Skip to main content
Trust centre · reviewed 14 September 2026

The controls, providers and limitations in one place.

NurseNote is a narrow writing assistant for fictional or genuinely de-identified text. This page does not claim clinical approval; it explains the current system so you can make an informed decision.

Data boundary

No identifiable patient information. Source and draft text are not written to a NurseNote note history.

AI boundary

Language and structure only. No diagnosis, treatment recommendation or escalation decision.

Human boundary

Every result stays editable and cannot be copied through the product until review is confirmed.

Service providers and processing roles

This is the current operational provider list for the public product. Provider terms may assign different controller or processor roles for particular activities; the Privacy Notice remains the controlling explanation of NurseNote’s processing.

ProviderPurposeData involvedUse
Base44Application hosting, authentication, database, backend functions and the Core model integration.Account, access, technical request data and de-identified note text during a requested generation.Required
Configured Google Gemini model via Base44Draft generation and a separate source-fidelity verification pass.De-identified source text and generated draft during the request. NurseNote does not add internet context.Required for note improvement
StripeSecure card checkout, payment confirmation, refunds and fraud prevention.Account email, purchase metadata and payment references. NurseNote does not receive full card details.Only when purchasing
Google Analytics / Tag Manager and Microsoft ClarityAggregate site and product-journey analytics.Page and allowlisted interaction data; note source and draft text are excluded.Optional — consent required
Google email servicesSupport, privacy, payment and security correspondence.The contact details and message you choose to send. Never include patient information.Only when contacting support

International processing may occur under the safeguards applicable to each provider and service. Do not use this provider list as permission to submit confidential or identifiable patient information.

Security controls

  • HTTPS in transit and restricted, service-only records for usage, payment and verification evidence
  • No application history of source notes or generated drafts
  • Browser and backend checks for common structured identifiers
  • Backend-enforced de-identification confirmation and versioned legal acceptance
  • Keyed one-way identity hashes, request-size limits and device, account and network rate limits
  • Deterministic marker checks plus an independent model pass before a draft is returned
  • Editable source comparison and a required human-review confirmation before copying

These controls reduce risk; they do not make NurseNote an approved patient-data system or guarantee that a generated draft is accurate.

Accessibility

NurseNote targets WCAG 2.2 AA and supports keyboard navigation, visible focus, labelled controls, status announcements, responsive layouts and reduced reliance on colour alone. This is a product target, not a certification.

If a barrier prevents use, send the page, device, browser and assistive technology involved—without patient information. We aim to acknowledge accessibility reports within three working days.

Report an accessibility barrier

Responsible security disclosure

Report a suspected vulnerability privately through the contact form or support email with “Security” in the subject. Do not access, retain or disclose other people’s data; do not disrupt the service; and do not include patient information. NurseNote does not currently operate a paid bug-bounty programme.

Contact NurseNote privately

Availability and support

NurseNote does not yet operate a real-time public status dashboard or promise clinical-service availability. Generation or checkout errors are shown in the product and must never delay clinical care, escalation or record keeping.

Help, payment, privacy, accessibility and security enquiries are acknowledged as soon as practical, with a target of three working days.

Read the detailed notices.

The Trust Centre is a practical summary. The Privacy Notice, Terms, Safety boundary and Governance page contain the fuller rules and limitations.