Skip to content
gasguide
Back

Privacy Policy

Last updated:

Summary

gasguide.app is a study and credentialing platform for CRNAs and SRNAs. We collect the minimum data needed to operate the service: your email and password, study progress, credential documents you upload, and payment information (processed by Stripe — we never see your card data). We do not sell your data, we do not share it with employers or programs unless you explicitly create a share link, and you can delete your account at any time (we cancel billing and irreversibly anonymize your personal information).

Who we are

gasguide.app ("we", "us") is operated by MEDTECH SOLUTIONS USA LLC. This policy is governed by the laws of the State of Florida, without regard to conflict-of-laws principles, consistent with our Terms of Service. EU and UK residents retain mandatory rights under their local law (see "Your rights" below). For privacy questions, contact privacy@gasguide.app.

Data we collect

Account information

  • Email address (required)
  • Password (stored as a bcrypt hash by Supabase Auth — we never see your plaintext password)
  • Optional MFA/TOTP secret if you enable two-factor authentication
  • Optional profile fields: display name, target CRNA program, graduation year, NPI number, state license numbers

Study activity

  • Question bank attempts, scores, and weak-area metrics (including module + section quiz attempts)
  • Section-by-section module completion (which sections you have marked complete)
  • Daily study attendance used for streaks
  • Weekly challenge completion and streak data
  • Personal study notes you write inline against any page
  • Lecture progress and bookmarks
  • 3D anatomy session history
  • Voice mock interview transcripts and scoring (see "Voice-AI" below)

Pre-SRNA application tracking (optional)

  • CRNA program applications you choose to track: school name, status, deadlines, interview dates, notes
  • GPA repair planning entries you create

Credentialing data (B2C and B2B)

  • Credential entries you create: license type, number, issuing authority, issue and expiration dates
  • Documents you upload: licenses, certifications, immunization records, BLS/ACLS/PALS cards, malpractice policies, CV (stored encrypted at rest in Supabase Storage)
  • Document version history and change log
  • Renewal reminders and email alert preferences
  • For employer portal users: organization membership and role; documents you authorize for sharing

Payment data

  • Stripe Customer ID and subscription status
  • Last four digits and brand of your payment card (returned by Stripe; full card data never touches our servers)
  • Billing email and address if you provide them at checkout
  • Invoice history

Technical data

  • IP address (for security, rate limiting, and abuse prevention)
  • User-agent string (browser and operating system)
  • Cloudflare edge logs (request paths, status codes, cached for 24-72 hours)
  • Server-side error logs (no personal data in error messages)

How we use your data

  • Operate the service: serve content, save your progress, process payments, send credential renewal alerts
  • Authenticate you and protect your account (session management, MFA)
  • Send transactional email: signup confirmation, password reset, payment receipts, expiration alerts you opted into
  • Improve the product through aggregated, anonymized usage statistics (which question types are weakest across cohorts, popular study sessions, etc.)
  • Comply with legal obligations and enforce our Terms of Service

Voice-AI mock interview data

When you use voice-based mock interviews (in the Admissions or Boards modules), audio is captured by your browser and sent to our infrastructure for processing. We use:

  • Whisper for speech-to-text transcription, run on our own GPU
  • Ollama (local LLM) to generate examiner responses, run on our own GPU
  • Kokoro TTS for examiner voice synthesis, run on our own GPU

Audio recordings are not retainedafter transcription unless you explicitly opt in to keep them for review. Text transcripts of your sessions and the examiner's scoring rubric output are stored so you can review your performance and so we can show improvement over time. You can delete any session or all sessions from your account settings. Transcripts are not used to train any third-party AI model. They are not used to train our own models without an explicit opt-in checkbox.

Consent + delete-on-request. Before the first voice session you must accept an in-app consent disclosure that lists the providers above and the retention windows below. Audio artifacts referenced by saved transcripts are scrubbed from our database within 24 hours; text transcripts follow a 365-day rolling retention window unless you delete them sooner. You can revoke consent and delete every voice transcript on file at any time from /account/voice-data (or per-session at /account/mock-interviews). Revoking consent re-prompts the disclosure on your next voice-mock visit.

