion - they only mean that the records below are kept for the stated period and then destroyed:
- Records of payment and supply of goods or services: 5 years (Act on Consumer Protection in Electronic Commerce). For the App, these are the subscription and transaction status records we receive from Meta (SKU, term, dates, status); we never hold card numbers or billing details
- Records of contracts and withdrawal of subscription: 5 years (same Act)
- Records of consumer complaints and dispute resolution: 3 years (same Act)
- Access logs: 3 months (Protection of Communications Secrets Act)
Method of destruction: electronic files are permanently erased using methods that prevent recovery; printed materials are shredded or incinerated.
[7. Requesting Data Deletion]
Any user, in any country or region, may request deletion of their personal data at any time, free of charge, without giving a reason. This applies equally to full-account users, guest users, and users who access the App through an institution. We do not limit the right to deletion to users in particular jurisdictions, and we do not review or approve requests before acting on them.
How to request
1. By email (recommended)
- Send to: cs@surgicalmind.com
- Subject: Data Deletion Request
- Include: your account email address or in-app nickname (full accounts), or your Meta username or the guest identifier shown in the App (guest use). This is the minimum needed to locate your records; we will not require any other personal information.
2. By post
- Surgical Mind Inc., attn. Data Protection Officer - 501-801, Sangmu Tower, 7 Sangmujungang-ro, Seo-gu, Gwangju, Republic of Korea
Process and timeline
1. We complete deletion and confirm the outcome within 30 days of receiving your request.
2. Scope of deletion: account data (including the mapping to your Meta User ID), guest identifier and guest usage records, nickname, email, first and last name, phone number, password, license acquisition date, country, training and assessment records, subscription status records, support enquiry records, and any other personal data held on our servers.
3. Copies held in backup storage are removed on our backup rotation schedule; until then they are isolated and not used for any purpose.
4. Once deletion is complete, your personal data cannot be recovered. Only fully de-identified statistical data may remain, and it cannot be re-linked to any individual by any means.
The only exception (legally required retention)
The records listed in Section 6 as required to be retained by law (payment and transaction records for 5 years, consumer dispute records for 3 years, access logs for 3 months) must be kept for those periods and are destroyed without delay once they expire. This exception is based solely on a legal obligation; it applies identically to all users, regardless of geographic location, and your location never affects your right to request deletion or how we handle your request. We do not refuse deletion requests for any other reason.
Related information
- Uninstalling the App from your headset deletes the data stored locally on the device. Data held on our servers must be deleted through the process above.
- Your Meta account itself, and the purchase, subscription, and payment records held by Meta, are governed by Meta's own privacy policy and can be managed through your Meta account settings or Meta support.
- If you use the App through an institution, you may also need to contact that institution regarding records it holds independently.
[8. Your rights]
Regardless of where you live, you may exercise the following rights:
- Access - confirm what personal data we hold about you and how it is processed
- Rectification - have inaccurate or incomplete data corrected
- Deletion - have your personal data erased (see Section 7)
- Restriction - ask us to stop processing your personal data
- Withdrawal of consent - withdraw consent at any time where processing is based on consent (this does not affect processing carried out before withdrawal)
- Portability - receive the data you provided in a structured format
To exercise these rights, contact cs@surgicalmind.com. We respond within 30 days of receipt. For children under 14, a legal guardian may act on their behalf; otherwise an authorised representative may do so with written authorisation.
We will not disadvantage or discriminate against you for exercising these rights. Note that deletion or restriction may mean you can no longer use some or all of the service.
[9. Children and minors]
NursingVR is nursing education content and is not directed to children.
- We do not knowingly collect personal data from children under 14 (in the Republic of Korea) or under 13 (in other countries).
- If we learn that we have collected data from a user below that age, we will deactivate the account and destroy the related data without delay.
- Minors under 18 must have the consent of a parent or legal guardian to use the App.
- Parents and guardians may request deletion of a child's data using the process in Section 7, which we handle on the same terms as any other request.
If you believe we have collected data from a child, please contact cs@surgicalmind.com.
[10. Security]
- Encryption in transit - TLS 1.2 or above is applied to the main communication channels between the App and our servers, and we continuously review and improve our security posture.
- Protection at rest - database access is limited to the minimum number of personnel and sensitive identifiers are stored encrypted. Passwords are stored using one-way encryption (hashing) and cannot be decrypted.
- Access control - we designate a minimum number of authorised personnel and keep records of permission grants, changes, revocations, and access.
- Data minimisation - we collect only what is needed to provide the service and destroy it once the purpose is fulfilled.
- Internal management - we maintain an internal data protection plan and provide regular training to personnel who handle personal data.
- Incident response - if a data breach occurs or is suspected, we will notify affected users and the relevant authorities without delay, in accordance with applicable law and Meta's developer policies.
No transmission over the internet or method of electronic storage can be guaranteed to be completely secure, but we maintain and continually improve reasonable and appropriate technical and organisational safeguards.
[11. Cookies and website]
- VR app (NursingVR) - does not use advertising identifiers or third-party tracking technologies, and contains no advertising SDKs.
- Website (acroxer.com) - uses strictly necessary cookies to keep you signed in and to provide basic functionality. You can refuse cookies in your browser settings, though features that require sign-in may then be unavailable.
[12. Contact and Data Protection Officer]
For questions, complaints, or remedies concerning our handling of personal data, please contact us. We respond within 30 days.
- Company: Surgical Mind Inc.
- Data Protection Officer: Il Kim
- Email: cs@surgicalmind.com
- Phone: +82-62-676-5552 (head office) / +82-2-2093-7760 (Seoul office)
- Address: 501-801, Sangmu Tower, 7 Sangmujungang-ro, Seo-gu, Gwangju, Republic of Korea
[13. Complaints and remedies]
If you need advice or wish to report a privacy concern, you may contact the following bodies:
- Personal Information Dispute Mediation Committee (Korea): +82-1833-6972 / www.kopico.go.kr
- Privacy Violation Report Centre, KISA (Korea): +82-118 / privacy.kisa.or.kr
- Supreme Prosecutors' Office, Cyber Investigation Division: +82-1301 / www.spo.go.kr
- National Police Agency, Cyber Bureau: +82-182 / ecrm.police.go.kr
Users in the European Economic Area and the United Kingdom may lodge a complaint with their local supervisory authority. Users in Switzerland may contact the Federal Data Protection and Information Commissioner. Users in any other country may contact the data protection authority in their own country. The bodies above are listed for convenience only; you may contact us directly (Section 12) or request deletion (Section 7) from anywhere in the world without contacting any authority.
[14. Changes to this policy]
We may revise this policy to reflect changes in law, in our services, or in how we process data. We will post the changes and their effective date in the App and on our website. Where a change is materially unfavourable to users, we will give notice at least 30 days before it takes effect.
- v2.0
> Date: 2026-09-08
> Summary of changes: Full revision. AcroXeR NursingVR and company details (head office address, telephone numbers, Data Protection Officer) stated explicitly; added the data received from the Meta platform and the purposes and legal bases table; described full-account and guest use and the data processed for each; added the data deletion procedure (Section 7); listed data we do not collect; detailed the cloud processor (Microsoft Azure), third-party sharing, international transfers, and retention periods
- v1.0
> Date: 2023-05-15
> Summary of changes: Initial version