Privacy Notice
Effective: September 27, 2026 · Version 6
SRNA Study Tool is an independent educational study resource. It is not operated by, affiliated with, sponsored by, or endorsed by any university, nursing program, faculty member, certification body, or licensing organization.
Guest use
Most study features can be used without an account. Guest study progress is stored locally in the browser, and SRNA Study Tool does not intentionally submit guest question-performance data to the calibration database.
To estimate current unauthenticated use without building a persistent guest profile, the application may create a random session identifier stored only in browser session storage and send a limited heartbeat to Supabase. The application heartbeat contains the random session identifier and server timestamps only. It is not intentionally linked to an email address, account identifier, study answers, page history, browser user-agent string, or a persistent cross-session identifier. Guest-session heartbeat records are deleted after approximately 24 hours. The resulting admin metric is an approximate count of active browser sessions, not a verified count of individual people. Supabase and network providers may independently process ordinary connection metadata under their own terms and privacy practices.
Account and Adaptive Mode data
An account is required for Adaptive Mode and may also be used for cross-device synchronization. Account authentication is provided through Supabase and requires an email address and authentication credentials. Passwords are handled by the authentication provider and are not stored in the study application's question-performance records.
For signed-in users, SRNA Study Tool may process question identifiers, whether a first attempt was correct, optional response time, session mode, study progress, synchronization metadata, and a private account identifier. The private account identifier is used to associate an account with its own progress and to prevent the same account from contributing multiple first-attempt observations for the same question.
Testing and calibration
Question-performance information may be used for testing, validation, question-quality improvement, and Adaptive Mode calibration. Population calibration results are de-identified and aggregated. Calibration rows are exposed to signed-in application clients only after at least 25 unique account contributors have provided an eligible first-attempt observation for that question. The aggregate calibration dataset does not include names, email addresses, passwords, or device identity.
Data collected and purposes
- Email and authentication data: account creation, sign-in, account security, password recovery, and session management.
- Study progress: resume sessions, show performance history, Smart Review, Due Review, backups, and cross-device synchronization.
- First-attempt performance: prevent duplicate statistical contributions, test question quality, and improve Adaptive Mode calibration.
- Technical synchronization metadata: maintain reliable cloud synchronization, version history, and device-management features.
- Ephemeral guest-session metric: estimate active guest usage using a random per-tab session identifier and heartbeat timestamps retained for approximately 24 hours.
- Account-administration metadata: permit the operator to see account email, account creation/last-sign-in timestamps, active or suspended access status, whether the current legal version was accepted, and whether the account has used Adaptive Mode. These fields are used for account administration, compliance, and support, not advertising or learner profiling.
- Question reports: investigate content issues using the question context, issue category, free-text comment, build, and sanitized page path. Submission requires an authenticated active account, but the report inbox does not store the submitter's account identifier or email address.
SRNA Study Tool does not intentionally collect sensitive demographic, health, financial, precise-geolocation, or government-identification information for Adaptive Mode calibration.
Question reports
If you use the Report Question feature, the report may include the question identifier and study context needed to investigate the issue, including the bank, set, question number, topic, question stem, answer choices, keyed and selected answer, explanation, source/page reference, issue category, your free-text comment, the application build, and the page path from which the report was submitted. Submission requires an authenticated active account, but the stored report is intentionally not linked to the submitter's account identifier or email address and does not include the browser user-agent string, URL query parameters, or URL fragment. Reports are stored in a private Supabase table and are available to the restricted operator-admin workflow for review and status updates. Supabase and network providers may independently process ordinary connection metadata under their own terms and privacy practices. Do not include sensitive personal, health, financial, patient, educational-record, or confidential information in a question report.
Privacy requests and operator administration
Signed-in users may submit privacy requests from the account panel for access, correction, deletion, appeal of a prior privacy-request decision, or another privacy matter. The request is stored with the account identifier, request type, optional details, status, and timestamps so the request can be tracked and handled. Do not include unnecessary sensitive information in the request details.
A restricted operator-admin account may view account-management metadata needed to operate the service, including account email address, account creation and last-sign-in timestamps, active or suspended access status, whether the current legal version has been accepted, and whether the account has contributed at least one eligible first-attempt response in Adaptive Mode. The operator-admin may suspend or re-grant cloud and Adaptive Mode access, manage privacy-request and anonymous question-report workflows, view aggregate system/CAT counts, export legal-assent evidence, and run defined retention cleanup. The browser admin panel is not designed to expose other users' synchronized study payloads, passwords, raw first-attempt CAT contribution rows, or the identity of a question-report submitter.
Service providers
SRNA Study Tool uses service providers for limited operational purposes: Supabase for authentication, database storage, synchronization, account-management functions, privacy requests, question reports, and Adaptive Mode calibration infrastructure; and GitHub Pages for website hosting. These providers may process technical information necessary to provide their services under their own terms and privacy practices. SRNA Study Tool does not authorize these providers to use SRNA Study Tool data for SRNA Study Tool targeted advertising or sale.
Sale, advertising, and profiling
SRNA Study Tool does not sell personal data and does not use personal data for targeted advertising. Adaptive question selection is a study feature and is not used to make decisions about education enrollment, employment, insurance, lending, health care, or other legally significant eligibility decisions.
