The honest short version: your study history is saved on your device first, and a copy is kept on Nurseal's servers so it survives a cleared browser, a lost laptop, or a switch to your phone. Material you submit for AI features must be transmitted to the AI provider. “Local-first” means your device works without a network — not that nothing ever leaves it. If you buy credits, your card is handled by Stripe on Stripe's own page and never reaches Nurseal (section 7c).
1. Scope and operator
This notice governs Nurseal, a Seal Studios product. Nurseal is operated by Elpidio Samuel Poblano Vallejo, an individual doing business as Seal Studios, in California, United States. He is the person responsible for the information described here — the data controller, in the language of privacy law — and “the operator,” “Nurseal,” and “Seal Studios” all refer to him throughout this notice.
Reaching him about your information — including any request in section 10 — hello@seal-studios.com, or by post to Elpidio Samuel Poblano Vallejo, PO Box 1714, Indio, CA 92202-1714, United States. That mailbox is monitored and serves as both the privacy contact and the support contact; there is one person behind Nurseal and pretending otherwise with two addresses would tell you less, not more. For anything tied to your account, the Feedback button inside the product is faster, because it arrives with your account already attached.
Where Nurseal runs. The operator is in California and the service is offered from the United States. Your information is processed in the United States and, depending on the provider, in other countries where that provider operates. Section 7 names every company Nurseal uses and links each one’s privacy policy, which is where that company says where it operates.
2. Your study history: on your device, and mirrored to your account
Your device is the first place everything is written, so Nurseal works with no network at all — you can take a whole test offline. A copy of three things is then synced to your Nurseal account:
- Practice questions generated for you — the question, its options, the correct answer, the explanations, the hints, and its topic and difficulty tags.
- Your answers — which option you chose, whether it was right, how many hints you used, whether you flagged the question as too hard and the reason you picked, when you answered, how long that question took you, and which study session it belonged to.
- Changes you make to your own difficulty level — when you set your level by hand and which level you set, and when you ask for harder questions to start coming back. This was missing from this list until August 12, 2026, though section 10a has said from the start that deleting your account removes it. It is named here now because this is the section meant to be the complete answer.
About that timing, since it is the one item here that can feel like being watched. Nurseal records how many seconds a question was on your screen, and the clock stops whenever the tab is not in front of you — a closed laptop is never counted as thinking. It is used for one thing: telling apart a hint ladder you worked through from one you clicked to the bottom in four seconds. Those two look identical without it, and they need opposite responses. That same distinction is why a count of how many answers took under five seconds appears in the operator summary described below. It is never shown to you as a timer while you answer, never used to rank you, and never shared with anyone outside Nurseal. Tests are untimed and stay that way.
This changed on July 24, 2026, and the reason is worth stating plainly. Earlier drafts of this notice said study history was designed to stay on your device and that no server-side database was planned. Browsers evict stored data: Safari clears script-writable storage after roughly seven days without visiting the site, so a week deep in clinicals could have erased a semester of your history — along with the record that makes questions you keep missing come back to you. Keeping nothing bought privacy by making the product lose your work. Keeping only what is listed above, saying so here, and letting you take them out or delete them is the honest trade.
These records are locked to your account by the database itself, not merely by the app: another signed-in user cannot read, change, or delete them. Answers are append-only — Nurseal never edits or quietly removes an answer you gave, because a difficulty estimate built on an edited history would be wrong about you. One narrow exception exists, for the person who operates Nurseal, and the next two paragraphs say exactly what it does and does not include.
What the operator can read, as built (August 11, 2026). The database holds one function that hands your summary to no one but an owner account — an account on a short list in the database, which is how Sami, who operates Nurseal, reaches it — and what it hands over is counts about studying, never anything you studied. Per account — yours among them — that is: how many practice questions were generated for you and how many of those came from Nurseal’s own test runs rather than real study (told apart by the name of the model recorded on each), how many separate tests they came from, the date and time of the first and the last, how they were spread across the five difficulty levels, across the six clinical-judgment steps, and across the two thinking levels, and which AI model produced them; how many distinct subjects they covered as a number, never the subject names; how many questions you answered, how many you got right, how many you got right only after hints, how many you skipped, how many you flagged too hard and which reason you chose, those same counts again at each difficulty level, how many separate sittings you spread them over, the typical time an answer took you and how many took under five seconds, and the date and time of the first and the last; how many questions you missed were attempted again in a later sitting and how many you got right that time; and how many times you set your difficulty level by hand or asked for the harder questions back, and where that level now stands. That list is the whole of what it reports about you — the rest of what comes back is the clock time of the read itself and a line naming what the summary is. No question text, no answer options, no correct answer, no explanation, no hint text, and no subject name. The exclusion is enforced by the database rather than by the screen that displays the result: installing the function makes it read back its own deployed code and refuse to install at all if either of the two content-bearing fields appears anywhere inside it. Running it stores nothing new in your account.
