Privacy Notice
Last updated: 24 August 2026
This notice explains what NurseNote collects, why it is used, who it may be shared with, how long it is kept and the choices available to you.
1. Controller and contact
NurseNote is operated by Ian Mayor, trading as NurseNote in the United Kingdom. For privacy questions, access requests or deletion requests, email nursenotesupport@gmail.com.
2. The new NurseNote Assess journey
NurseNote Assess is a formative practice product for entirely fictional scenarios. The three current assessments are rule-based; they do not send the learner’s note to a large language model.
- The note is transmitted securely to a Base44 backend function for the selected assessment.
- NurseNote does not write submitted note text to an entity, analytics event or product-performance log. While you are writing, an unfinished draft may be held in session storage in the current browser tab so an error or refresh does not erase it. The draft is removed after a successful assessment and normally disappears when that tab is closed.
- For signed-in learners, NurseNote may retain the scenario, rubric version, attempt number, completion time, overall score and six domain scores.
- For guests, equivalent score metadata may be stored on the learner’s own device.
- A random browser identifier or hashed network identifier is used to enforce a fair daily assessment allowance.
Do not enter a real patient’s information. Use only the fictional facts displayed in the scenario.
3. Other data NurseNote may collect
- Account data: name, email, account role and service preferences.
- Assessment outcome data: scores, score band, scenario version, attempt number, primary improvement focus and timing—not the submitted note text.
- Agreement data: the version of the Terms and Privacy Notice accepted, an 18-or-over confirmation and the time and method of acceptance.
- Support and pilot enquiries: contact details, organisation, role and the message you choose to send.
- Technical and security data: IP or hashed identifiers, device/browser information and error or performance metadata.
- Analytics data: page and funnel events after analytics consent. Clinical or learner note text must not be included in these events.
- Pilot billing data: organisation and invoice contact details needed to quote, contract and account for an agreed paid pilot. NurseNote does not currently take payment on this website.
4. Retired product routes and learning content
NurseNote previously tested AI-assisted drafting tools. Those tools are not part of the current public NurseNote Assess product. Some educational articles discuss the risks and limitations of AI in documentation; reading an article does not send note text to an AI model.
5. Purposes and lawful bases
- Contract: to create an account, provide requested services, respond to support and deliver an agreed paid pilot.
- Legitimate interests: to secure the service, prevent abuse, diagnose failures and improve the product using minimised outcome metadata.
- Consent: for non-essential analytics or marketing communications where consent is required. Consent can be withdrawn.
- Legal obligation: where records must be kept for tax, accounting, dispute or regulatory purposes.
NurseNote is not designed to collect special-category patient data. If real patient information is entered contrary to these instructions, stop using the tool and contact us promptly.
6. Service providers and transfers
NurseNote relies on Base44 for application hosting, authentication, database and backend functions and, after consent, analytics services such as Google Analytics and Microsoft Clarity. An agreed organisational pilot may also require professional advisers and invoicing or payment providers; the applicable providers will be identified in the pilot paperwork.
Some providers may process data outside the United Kingdom. Applicable safeguards depend on the provider and service configuration. A complete, current subprocessor and international-transfer schedule is not yet published; request it before organisational use. This is one reason the current organisational offer is a controlled founding pilot rather than general clinical deployment.
7. Retention
- Account and signed-in assessment outcome data is kept while the account is active and until deletion is requested, subject to records that must be retained for legal reasons.
- Guest score progress remains in that browser until the learner clears site storage. An unfinished note draft remains only in the current tab session until successful submission, manual clearing or the tab session ends.
- Agreement acceptance records are kept for as long as reasonably needed to evidence the terms governing the account and resolve legal claims, subject to a documented retention review.
- Short-term assessment allowance records are retained only for abuse-prevention and daily-limit operation.
- Support and pilot enquiry records are kept while the enquiry is active and for a limited period needed for follow-up, disputes and business records.
- Consent-based analytics retention follows the configured analytics provider settings.
NurseNote will review and document more specific deletion schedules before any scaled organisational rollout.
8. Children and supervised learners
Direct individual access is intended for people aged 18 or over. If an organisation arranges supervised access for a learner under 18, the organisation and NurseNote must agree appropriate transparency, safeguarding and data-handling responsibilities before that use begins.
9. Automated decisions
Formative scores must not be used to make employment, education, disciplinary or other decisions with legal or similarly significant effects. NurseNote does not use the assessment to make such decisions about learners.
10. Security
NurseNote uses HTTPS, access controls and data-minimisation measures in its application design. No internet service can promise absolute security. Report suspected security or privacy issues to nursenotesupport@gmail.com.
11. Your rights
Depending on the processing and lawful basis, UK data-protection rights may include access, correction, deletion, restriction, objection and portability. You can also withdraw analytics or marketing consent.
A signed-in learner can request a machine-readable export from Account. The export covers account information, current assessment outcome records, agreement records, support and preferences, technical events and any retrievable legacy product records linked to the account. Submitted NurseNote Assess note text cannot be included because the current product does not retain it.
Account also offers removal of deletable product records. This does not close the authentication account and does not remove records NurseNote may need to retain for agreements, support, billing, security, fraud prevention, legal claims or audit. The result explains what was removed and what remains. Request full account closure or exercise another right by emailing nursenotesupport@gmail.com.
You have the right to object to processing based on legitimate interests. Tell us why you object and we will assess the request against the legal test.
You may complain to the Information Commissioner’s Office if you are unhappy with how personal data is handled.
12. Cookies and analytics choices
Optional analytics remain denied unless you actively accept them. You can change your choice at any time from the Cookie settings link in the site footer. See the Cookie Notice for categories and provider information.
13. Changes to this notice
This notice will be reviewed as the assessment library, organisational reporting and service providers change. Material new uses of personal data will be explained before they begin.