What we collect, why, and what we will not do with it.
This policy explains what Study Nurse AI collects when you use the product, how it's stored, and your rights over it. The short version: we collect what we need to run the service and nothing else. We do not sell your data. We do not share your study materials with third parties for training or advertising.
1. What we collect
account information
- Either an email + password you set, or your Google account identity if you sign in with Google. Passwords are stored only as a salted hash; we never see the plain text.
- Subscription tier and billing status, so we know which features you can use.
- Approximate region (derived from IP), used for fraud prevention and sales-tax compliance.
study materials you upload
- PDFs, DOCX files, images, and audio recordings you choose to upload for question generation.
- Text we extract from those files, kept long enough to generate your questions and shown back to you in your library.
activity inside the product
- Questions generated for you, your answers, your bookmarks, your flashcards, and your performance over time. This is what powers your dashboard and weak-topic detection.
- Diagnostic logs when something fails. Logs are stripped of personally identifying content where possible.
payment information
- Billing is handled by Polar, our payment provider. Your card details go directly to Polar and never touch our servers. We see only your subscription status and the masked last four digits.
2. What we will not do
- We do not sell your data to anyone, full stop.
- We do not use your study materials to train third-party AI models. The text you upload goes only to the language-model providers we use to generate your questions, and only for that single request.
- We do not run advertising and we do not share your usage with ad networks.
- We do not email you marketing without your consent. Account emails (receipts, password resets, security notices) are transactional.
3. Who we share data with
The minimum number of subprocessors needed to operate the service:
- Vercel: application hosting.
- Supabase: database, authentication, and file storage for your uploads.
- Google: only if you choose to sign in with a Google account. Google sees that you authenticated with us; we receive your email and basic profile from Google.
- Anthropic and OpenAI: language-model providers used to generate your practice questions and transcribe audio. Your uploaded text is sent only with the generation request and is governed by their data-handling terms, which disallow training on API content by default.
- Polar: payment processor. Handles checkout, subscription lifecycle, and invoices.
- Resend: sends transactional emails (receipts, password resets, security notices).
- Sentry: error tracking. Alerts us when something breaks. Personal identifiers are scrubbed where possible.
We do not authorize any of these providers to use your data beyond providing their service to us.
4. How long we keep things
- Account data:for as long as your account is active. If you delete your account, it's removed within 30 days.
- Uploaded source files: retained while your account is active so you can regenerate from them. You can delete an upload at any time from your library.
- Generated questions and your answers: kept for as long as your account is active so your dashboard and spaced-repetition queue remain useful.
- Billing records: retained for the duration required by tax and accounting law in our jurisdiction (typically up to 7 years), even after account deletion.
5. Your rights
Wherever you live, you have the right to access your data, correct it, export it, and request deletion. Inside the product, the Settings page lets you export everything as JSON and delete your account. If you'd rather make those requests by email, write to info.stilak@gmail.com.
If you're in the EU, UK, or California, additional rights apply under GDPR and CCPA respectively, and we will honor those requests under those laws' timelines.
6. Children
Study Nurse AI is intended for nursing students, who are generally adults. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, email us and we will remove it.
7. Changes to this policy
When we make material changes, we'll email registered users and update the effective date at the top of this page. Previous versions are available on request.
8. Contact
Questions, requests, complaints. Email info.stilak@gmail.com. The dev reads every one.