And one check about your account rather than your studying, as built (August 12, 2026). The operator can also see, for every account, whether it currently has access at all, when it was created, when it last signed in, and how much of the daily allowance it has used today. It exists because of a real failure: an account was set up without access and sat that way for seventeen days, and the only thing that eventually surfaced it was the person telling us. Nothing in the system was watching, because a refusal is turned away before anything is written down — so being unable to use Nurseal left no trace at all. This check reads the settings on your account so that nobody sits locked out unnoticed again. It stores nothing, and it reads none of your study history.
Two limits, stated because both are easy to overclaim. This is not anonymous, and is not described as such: the summary is per account, so while Nurseal is a private pilot of a few people, an average is one person’s number with a plural name on it. What is true is smaller and worth more — the operator knows whose rows these are and does not read what you studied or what the questions said. And this describes the door Nurseal is built with, not a claim about what anyone administering a database is technically unable to do: reading study content directly is not routine, is not what this function does, and is not something Nurseal is built to do. The narrow door exists to answer one question — whether the questions are landing near the 70–85% correct they are calibrated to — which the usage records in section 3 cannot answer, because they count what was spent and not whether it taught you anything.
Not synced, and not stored on our servers: the study material you add or paste (see section 3), and your study-buddy conversations — both what you type and what comes back (see section 3a). Interface settings, theme, and local vector memory remain on your device only.
Built, as of July 26, 2026: you can download your whole study history and you can delete it, both from the account page. The download is one file containing your account record and every question and answer — and it checks your account first, so if it cannot reach the server it tells you the file may be missing answers synced from another device rather than quietly handing you a partial one. Deleting removes the questions and answers from your account and from the device you are using. Two honest limits: deleting your study history does not delete your account (that arrives with the usage records it has to clear), and if you also study on another phone or laptop, that device keeps its own copy until you delete there too. Publishing a monitored privacy contact (section 13) remains a required gate before anyone outside the private pilot is let in.
2a. Study tables: the one place your study data is shared on purpose
Everything above is built so that one account’s study data cannot reach another’s. A study table deliberately crosses that line, and this section is the whole of what crosses. Since August 25, 2026 the crossing includes one thing that lasts: anyone at the table who has an account can choose, at the end, to keep the questions they answered. You open a table on a test you already made; up to seven other people join it by typing a five-character table code you read out to them — eight at the table, counting you. They need no account, no email, and no password.
- What everyone at the table sees: the questions from the test you opened it on — the question, its options, the correct answer and the explanation, revealed together when you choose — plus every person’s chosen first name, whether they are still there, whether they have answered yet, and, at the end, everyone’s score.
- What you give it: a first name you type for this table, and which option you pick on each question. Your real name and your email address are never sent to the table, and nobody at the table is shown anything that identifies your account.
- Table talk — a small chat beside the questions. Messages are 280 characters or fewer, carry a first name only, go to that one table and nowhere else, are never saved, and are never sent to any AI provider.
What never reaches a table: the study material you added or pasted, your study history, how many hints you have used, your study-buddy conversations, your difficulty level, your exam date, and your email address.
One thing about your account does reach it, and only when you open one. When you open a table, Nurseal sends it the internal id your account carries in our database — not your name, not your email, and nothing you have studied — and the table holds it for as long as the table exists. It is there for one reason: it is how Nurseal knows the table is yours, so that one account cannot leave several tables running at once. It is never shown to anyone at the table and is never sent to any of them, it cannot be worked out from anything a guest is shown, and it is deleted with the table. If you only ever join tables and never open one, nothing identifying your account reaches a table at all.
The room itself does not survive the room. While it is running, the table’s state — who is at it, where everyone is, the scores so far — is held in one place that exists only for that table. It is deleted when the table ends, and it deletes itself after about two hours with nobody using it. Table talk is not part of that state: a message is passed straight to the other screens and is written nowhere, which is why the bullet below can say it is never kept. A table cannot be re-opened; the code stops working, and a code that has finished is answered exactly the same way as a code that never existed. Guests leave nothing behind at all: unless a guest signs in and keeps their own answers (below), Nurseal stores no record that a guest was ever there.
Keeping the questions you answered, if you have an account and you ask for it. When the table finishes, anyone signed in is offered the questions they answered, to keep. That copy is sent to your device at the moment the table ends, so it reaches you only if you are still connected then — if your connection has dropped, the table is already gone and cannot send it again. Nothing is saved unless you press that button. If you do, those questions are copied into your own study history as an ordinary test: your copy, under your account, counting towards your difficulty level and included in what you download and in what account deletion removes. Nobody else’s answers come with it, and nothing you keep appears in anyone else’s account.