Retention and deletion
Local guest progress remains in the browser until the user clears it or imports/replaces it. Ephemeral guest-session heartbeat records are retained for approximately 24 hours. The authentication account, current cloud study state, device records, privacy requests, and raw first-attempt calibration contributions are maintained only for their stated operational purposes and are removed with account deletion where the database relationship is account-linked. Cloud restore/version history is subject to a target 90-day retention period. Ephemeral guest-session heartbeat records are limited to approximately 24 hours. Completed or denied privacy requests are subject to periodic review and a target maximum of three years when continued retention is needed to document request handling.
Resolved question reports are subject to a target maximum retention period of two years unless a report remains needed for an active quality, security, dispute, or legal matter.
For contract evidence and legal/compliance defense, SRNA Study Tool retains a minimal pseudonymous legal-assent record for up to five years from the server-recorded acceptance. That record may include the account UUID, a one-way SHA-256 hash of the account email at the time of acceptance, the Terms and Privacy versions, cryptographic hashes of those documents, the adult acknowledgement, and acceptance/recording timestamps. The retained legal-assent record does not include the plaintext email, password, study answers, synchronized study payload, or raw CAT contribution data. Account deletion does not erase an unexpired legal-assent evidence record.
De-identified aggregate calibration statistics may be retained after account deletion because the deleted account's raw contribution is removed and affected item statistics are recalculated from remaining contributions. Legal document snapshots and their hash manifests are retained as an immutable version archive.
Operator account administration
The operator has a restricted administrator panel for legitimate service administration. It can display account-management metadata, aggregate guest/CAT usage statistics, privacy-request status, anonymous question-report content/status, and legal-assent records; suspend or restore an account's cloud/Adaptive Mode access; and permanently delete a non-admin account. The administrator panel is intentionally not designed to expose another user's password, synchronized study payload, individual answer history, or raw CAT contribution rows. Administrative actions are limited to operating, securing, supporting, and complying with obligations for the service.
Your controls and privacy requests
Signed-in users can download a backup of study progress, manage synchronized devices, restore prior progress, sign out, and use Delete account & data for self-service deletion of the authentication account and active account-linked cloud study data. The limited pseudonymous legal-assent evidence described under Retention and deletion is retained until its defined retention date.
The account panel also provides a private Privacy request form for access, correction, deletion, appeal of a prior privacy-request decision, or another privacy matter. Requests may require reasonable authentication or verification before account-linked information is disclosed or changed. If a request is denied and applicable law provides an appeal right, choose Appeal decision and identify the prior request or decision in the details.
Privacy-request appeals
If a privacy request is denied, a signed-in user may submit an appeal from the same Privacy & Account section by choosing “Appeal decision” and identifying the prior request. Appeals will be reviewed separately from the original request to the extent reasonably practicable. If applicable law provides a right to contact a regulator or attorney general after an unsuccessful appeal, the response to the appeal should identify that option.
Age
SRNA Study Tool is intended for adult learners. You must be at least 18 years old to create an account or use Adaptive Mode. The service is not directed to children under 13.
Security
SRNA Study Tool uses authenticated access controls, row-level security where applicable, restricted database functions, a private least-privilege operator-admin role, versioned legal records, and data minimization. No internet service can guarantee absolute security.
FERPA and educational records
SRNA Study Tool is not operated by or on behalf of a school, university, nursing program, or other educational institution and is not intended to receive education records from an educational institution. Users should not enter grades, student identification numbers, disciplinary records, accommodations, or other nonpublic education-record information into question reports, privacy-request details, or other free-text fields. If an educational institution later adopts the tool, directs its use, or asks the operator to process education records on the institution's behalf, that deployment must receive a separate FERPA and institutional-contract review before such records are processed.
HIPAA and patient information
SRNA Study Tool is not designed to receive or store protected health information on behalf of a health care provider or other HIPAA covered entity. Do not enter patient names, medical-record numbers, dates of birth, clinical case details that identify a patient, or other protected or confidential patient information into question reports, privacy-request details, or other free-text fields. A separate legal and security review would be required before the tool could be used to process protected health information on behalf of a covered entity.
Educational and research status
Performance data is collected for operation, testing, validation, question-quality improvement, and Adaptive Mode calibration. The service does not represent this operational collection as university-sponsored research. Whether a future activity is human-subject research does not depend only on whether results are published. Before using identifiable or account-linked learner data in a systematic investigation designed to develop or contribute to generalizable knowledge, the operator should obtain an appropriate institutional or ethics determination and any required review before that research use begins.
Data minimization and purpose limits
SRNA Study Tool limits personal-data collection to information reasonably necessary for authentication, synchronization, account security and administration, study functionality, short-lived guest-session counting, testing, validation, question-quality improvement, Adaptive Mode calibration, and privacy-request handling. Personal data is not intentionally repurposed for unrelated advertising or sale.
Changes to this notice
This notice may be updated when data practices or features change. Material changes will be identified by a new effective date. When a material change affects account-based processing or the legal terms governing use, SRNA Study Tool may require renewed acknowledgement before continued use. Materially different uses of personal data will be disclosed before the new use begins and, where legally required, appropriate consent will be obtained.
This notice describes the current technical design and is not a substitute for advice from a licensed attorney regarding a particular deployment or jurisdiction.