Beta legal notice · draft for legal review
Beta Privacy Notice
1. Scope and purpose
This notice explains how the RN Open Lab beta collects, uses, stores, and protects information during invitation-only product testing. Beta information is used to provide access, show each tester their own results, evaluate questions and features, troubleshoot technical problems, and improve the educational product.
2. Information collected at entry
- Full name and assigned individual tester code.
- Nursing-program credential, such as ADN/ASN, BSN, entry-level MSN, or other.
- Program format, such as traditional, accelerated, bridge, or other.
- Confirmation that the tester is at least 18 years old.
- Acceptance time and version of the Beta Terms and Privacy Notice.
3. Optional tester-profile information
After diagnostic results are displayed, testers are strongly requested—but not required—to provide additional background information. Blank responses are treated as “prefer not to answer.” This information may include:
- Graduation month and year.
- State or jurisdiction where the tester plans to seek initial licensure.
- Number of previous NCLEX attempts.
- Planned NCLEX month and year.
- Types or names of preparation materials previously used.
- Self-reported confidence and additional preparation context.
Optional profile information does not change scores, diagnostic classifications, module access, or educational feedback.
4. Learning and technical activity
- Modules opened, completed, or revisited.
- Question identifiers, item types, selected responses, correctness, and partial-credit information.
- Diagnostic and module scores, attempts, completion status, and time spent.
- Rationale, hint, coaching, study-planning, and feature-use information when available.
- Browser-generated technical errors and voluntarily submitted beta feedback.
5. How information is used
- Authenticate individual beta access and maintain private sessions.
- Display a tester’s own scores, history, and recommendations.
- Provide the authorized administrator with beta oversight.
- Identify confusing, overly difficult, technically broken, or poorly performing questions.
- Evaluate usability across program pathways and preparation experiences.
- Protect the beta, investigate misuse, and maintain technical security.
Information will not be sold or used for unrelated behavioral advertising.
6. Who can see identifiable information
A tester can see only their own identifiable scores and activity. The authorized beta administrator can see all tester records for beta operation and evaluation. Other testers cannot view another tester’s information.
Identifiable results will not be disclosed to a school, nursing program, board of nursing, employer, or preparation company without the tester’s authorization, except when disclosure is legally required or necessary to address security or unlawful activity.
7. Service providers and storage
Beta records are stored in a restricted Supabase Postgres database. Vercel hosts the website and its protected server routes, and Supabase provides the managed database service. These providers process information needed to deliver and operate the beta under their applicable service terms and privacy commitments.
Cloudflare provides bot-detection services for the public access-request form and may process technical request information needed to verify legitimate submissions.
8. Retention
Identifiable beta information will be retained for no longer than 12 months after the beta testing period ends, unless a longer period is required by law, needed to resolve a documented security or legal matter, or separately authorized by the tester. At the end of the retention period, identifiable records will be deleted or converted to de-identified statistics that are not reasonably linked to an individual tester.
9. Tester choices and requests
Testers may request access to, correction of, or deletion of their identifiable beta information. A deletion request may end access because the individual tester record is needed to authenticate and display private results. Requests should be sent to rnopenlab@rnopenlab.app and should include enough information to verify the requester’s assigned tester record.
10. Security and limitations
Reasonable administrative and technical safeguards are used, including individual codes stored only as hashes, signed server sessions, server-only database credentials, database row-level security, and separation of tester and administrator views. No internet transmission or storage system can be guaranteed completely secure. Testers should promptly report suspected unauthorized access and should not share their codes.
11. Adults only
The beta is intended only for individuals who are at least 18 years old. It is not directed to children or minors.
12. Contact and changes
Material changes will be identified by an updated version and effective date. If a material change affects previously collected information, additional acknowledgement may be requested. Privacy questions and data requests should be sent to rnopenlab@rnopenlab.app.