- A question is kept only if its record is complete. Each one is filed in your study history with the details that history needs — its subject, its difficulty, and the rest. If any of those did not come through with it, that question is left out, and the results screen says how many rather than quietly handing you a smaller number.
- You keep what you were shown, and nothing more. Each question arrives with the wording, the options, the correct answer and the one explanation that was on screen at the table. The hints are not included — a table never shows them to anyone.
- Table talk is never kept. The chat is not part of what you save, is not written anywhere, and goes nowhere when the table ends.
- How long each question took you is not recorded at a table. A table is paced by whoever is hosting, so the time on your screen is not time you spent thinking, and Nurseal records no number rather than a misleading one.
- Guests keep nothing unless they sign in on that device, there and then. Saving works through your own account, so while you are not signed in there is nothing to save into. If you sign in from the results screen — that page opens the sign-in tab beside itself, so the results stay open behind it — you are then offered the questions you answered, exactly as anyone signed in would be. This does not reach back into the table. The table is already gone and is never re-opened; what you are being offered is the copy your own device was sent just before it ended, which is why it reaches you only if you were still connected at that moment. That copy is held by that page alone, so closing or reloading the page loses it, and nothing is saved unless you press the button.
This changed on August 25, 2026. Until then this section said that a table put nothing into any account at all, which was true of the product as it stood. It is called out rather than quietly reworded, because “nothing is saved” is exactly the kind of sentence that is easy to leave standing after it has stopped being true. Later the same day the guest bullet above changed too: it had said a guest cannot keep anything and that making an account afterwards would not reach back. Signing in on the results screen now unlocks the copy that device had already been sent, so the first half had stopped being true — and the second half was describing the table, which really is gone, in words that read as a promise about your answers.
And two sentences here were corrected on August 26, 2026, both found by a reviewer reading this section cold. It had listed, among the things that never reach a table, anything at all that identifies your account — true of everyone who joins one, and false of whoever opens one, which the paragraph above now states plainly. And it had said without qualification that anyone signed in is offered their questions at the end, when that is true only for a device still connected at the moment the table ends. Neither was a change in what Nurseal does; both were sentences that promised more than the product could keep, and they are called out here for the same reason as the note above.
One thing worth knowing before you read a table code out. Anyone who has the code can join while the table is live, so the code is the whole of the door — say it to the people you meant to invite. Nurseal caps a table at eight people and lets you run one at a time.
3. Information sent for AI processing
When you ask Nurseal to generate, embed, explain, summarize, map, or chat about material, the relevant prompt and source content must be transmitted to the AI provider. Do not submit sensitive, confidential, patient-identifying, or unauthorized information.
Adding a file, as built (July 31, 2026): when you add a PDF or a text file, that file is read inside your browser and never leaves your device — it is not uploaded to Nurseal, and it is not sent to Google. What comes out of it is the plain text, which appears in the box on screen where you can read and edit it before you build anything. From that point on it is treated exactly as if you had pasted it, and only what is in that box is ever sent anywhere. Nurseal does not keep the file, its name, or its page count; the text that came out of it is kept in this browser as section 3b describes.
The real path, as built (July 24, 2026): when you ask for a practice test, the study material you pasted and your test settings travel from your browser to Nurseal's server (a Cloudflare Worker) and from there to Google's Gemini API, using an AI key that Seal Studios owns and pays for. Nurseal's server handles your material only long enough to make that one request and does not store it. What Nurseal does keep is a per-request usage record — which account asked, the operation, AI model, token counts, computed cost, success or failure, and timestamps — because spending caps and honest billing require it. This record never contains your study material, your prompt, or your answers. The generated test itself may be held server-side for up to 15 minutes, solely so an accidental refresh or double-click returns the same test instead of billing twice, and is then purged. The questions produced from your material, and your answers to them, are saved to your account as described in section 2 — your study material itself is not. Google's handling of submitted content is governed by Google's own terms (section 5). An optional connect-your-own-provider path may be offered later; if it ships, this notice will describe it before it is available.
3a. The study buddy
Available since August 2026. On the screen you see after a test, and on your history page, each question you have already answered carries a study buddy you can ask about it. It is entirely optional — nothing is sent unless you type a question and press Ask. It does not appear on a question you have not answered yet, and it does not appear when you are signed out.
The real path, as built. When you send a message, three things travel to Nurseal’s server (the same Cloudflare Worker as section 3) and on to Google’s Gemini API: what you typed, the earlier messages in that same conversation (the most recent twenty), and context about that one question. The context is not taken from your browser — Nurseal’s server reads it from your account: the question, its options, the correct answer, the explanations, the teaching note, which option you chose, and counts of how many separate sittings that question and others on its topic have caught you. Nothing about any other account is ever in it, and the database itself is what decides you may see that question.
