Privacy
What is held about you, where it lives, and who can see it.
- Who runs this. One named operator, on one server on Cloudflare's network, for a small invite-only group of Accelerated BSN students. Send questions to that operator directly.
- What is stored. Your account (email, an Argon2id hash of your MyNurse password, display name, optional phone, optional avatar photo); Canvas courses, assignments, due dates, submission states and scores; the text of Canvas course pages and the questions from quizzes you have finished; course files (your instructors' slides, handouts and syllabi, fetched in your own signed-in Canvas tab and kept for your account only); textbook PDFs on your shelf (free, openly licensed texts and any you upload yourself) and the highlights and notes you make in them or import from your own VitalSource notebook; study guides from a previous cohort, if any were added to your account; calendar events from Canvas and, where one was set up for you, your class schedule; email headers and message bodies from your Canvas inbox and, if connected, your school email; ATI results you captured; contacts derived from mail headers and Canvas rosters; group membership, project links and chat messages you wrote; practice tests and your answers; and server logs (timestamp, path, status, truncated user agent, hashed IP — never query strings, never bodies). Signed in, Your material lists what is stored for your account, kind by kind, with where it came from and the limits on it.
- What is never stored. Your school password, your Canvas password, your ATI password. There is no field for any of them. Never type one here.
- Where it lives. With Cloudflare, the hosting provider: one SQLite database file on a single Cloudflare Containers server, copied continuously to a private Cloudflare R2 storage bucket, with your files (course documents, textbooks, your photo) in a second private R2 bucket. R2 encrypts everything it stores at rest (AES-256); the server's own disk is temporary and is wiped every time it restarts. So Cloudflare does hold your data at rest, under its terms as the host, and it also carries the encrypted connection from your browser and sees request metadata (hostname, path, timing) as any CDN does.
- Who can see it. You. Other users see only what you explicitly share, which never includes your mail and never includes your grades unless you turn that on and confirm it. The operator has filesystem access to the server and could read the database. Treat it accordingly.
- What leaves the server. Nothing, for practice tests and summaries, while the paid tier in Settings is off — it is off per user until you turn it on. Turn it on and the text of that request goes to Anthropic's API under their terms; each answer says when it did.
- FERPA. FERPA governs your school, not this tool, and nothing here is a record you do not already have access to. The same shape applies anyway: default-deny sharing, explicit opt-in for grades, no third-party disclosure, and deletion on request.
- Retention and deletion. Synced data refreshes continuously and can be rebuilt from the source. Settings → Delete my account revokes every session and connection immediately, hard-deletes your data within 24 hours, and ages out of backups within 30 days. Chat messages you wrote are replaced with "message deleted" so other people's threads still read.
- Cookies. Two, both first-party, both strictly necessary: a session cookie and a CSRF token. No analytics, no trackers, no third-party scripts — so there is no consent banner to click.
- Changes and breach. Expect 7 days' in-app notice before a material change. If the database is exposed, you will be told within 72 hours, with what was in it.
Keep your own copy of anything you cannot lose: the database is copied continuously to R2 and snapshotted nightly, but every copy is in the same Cloudflare account — tracked on the Health page.