Legal

Privacy Policy.

Effective May 9, 2026Last updated September 20, 2026

NurseMind is a study and self-directed learning tool for nursing students and licensed nurses. We collect the minimum necessary to deliver the Service, store nothing we don't need, and never sell your data. The product is architecturally prevented from receiving Protected Health Information. This page explains the rest in plain language.

1

Scope

This Privacy Policy explains how NurseMind, Inc. ("we," "us," "NurseMind") collects, uses, and protects information when you use the NurseMind iOS app (Bundle ID app.nursemind.ios) and the website at nursemind.app (together, the "Service").

NurseMind is a clinical reference and self-directed learning tool for nursing students and licensed nurses. It is not a clinical decision support system, not a medical device, and not designed to receive or process Protected Health Information.

2

What we collect

Account and identity

By default, NurseMind creates an anonymous account on first launch — a randomly generated UUID with no name, email, or other identifier attached. You may optionally connect Apple or Google from Account & sync in Settings after onboarding. Apple supplies an account identifier and your email address, which may be a private relay address. Google supplies an account identifier, email address, and basic profile information such as your name and profile picture when available. Supabase uses this information for authentication and saved-data sync. We request only basic Google identity permissions, not Gmail, Drive, contacts, or health data. We never receive your Apple or Google password, and do not share this account information with advertising partners.

Profile preferences

Optional, user-entered: display name, nursing role (RN, LPN, CNA, student), unit specialty, and years of experience. Used only to personalize content and the AI co-pilot's specialty awareness. Stored in your account on our backend so it syncs across signed-in devices.

Usage and content

Library bookmarks, in-app preferences, and saved AI answers are stored locally and synced to your internal account. Connecting Apple or Google lets you recover them on another device. Unsaved conversation history is stored on your device; relevant recent turns are sent for AI processing as described below. Your user-selected profile photo stays on your device.

AI co-pilot inputs and responses

Questions you submit to the AI co-pilot, the cited evidence chunks retrieved to ground the answer, and the AI's response. Used to deliver the answer, enforce daily quotas, and (anonymized, aggregated) improve the system prompt and retrieval. Inputs pass through a server-side scrubbing step that detects and removes apparent patient-identifying data (names, MRNs, dates, room numbers) before reaching any third-party model.

OpenAI or Anthropic processes scrubbed questions, recent conversation context, relevant nursing preferences, and retrieved evidence to classify requests, generate answers, and check source support. The configured AI provider also supports external source searches when needed. OpenAI API data is not used for training by default. We disable optional response storage; provider abuse-monitoring retention and other processing policies still apply. This is not a zero-retention guarantee. See OpenAI's API data controls.

Our backend may cache an approved answer for up to five minutes for an exact repeat from the same user. The cache does not store the raw question or conversation history.

Subscription and billing

Subscription status (free, monthly, yearly) and the entitlement timestamp. Billing itself is handled by Apple through StoreKit; we do not see your payment card or Apple ID. We use RevenueCat to manage entitlement state — RevenueCat receives a hashed account identifier, the product purchased, and standard purchase metadata from Apple.

Device and diagnostic

Device model, iOS version, app version, locale, and crash reports (via Sentry). Used to triage bugs and prioritize fixes. We do not collect precise location, the contents of your photo library, your contacts, or any other on-device data.

Product analytics

Anonymous, aggregated usage events (e.g., "user opened Library tab," "user submitted an AI question") via PostHog. We use the minimum analytics necessary to understand which features matter. We do not link analytics to your identity beyond an anonymous installation ID, and we never sell analytics data.

3

What we don't collect

NurseMind is architecturally prevented from collecting Protected Health Information. The product has no patient name, date of birth, MRN, room number, or chart fields anywhere in its UI. We ask that you never enter patient-identifying information in any input — including AI questions and saved content. Our input filters remove recognized identifying patterns before model processing. These filters do not replace your responsibility to keep patient-identifying information out of the Service.

We do not collect or process: precise location, contacts, calendars, photos, microphone audio (other than transient, on-device speech recognition you initiate by tapping the microphone — that audio never leaves your device), health data from HealthKit, or biometric identifiers.

4

How we use information

To provide the Service: render the library, answer your AI questions with grounded citations, sync your bookmarks and saved content across signed-in devices, enforce daily AI quotas, manage your subscription state.

To improve the Service: triage crashes, evaluate which library entries get the most use, tune the AI co-pilot's retrieval and refusal behaviors. All improvement work uses anonymized, aggregated data.

To communicate with you: respond to support emails and (only if you opt in via your iOS notification permission) send a small number of useful product notifications.

We do not sell your data or license it to data brokers. We do not send clinical questions, answers, or library activity to advertising partners.

With your App Tracking Transparency permission, Meta receives device and app identifiers, app activations, onboarding and tutorial completion, paywall views, checkout starts, and trial and subscription events to measure NurseMind ads. RevenueCat sends subscription events, including product, price, currency, and timestamps. Matching information can include IDFA, vendor and app-scoped identifiers, IP address, device information, and a pseudonymous account identifier. We do not provide Meta with your name, email, phone number, or profile details.