Sent to be answered, and not kept. Those three things are transmitted every time you press Ask — a conversation has no memory at the AI provider, so the earlier messages have to travel again with each new one. Nurseal’s server holds them only for the length of that one request and stores none of them. The conversation itself is saved in this browser only: it is not synced, it is not readable by the operator, and it is not in the file you download from “Download my records” — that file promises everything Nurseal holds about you, and Nurseal holds no conversation. Two plain consequences: clearing your browser data clears your conversations, and a conversation you had on your laptop is not on your phone. Deleting your study history and deleting your whole account both clear them from the device you do it on, and both say how many were removed.
What Nurseal does keep is one usage record per message, exactly like the one in section 3: which account asked, that the operation was a study-buddy message, the AI model, token counts, computed cost, success or failure, timestamps, and a reference code for the request. It never contains your message or the answer you got back.
About that reference code, because it is the one item here that deserves explaining. It is a fixed-length scramble — a one-way hash — computed from your account, which question you asked about, and the text of the message, and it exists for one reason: if a tap registers twice, the two requests produce the same code and you are charged once instead of twice. It cannot be turned back into your message. It is deliberately computed from as little as possible — not from the earlier messages in the conversation, and not from any answer you were given — so that the record kept for billing carries the smallest fingerprint that still does its job.
A message that fails or comes back empty is recorded as a failure and does not count against your daily allowance.
What the buddy is, and is not. It answers about one question you have already answered, using that question’s own explanations — the same AI-generated ones already on your screen, which no clinician has reviewed. Its own answer is AI-generated too and can be wrong; every answer carries a line telling you to check it against your own notes or your instructor, and that line is not a formality. It is a study aid, not clinical advice. Do not type sensitive, confidential, or patient-identifying information into it — the same rule as section 3, and it applies to a chat box more than anywhere else, because a chat box invites you to write freely.
3b. Study material kept on this device
Kept in this browser only. When you build a test, Nurseal keeps a copy of the text and test settings in this browser so that test can offer New test, same material without asking you to paste or add the material again. It is not kept on Nurseal’s servers and is not part of your account. It can stay in this browser until you delete your study history or account on this device or clear this site’s browser data; the browser can also remove its stored data on its own, and Safari may do that after roughly seven days away as section 2 explains.
Two plain consequences: clearing your browser data clears this material, and a test built from material on your laptop offers the button on your laptop only, not on your phone. On a shared device, each account signed in on this device has its own separate copy; a second person signing in cannot see yours.
That material is not included in “Download my records”. That file promises everything Nurseal holds about you in your account, and Nurseal holds no server or account copy of this material to hand back. Deleting your study history or your whole account clears it from the device where you perform the deletion, and the result says how many tests had material removed.
This changed on September 9, 2026. Before then Nurseal kept no copy after you left the build page, so making another test from the same material meant adding it again. It is called out rather than quietly reworded because the earlier promise that no copy remained stopped being true when this on-device copy was added.
3c. Work you do before signing in
Kept in this browser only, and not in any account. You can take a test without signing in. That work is written to a separate store in this browser, and none of it is synced anywhere while you are signed out — syncing is what an account is for.
The first time you sign in on this device, Nurseal offers to move that work into your account. If you accept, it is copied across and the signed out store is emptied. If you decline, it stays in this browser until you delete your study history, delete your account, or clear this site’s browser data.
On a shared device this is worth knowing before you walk away. Until somebody claims it, whoever signs in on this device next is the one offered it. Once an account has claimed it, it is locked to that account and anyone else signing in is refused rather than shown your work.
4. AI key handling and billing
Genaya's private prototype may use a Gemini API key entered directly in the browser. The prototype is designed to store that key only as explicitly disclosed in onboarding and to send it only to Google's API. Google advises against exposing API keys client-side in production, so this browser-direct behavior is not used for the hosted service.
The hosted service uses a dedicated, revocable Gemini key owned by Seal Studios, stored as a server-side secret. It is never sent to your browser, never placed in URLs or logs, and never committed to source control. You do not create, supply, or pay for an AI key today. If an optional customer-funded provider connection (for example via OpenRouter) is offered later, its credential custody, disconnect/delete controls, and billing responsibility will be security-reviewed and described here before launch.
5. Google service distinction
Under Google's Gemini API terms effective March 23, 2026, unpaid-service prompts and responses may be used to provide, improve, and develop Google products, and human reviewers may process them. Google instructs users not to submit sensitive, confidential, or personal information to unpaid services. For Paid Services, Google says prompts and responses are not used to improve its products, though limited safety and security logging applies.