Service providers we use

We rely on these third-party processors. Each is contracted under a DPA where applicable:

  • Supabase — auth, database, file storage. Your account credentials, study data, and uploaded documents are stored in Supabase's US-region infrastructure. Supabase privacy policy.
  • Stripe — payment processing. Your card data is collected by Stripe directly via Stripe Elements and never reaches our servers. Stripe privacy policy.
  • Cloudflare — hosting, CDN, DDoS protection. Cloudflare sees all requests (URL, IP, headers) and caches static assets. Cloudflare privacy policy.
  • Resend — transactional email (account confirmation, password reset, expiration alerts). Resend processes your email address and message content. Resend privacy policy.
  • AWS Textract — optional OCR on credential documents you upload, when you enable that feature. The document image is sent to AWS, OCR text is returned, and AWS does not retain the document under our service configuration. AWS privacy policy.
  • Twilio — SMS expiration alerts, only if you opt into SMS. Twilio processes your phone number and the alert message. Twilio privacy policy.
  • Nursys e-Notify (NCSBN) — license primary-source verification. Receives your name and license identifiers when you enable license verification. Nursys.
  • OpenAI — generates lecture narration and study panels from our course content. No user data is sent. OpenAI privacy policy.
  • Anthropic — powers the AI tutor; your free-text tutor questions are processed to generate answers. Anthropic privacy policy.
  • Sentry — error monitoring so we can fix crashes. Reports are scrubbed of personal data before capture. Sentry privacy policy.
  • Google Drive (optional) — if you connect Drive to import credential documents, we receive read-only access to the files you select. We never browse your full Drive. You can disconnect at any time from your account settings. Google privacy policy.
  • Microsoft OneDrive / Dropbox (optional) — same as Drive: read-only access to files you pick for import, disconnect anytime. Microsoft · Dropbox.
  • Plausible Analytics — cookie-free, privacy-friendly product analytics (page views, referrers, anonymized request data). No cross-site tracking and no personal profiles. Loaded only when you have not opted out at /account/privacy. Plausible privacy policy.

We do not use Google Analytics, Facebook Pixel, advertising trackers, or any third-party ad networks.

Share links

If you generate a share link for a credential document (for example, to send to a hospital verifier or a CRNA program admissions office), the recipient of that link can view the document until you revoke the link or it expires. Share links are signed, time-limited URLs scoped to the specific document you selected. We log when share links are accessed so you can see who viewed what and when.

What we don't do

  • Sell your data to third parties
  • Share your study performance, transcripts, or documents with employers, programs, or insurance companies (you control all sharing via share links)
  • Use your interview transcripts to train AI models without an explicit opt-in
  • Track you across other websites or use advertising cookies
  • Send marketing email without an opt-in

Your rights

You have the right to:

  • Access — download all data we have about you. Email privacy@gasguide.app and we will respond within 30 days.
  • Delete — request account deletion from /account/delete. An automated daily sweep processes the request within 30 days: we cancel any active subscription and irreversibly anonymize your account (we clear your email, name, phone, NBCRNA id, and target program). Study activity such as question-bank attempts and mock-interview history is not personally identifiable on its own and is retained in anonymized form so it can no longer be linked to you. Records we are legally required to keep (for example, payment records for tax purposes) are retained for the period required by law.
  • Correct — edit profile fields, credential entries, and study data from your account dashboard at any time.
  • Export — request a copy of your data by emailing privacy@gasguide.app; we will provide it in a portable, machine-readable format within 30 days.
  • Opt out of marketing email (we send transactional email only by default).
  • Lodge a complaint — if you believe we have violated your privacy rights, you may contact your local data protection authority.

California residents have additional rights under the CCPA, including the right to know what personal information we collect and the right to opt out of any "sale" (we do not sell data). EU residents have rights under the GDPR including data portability and the right to be forgotten. To exercise any of these rights, email privacy@gasguide.app.

Data retention

  • Account data: retained until you delete your account
  • Study activity: retained until you delete your account
  • Voice-AI transcripts: retained until you delete the session or your account
  • Voice-AI audio: not retained after transcription unless you opt in
  • Credential documents: retained until you delete them or your account
  • Payment records: retained for 7 years to comply with US tax law
  • Server logs: 30-90 days, then aggregated or deleted
  • Support correspondence: 2 years for service-quality and security review

Security

We use industry-standard practices: TLS 1.2+ for all traffic; bcrypt password hashing; row-level security policies in our database so each user can only access their own data; optional TOTP-based two-factor authentication; encrypted-at-rest file storage; principle of least privilege for admin access; security review of code changes before deployment. No system is perfectly secure. If we discover a breach affecting your data, we will notify you without undue delay under our published breach-notification SOP (/legal/breach-notification-sop): Covered Entities within 10 business days of discovery, affected individuals within the timelines required by applicable law.

Children's privacy

gasguide.app is not directed to children under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.

International users

Our infrastructure is located in the United States. By using gasguide.app from outside the US, you consent to your data being transferred to and processed in the United States under US law.

Changes to this policy

We may update this policy. Material changes (new categories of data collection, new sharing of data, changes to retention) will be announced by email at least 30 days before they take effect. The "last updated" date at the top reflects the most recent revision.

Contact

Questions, concerns, or requests: privacy@gasguide.app

For credentialing-data verification requests from employers, please use the share link the credential holder provided rather than emailing privacy.

gasguide.app is an independent platform and is not affiliated with the AANA, NBCRNA, COA, or any specific CRNA program. Back home.