The TikTok Business SDK also measures installs and subscription events using app/device identifiers and an internal account identifier. It reads IDFA only with your tracking permission. You can decline or change tracking permission in iOS Settings → Privacy & Security → Tracking. Meta event sharing requires authorized consent. App features and subscription access do not depend on granting permission.

5

Service providers and advertising partners

We share information only with the third-party services listed below, each used for a specific purpose disclosed here:

  • AppleUnited States
    App distribution, Sign in with Apple, StoreKit billing
  • Supabase, Inc.United States
    Authentication and Postgres database (account record, profile preferences, saved content)
  • RevenueCat, Inc.United States
    Subscription entitlement management and consented Meta subscription-event delivery
  • Meta Platforms, Inc.United States
    Consented advertising measurement using device/app identifiers, app activations, and subscription-funnel events
  • TikTokUnited States
    Advertising attribution using app/device identifiers, an internal account identifier, and install and subscription events
  • Anthropic PBCUnited States
    External source search and AI processing when configured; receives scrubbed questions and context, plus evidence, nursing preferences and draft answers when used for generation or review
  • OpenAI, L.L.C.United States
    AI request classification, answer generation, evidence review, external source search and text embeddings; receives scrubbed questions and context, relevant nursing preferences, evidence and draft answers
  • Google LLCUnited States
    Optional account sign-in using basic identity and authentication information; no clinical questions or saved answers
  • ImprovMXUnited States and Europe
    Support email forwarding; receives your sender address and messages or attachments you choose to email us
  • Google LLC (Gmail)Global infrastructure
    Support email inbox; stores your sender address and messages or attachments you choose to email us
  • SMTP2GOUnited States hosting
    Delivery of support replies; processes recipient addresses, reply content and attachments, and email delivery metadata
  • SentryUnited States
    Crash reporting and error monitoring
  • PostHog, Inc.United States
    Anonymous, aggregated product analytics
  • Vercel, Inc.United States
    Web hosting for nursemind.app

These services process information under their applicable terms and privacy policies. Clinical questions, answers, and library activity are excluded from advertising events. The Service is not designed to receive Protected Health Information.

6

Where information is stored

Your account data, profile preferences, saved bookmarks, and saved AI answers are stored in our Supabase Postgres database hosted in the United States. Unsaved conversations stay on your device; our operational AI logs exclude question and answer text. If you flag an answer, its content is submitted for quality review. Crash and analytics data is stored by Sentry and PostHog, both in the United States.

The Service is intended for users in the United States at v1 launch. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.

7

How long we keep it

Account, profile, and saved content: retained while your account is active. If you delete your account from the Profile tab, we permanently delete the associated records within 30 days, excepting backups, which roll over within 90 days.

Unsaved AI conversation history is stored on your device. Approved-answer caching on our backend lasts up to five minutes. Saved answers follow the account-retention policy above; AI provider processing follows the policies described in Section 2.

Crash and analytics data: retained for up to 12 months in anonymized aggregate form.

8

Your choices and controls

Delete your account. In the iOS app, go to Profile → Manage subscription → Delete account. This removes all account data from our backend within 30 days.

Cancel your subscription. Subscriptions are managed by Apple. Open Settings → your name → Subscriptions → NurseMind to cancel. Cancellation takes effect at the end of the current billing period. Refunds are handled by Apple.

Opt out of analytics. Toggle off product analytics in Profile → Notifications and privacy. (Coming in a future release; for now, write to hello@nursemind.app and we'll honor your opt-out request.)

Disable notifications. Profile → Notifications, or in the iOS Settings app under NurseMind.

Export your data. Email hello@nursemind.app and we'll send a JSON copy of your saved bookmarks, profile, and saved AI answers within 30 days.

9

California privacy rights

If you reside in California, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to (1) know what personal information we have about you, (2) delete your personal information, (3) correct inaccurate personal information, and (4) opt out of "sale" or "sharing" of your personal information.

We do not sell your data for money. Advertising measurement disclosures and tracking controls are described in Section 4. You can withdraw tracking permission in iOS Settings. To request access, correction, deletion, or an opt-out of sharing, email hello@nursemind.app from the email address associated with your account. We will respond within 45 days.

10

Children's privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly. If you believe a child under 13 has provided us with personal information, contact hello@nursemind.app.

The App Store age rating for NurseMind reflects content appropriate for users 12 and up; however, the Service is functionally designed for nursing students (typically 18+) and licensed nurses.

11

Security

All connections between the iOS app and our backend use TLS 1.2+. Authentication tokens are stored in the iOS Keychain. Database access is gated by row-level security policies that scope every read and write to the authenticated user's UUID. We review access and infrastructure regularly and maintain a written security policy.

No system is perfectly secure. If you believe your account has been compromised, email hello@nursemind.app immediately.

12

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective" date at the top of this page and, for significant changes, surface an in-app notice. Continued use of the Service after a change constitutes acceptance of the updated policy.

13

Contact

Questions about this policy? Email hello@nursemind.app. We answer within five business days.

NurseMind, Inc. · United States · Last updated September 20, 2026.