Nurseal's hosted AI requests are made under Seal Studios' actively billed (paid-tier) Google project, and are governed by the Gemini API terms and Google's privacy policy as they stand at the time of the request. Nurseal does not describe Google usage as included or free: the operator pays Google, and what you buy from Nurseal is credits (Terms, section 9).
6. Optional integrations
Payments have left this list. Stripe is a processor Nurseal uses on every purchase, not an integration you choose to connect, so it is described in full in section 7c rather than deferred to a future notice. Nurseal offers no optional integrations today — there is nothing here for you to connect, and section 7 lists the complete set of outside companies your information reaches. If one is ever offered, Nurseal will request only the access that feature needs, and the order is fixed: this notice and a consent screen shown at the moment you would connect it will both name the integration, what it reaches, what it is used for, how long it is kept, and how to disconnect and delete it — before it ships, not after. Genaya's general calendar and personal/business systems are separate from Nurseal.
7. Technical and transaction information
Running Nurseal means IP address, browser and device information, request timing, sign-in data, usage counts, errors, payment status, and abuse and security signals pass through the companies that host it. Nurseal’s own server handles your study material only long enough to send the one request you asked for (section 3) and does not store it.
Here is every outside company Nurseal uses, and what each one gets. This list is the whole set — it is derived from the addresses Nurseal’s code actually calls, not from memory, and nothing else is contacted on your behalf.
- Cloudflare — hosts the site and Nurseal’s server. Sees your IP address, browser information, and the timing and status of every request, as any web host does. It does not receive your study material as a stored record; it carries the request that contains it.
- Supabase — the account system and the database. Holds your email address, your sign-in sessions, your account record and consent answers, your study history, your credit balance and purchase records, your feedback, and the per-request usage ledger described above.
- SMTP2GO — delivers Nurseal’s email: the sign-in email, and the dormancy warning in section 10a. It gets your email address and the contents of those messages. It is not used for marketing, and Nurseal sends you no marketing email.
- Google (Gemini API) — generates the questions and answers the study buddy. Gets exactly what sections 3 and 3a describe. Nurseal attaches nothing that identifies you — your name, your email address and your account number are not part of that request. What Nurseal cannot control is what is inside the material you paste, which is one of the reasons section 3 asks you not to submit patient-identifying or confidential information.
- Stripe — takes payments. Gets what section 7c describes, which also sets out exactly how your card details are handled: they are entered into Stripe's own form, and section 7c states what Nurseal does and does not see.
- Telegram — used once a day to tell the operator how many unread feedback reports are waiting. It receives a number. It does not receive your report, your email address, or anything identifying you, and the database function behind that message is written so that it cannot return a report’s text at all.
What is written into logs. Nurseal does not write your study material, your questions, your answers, your study-buddy messages, or the AI’s replies into any log. Sign-in tokens and the AI key are excluded the same way. What ordinary operational logging can contain is the shape of a request — when, which route, how long, whether it succeeded, and an error message when it did not.
How long each of them keeps it. The records Nurseal itself controls are covered in section 11, and deleting your account removes them (section 10a). The retention periods of the companies above are set by those companies under their own published policies, linked beside each name, and the operator does not control them and cannot state a period on their behalf — Stripe in particular keeps its own record of a payment for as long as its legal obligations require, which is why section 10a explains that deleting your account does not erase the payment from Stripe.
7c. Paying for credits, and Stripe
Nurseal uses Stripe to take payments. Stripe is a processor acting for Nurseal, and it is the newest of the outside companies that handle anything of yours. This section exists because adding one is the kind of change that ought to be announced rather than discovered.
The real path, as built. When you press a buy button, Nurseal’s server creates a checkout session with Stripe and sends you to a page hosted by Stripe. You type your card details there, on Stripe’s page, into Stripe’s form. Nurseal never sees, receives, or stores your card number, its expiry, or its security code — not for a moment, and not in a form we then discard. There is no field on any Nurseal page that a card number goes into. When the payment succeeds Stripe tells our server, over a signed message we check before believing it, and your credits are added.
What Nurseal tells Stripe. Three things and no more: the email address on your Nurseal account (so the payment can be attached to you and so Stripe can reach you about it), which pack you are buying and what it costs, and an internal reference to your account — the same account identifier the database uses, which means nothing outside Nurseal. Your study material, your questions, your answers, your difficulty level, and your exam date are not sent to Stripe and never have been.
What Stripe tells Nurseal, and what we keep. Stripe tells us that a payment succeeded, which pack it was for, how much was collected, in which currency, and its own reference for the event. We keep exactly that, as your purchase record: the date, the pack, the number of credits, the amount, the currency, and Stripe’s reference. Your account page shows you the date, what you bought, and what you paid, under “Purchases”. Stripe’s reference is kept but not displayed — it is an internal identifier rather than something you would use, and we will quote it to you if you ever need it to trace a payment. We do not receive and do not store your card number, any part of it, your billing address, or the name on the card — if you want those, they are in your Stripe receipt and on your card statement, not here.
Stripe also collects things directly from you that never pass through us — your card details, and the technical and fraud-prevention information any payment processor gathers about the device paying. Stripe is the controller of that, under its own privacy policy, linked above. We cannot see it and cannot delete it for you.
Your card statement should read NURSEAL. That is the descriptor we submit to Stripe; banks abbreviate and reformat descriptors in their own ways, so yours may show it differently. Said here because an unfamiliar name on a statement is the ordinary reason someone disputes a charge they actually made.
About receipts, stated plainly because it would be easier to leave vague. Your purchase record on your account page is the receipt Nurseal is responsible for, and it is written at the moment the payment lands. Nurseal does not promise you an email receipt, because whether one is sent is a setting inside Stripe rather than something this product controls or can verify. If one arrives, it comes from Stripe. If none arrives, nothing has gone wrong with your purchase — check your account page, which is the record either way.
Refunds. A full refund is yours for the asking while both of two things are true: it is within 14 days of your purchase, and you have spent fewer than 50 of the credits it gave you. Your account page and the credits page both show whether that is still true for you, computed from the same record, so they cannot tell you different things. Ask through the Feedback button on any page while signed in — it reaches the person who operates Nurseal, with your account attached, so you do not need an order number. Outside that window your credits do not expire, and you can still ask.
Tax. No tax is added at checkout; the price shown is the amount charged. Nothing here is tax advice about what you may owe.
If you delete your account, your purchase records are deleted with it, along with your credits. They are not kept behind under another name. Stripe keeps its own record of the payment independently, for as long as its obligations require — that record is not ours to delete, and it is the one that matters for a chargeback or a tax question. This is stated in section 10a as well, because that is where someone about to delete an account will actually be reading.
7a. Feedback and bug reports
While you are signed in, every study page and this account page carry a Feedback button. It is entirely optional — nothing is sent unless you write something and press Send. (Signed out, the button is not shown, because a report has to be attached to an account.)
When you send one, Nurseal stores only these: the message you typed, the page you were on when you opened the box (the page address only, without anything after the “?”), the app version, the date and time it was sent, an internal reference number, and your account. Nothing else is collected — no screenshot, no copy of the page, no console or error capture, and none of your study material, questions, or answers.
While you are typing, an unsent draft is kept in this browser so a failed send or an accidental reload does not lose your words. It is deleted as soon as the report sends.
Please note that a bug report contains whatever you choose to type. If you paste part of your notes or a question into it to explain the problem, that text is stored with the report. Send only as much as you need to.
Reports are readable by the operator of Nurseal, together with the email address on your account, so that a reply is possible. They are not shared with anyone else and are not used to train anything. There is a limit of 20 reports per account in any 24 hours.
Reports you have sent are included in the file you download from “Download my records”, exactly as they were stored (blank space at the very start and end of a message is trimmed before sending). A report is not part of your study history, so deleting your study history does not delete them. Deleting your whole account does. To have one specific report removed sooner, ask Sami directly — he operates Nurseal and can remove it.
7b. Your exam date
On your account page you can, if you want to, tell Nurseal the date you sit the NCLEX. It is entirely optional — the whole product works without it, and nothing asks you for it anywhere else.
It is used for exactly one thing: scheduling your reviews. With a date, the gaps between reviews get shorter as the date approaches, and nothing is scheduled for after it. Without one, reviews follow a fixed schedule instead. It is not used for reminders, is not sent to the AI provider with your questions, and is not shared with anyone.
Nurseal stores the date only — not your school, your programme, your state, or your board. It is kept with your account, it is included in the file you download from “Download my records”, and deleting your whole account deletes it. You can change it or remove it at any time from the same place you set it, using Remove it; removing it puts your reviews back on the fixed schedule. Note that it is part of your account rather than your study history, so deleting your study history does not remove it.
7d. The one question we ask you
Once — and only once — after you have answered at least one practice question, a card in the Study Room asks you where your school deadlines live right now, and offers five answers: a phone calendar, a paper planner, Canvas or your school portal, in your head, or somewhere else. There is a No thanks button beside them and it is a real answer, not a way of postponing the question.
What it is for, stated plainly: it is research, and it is for us. We are deciding whether to build a place in Nurseal for your school deadlines, and we would rather ask you than guess. Nothing reads your answer to change what you see — it does not affect your account, your credits, your questions, your difficulty level, or anything else about how Nurseal behaves for you.
Nurseal stores which of the six buttons you pressed, and nothing else. Not the name of your school, not your programme, not any deadline. If you press No thanks, that is what gets stored, so that we know not to ask again on your other devices.
It is kept with your account. It is included in the file you download from “Download my records”, and deleting your whole account deletes it. Like your exam date it is part of your account rather than your study history, so deleting your study history does not remove it. It is not sent to the AI provider, not sent to Stripe, and not shared with anyone.
8. Cookies, analytics, and tracking
Nurseal does not use advertising cookies or cross-site behavioral tracking, and runs no analytics product at all — no page-view counter, no session recorder, no third-party script that watches what you do. Nothing on any Nurseal page collects information about you across other websites, because nothing on any Nurseal page belongs to a company that operates on other websites.
What is stored in your browser is the product itself, not tracking: your sign-in session, your study history (section 2), your settings, your study-buddy conversations (section 3a), your study material (section 3b), the record of what a test was built from that lets it offer New test, same material (section 3b), any unsent feedback draft (section 7a), the address you asked for a sign-in link at, a marker from a purchase you started so the page can tell you when your credits land (section 7c), and, if you have used Nurseal signed out on this device, the signed out copy of that work until you claim it or delete it (section 3c). It is there so the app works and so a test survives a dropped connection — it is not read by anyone else, and it leaves your browser only where this notice says it does: your study history to your account (section 2), your answers to a study table when you join one (section 2a), your study material and your study-buddy messages to the AI provider (sections 3 and 3a), a feedback report when you send one (section 7a), and your sign-in with every request you make to your own account (section 7). Clearing it signs you out and removes the local copy of your history.
Browser privacy signals. Nurseal does not sell your information, and does not share it for advertising or any other cross-context behavioural purpose, so there is nothing for a Global Privacy Control or “Do Not Track” signal to switch off — the behaviour those signals ask for is what Nurseal already does. A study table is the one place your study data is shared on purpose (section 2a); that is a room you open or join, not advertising, and nothing reaches a table unless you join one. If analytics, cookies, or similar technology is ever added, this notice and any required consent controls will be updated before collection begins, and this paragraph will say what changed.
9. Sensitive and health-related information
Clinical-study material and performance history may be sensitive wherever they are held — on your device or in your account. Nurseal does not ask you to enter patient data, and section 3 asks you not to. The consent you are asked for, as built: the account page asks whether Nurseal may count how you use it for its own product telemetry, records your answer as a dated receipt against the version of the wording you were shown, and lets you withdraw it in the same place. Those receipts are append-only — a withdrawal is a new receipt, never an edit to an old one — and they are in the file you download (section 10). What that answer actually controls, stated because it is easy to overclaim: one thing — whether your account appears in the day-by-day usage series in the operator’s cost summary. It does not stop the per-request record in section 3 being written, because that record is what enforces the spending caps and cannot be optional. And it does not put those records out of the operator’s reach: the same narrow owner door described in section 2 can read the ledger itself. Saying no changes what is reported about you, not what is kept or who may read it. Widening what is collected still requires the review described below, before it is built.
An earlier draft of this notice required a fresh legal and privacy review before adding cloud sync or central storage for these categories. That review is what produced the July 24, 2026 change described in section 2, and it set the limits that change ships under: only what section 2 lists is synced, never your study material or chat text; the records are locked to your account at the database layer, subject to the one narrow operator read described in section 2; answers are append-only; and export and deletion controls must exist before this product is offered to anyone. Those export and deletion controls shipped on July 26, 2026, so that condition is now met rather than pending. Any further widening of what is stored requires the same review again, before it is built.
10. Your choices and requests
Available now: downloading the record Nurseal holds of your studying, deleting your study history, and deleting your whole account — all from the account page, described in sections 2 and 10a. The file holds your account record (your profile, your entitlement, your exam date from section 7b and the one answer from section 7d), your consent receipts, your feedback and bug reports, and your whole study history. What is not in it, and why: your study-buddy conversations, because Nurseal does not keep them — they are sent to be answered and not retained, so there is nothing on our side to hand back (section 3a); the study material kept only in this browser, because Nurseal has no server or account copy to put in the file (section 3b); your purchase records and your credit balance, which your account page already shows you and section 7c describes; the per-request usage ledger described in section 3, which is Nurseal’s accounting of what it spent rather than a record of what you studied; and the counter behind your daily allowance, which is a running total for today and nothing else. The last three are held about you, so the request route below reaches them. Still planned: re-importing a file you downloaded.
Asking for anything the buttons do not cover. Email hello@seal-studios.com, or use the Feedback button while signed in, and say what you want. That covers a request to see what is held about you, to correct something that is wrong, to delete something, to get a copy in a portable form, or to object to a use — whether the information sits with the operator or with one of the companies in section 7. The operator will answer within 30 days. If a request cannot be honoured, you will be told why rather than simply refused. Making a request costs nothing and Nurseal will not treat you differently for having made one.
What exists today: from the account page you can download the one file described above, and you can delete your study history. Deleting it is a single all-or-nothing action; there is deliberately no control for silently removing one individual answer, because a history you can edit is one your difficulty settings would be wrong about. What is still not built: re-importing a downloaded file — a study history you could edit and upload again would have the same problem as one you could edit in place.
10a. Deleting your whole account
Available since August 2026, from the account page. Deleting your account removes your sign-in, your account record (profile and entitlement), your consent answers, your entire study history — every question, every answer, and every correction you made to your difficulty level — every feedback or bug report you have sent (section 7a), and your credits and your purchase records (section 7c), in one action, and clears the device you did it from — including any study-buddy conversations stored in that browser (section 3a) and the study material kept with your tests (section 3b), the only places Nurseal ever kept those local copies. It cannot be undone, and a new account starts from nothing.
Your purchase records go with it, deliberately, and that decision has a reason worth reading before you delete. Nurseal does not keep a shadow copy of what you bought after you have asked to be erased — keeping personal records of a person who just asked to be forgotten, in order to look thorough, is the opposite of what deletion is for. It is safe to do because Stripe holds the authoritative record of the payment independently of us (section 7c), for as long as its own obligations require. So the money is not being erased from the world; our copy of it is. If you want your own copy of what you paid, save your card statement or your Stripe receipt before you delete — the download described in section 10 does not include your purchase records — afterwards we genuinely cannot produce it, and that is the intended behaviour rather than a limitation.
What can survive account deletion. Study material and Study Buddy conversations saved in a browser on another device are not reached when you delete from here; they can remain on that other device until you remove them there as sections 3a and 3b describe, or until the browser removes its own stored data. Nurseal also keeps an internal ledger of the AI requests it paid for — when a test was built, what it cost, how many questions, at what difficulty. When you delete your account, those rows are kept but your identity is removed from them at the database layer, permanently and automatically. They are bookkeeping: they never contain your study material, your questions, or your answers, and after deletion they no longer say who they belonged to. They are kept because deleting them would falsify the service’s own accounting — the bills it reconciles against its AI provider would stop adding up.
Dormant accounts. Your account is kept for as long as you use it. After 24 months without a sign-in it is deleted, including any credits you have not spent — and with everything else that implies above — and one warning email is sent about 30 days beforehand to the address you sign in with. Signing in at any point keeps the account and resets the clock; that is the only step, and the warning email itself is a sign-in email.
11. Security and retention
No service can promise perfect security. Nurseal will minimize collection, restrict access, use encrypted transport, and exclude credentials and submitted study content from logs.
Retention, as built: the study history in section 2 is kept for as long as your account exists, because its whole purpose is to still be there next semester. Deleting your account removes it (section 10a), and accounts dormant for 24 months are deleted after a warning (section 10a). The study material you add or paste is never retained on Nurseal’s servers — and a file you add is never even received, because it is read in your browser (section 3). A copy of its extracted or pasted text is kept in this browser with the test as section 3b describes, while generated tests held for the 15-minute duplicate-request window are purged from the server automatically. Study-buddy messages pass through Nurseal to be answered and are not retained on the server; the conversation itself is kept in your browser for as long as you keep it (section 3a). The per-request usage ledger described in sections 3 and 10a is kept indefinitely as accounting. While your account exists those rows are linked to it; deleting your account removes that link permanently, and what remains is bookkeeping that no longer says whose it was. Your purchase records (section 7c) are kept for as long as your account exists and are deleted with it; Stripe’s own record of the same payment is kept on Stripe’s schedule and is outside our control. Nurseal keeps no credential store and no request log of its own. The operational logging described in section 7 is not retained: Nurseal’s server has no log retention configured, so that output exists only while someone is watching it live. Cloudflare’s own request records and Supabase’s record of your sign-ins are kept on those companies’ schedules, linked in section 7, and the operator does not control them.
12. Children and age eligibility
Nurseal's AI features are for adults 18 and older. The service is not directed to children and should not knowingly collect personal information from anyone under 18.
13. Changes and contact
Material changes will be dated and communicated through the product or another reasonable channel before they take effect where required.
Contact. Elpidio Samuel Poblano Vallejo, doing business as Seal Studios — hello@seal-studios.com, or PO Box 1714, Indio, CA 92202-1714, United States. That mailbox is monitored and is the privacy contact named in section 1.