Privacy Policy

Our privacy policy and how we use your data

Version 1. Effective date: 26 July 2026.

This policy explains what personal data SteadyRN collects, why, who else sees it, and what you can do about it. It describes the site as it actually works today, not a larger product we might build later. There is very little to describe: there are no accounts here, and the readiness check is anonymous.

1. Who is responsible for your data

The data controller is MB Evelaina, a small partnership (mažoji bendrija) registered in the Republic of Lithuania, trading as SteadyRN at steadyrn.com.

MB Evelaina, a small partnership (mažoji bendrija) registered in the Republic of Lithuania.

  • Trading as: SteadyRN, steadyrn.com
  • Company code: 307863457
  • VAT identification number: LT100020307614
  • Registered address: Europos pr. 34-47, Kaunas, Lithuania
  • Email: support@steadyrn.com

Because we are established in the European Union, we process personal data under the EU General Data Protection Regulation (GDPR) wherever in the world you are.

Data-protection questions go to the email address above or through the contact form. We have not appointed a Data Protection Officer and are not required to.

2. No account, no password, and the check is anonymous

Taking the readiness check and preordering the Founding Pass do not involve an account. You never create one, we never ask you for a password, and neither step asks for your name, your nursing registration, your date of birth or your location. If we ever introduce accounts, we will update this policy before we do.

Your check is held against a random token our server generates. That token is the link to your report: anyone holding the link can read that report, and we cannot tell from it who you are.

Your email address enters the picture in one place only. If you preorder, Stripe collects it at checkout so it can send you a receipt and so we can reach you about delivery and refunds. We run no email sign-up form anywhere on this site.

3. What we collect, and why

Grouped by when it happens:

  • When you take the readiness check: which option you selected for each item and whether it was correct, your percentage score per NCLEX category, your pass-probability estimate and its coarse band, your weakest category, how far through the check you got, the timestamps, the market and language the check ran in, and the random session token that lets you reopen your report. We use this to score your check, show you your report, and count how many people finish.
  • How you arrived: the utm_source, utm_medium, utm_campaign, utm_content and utm_term values in the link you clicked, a click-through token from our own advertising redirect, and the address of the page that referred you. We use this to know which advertisement or channel brought you here, so that we do not keep paying for ones that do not work.
  • If you place a preorder: your email address as Stripe passes it to us at checkout, the amount and currency charged, the payment status, Stripe's checkout-session and payment-intent identifiers, the market you were priced against, the delivery date committed to you, and the times of payment, refund request and refund. We use this to take the payment, deliver what you paid for, honour the refund guarantee and keep the accounting records the law requires. We never receive your card number, expiry date or security code.
  • If you write to us: the name, email address and message you type into the contact form. This is delivered to our support mailbox as an email; it is not stored in our database. We use it to answer you.
  • Cookies and measurement: only what our Cookie Policy describes, and only the optional parts you have consented to.

4. We do not collect health data

To be completely plain: SteadyRN collects no health data about you, and no special-category data of any kind within the meaning of Article 9 GDPR.

Your answers to the readiness check are answers to examination questions about hypothetical patients. They measure how ready you are to sit a licensing examination. They are not a medical record, not a health assessment and not a diagnosis, and they say nothing about your health or anyone else's.

We never ask about your health, and we ask you not to send us health information about yourself or about a patient through the contact form. If you do, we will delete it.

5. Our legal bases

Under Article 6 GDPR we rely on:

  • Running the readiness check and showing you your report — performing the free service you asked us for, Article 6(1)(b).
  • Taking your preorder, delivering it and processing refunds — performing our contract with you, Article 6(1)(b).
  • Keeping the record of a payment — our legal obligations under Lithuanian accounting and tax law, Article 6(1)(c).
  • Counting completions and deciding whether to build the full product — our legitimate interest in knowing whether the product is worth building, Article 6(1)(f). We work from aggregate counts. This does not involve profiling you or making any decision about you.
  • Reading the campaign parameters in the link you arrived on — the same legitimate interest. Those values arrive in the address of the page; reading them does not involve storing anything on your device.
  • Analytics and advertising storage — your consent, Article 6(1)(a). It stays switched off until you allow it and you can withdraw at any time from the Cookie settings control.
  • Preventing abuse, diagnosing errors and keeping the service running — our legitimate interest in a service that works and is not being attacked.

6. Who else processes it

We use a small number of providers. They process personal data on our instructions, under a data-processing agreement, and not for their own purposes:

  • Stripe takes the payment and issues refunds. Stripe is the only party that handles your card details, and it acts as an independent controller for its own fraud-prevention and regulatory purposes as well as our processor.
  • Supabase hosts the database that holds readiness-check sessions, answers and preorder records, and the authentication service behind the site.
  • Vercel hosts and delivers the website and runs the server-side code.
  • Google provides analytics and advertising measurement — active only with your Analytics or Advertising consent.
  • Meta measures the performance of our advertising — active only with your Advertising consent, and only where advertising measurement is enabled.
  • Sentry receives technical error reports when error monitoring is enabled, which can incidentally include an IP address.

One further category of recipient: the transactional email provider that carries contact-form messages to our support mailbox and any email we send you about your preorder (Resend). It sees the email address and the content of that message.

That is the complete list. We do not disclose personal data to anyone else except where we are legally obliged to, or where we must to establish or defend a legal claim.

7. Transfers outside the EEA

SteadyRN is operated from Lithuania and most of the people who use it are outside the European Economic Area, primarily in the Philippines. Our providers also process data outside the EEA, mainly in the United States.

Where personal data leaves the EEA we rely on the European Commission's standard contractual clauses, on an adequacy decision where one covers the provider (including the EU–US Data Privacy Framework for certified United States providers), and on the safeguards in each provider's data-processing terms. Ask us and we will tell you which mechanism covers a specific provider.

8. How long we keep it

  • Readiness-check sessions, answers and scores: up to 12 months from the date of the check, then deleted or reduced to aggregate statistics that are no longer personal data.
  • Preorder records, including the email address Stripe gave us: for as long as Lithuanian accounting and tax law requires us to keep the records of a transaction — currently ten years for accounting documents — and then deleted. This is longer than we would otherwise keep it, and it is the one record we cannot delete on request.
  • Contact-form messages: up to 24 months in our support mailbox, then deleted.
  • Cookies and similar storage: for the durations listed in our Cookie Policy.

9. Your rights

Wherever you live, you can ask us to give you a copy of the personal data we hold about you, correct it, delete it, restrict what we do with it, give it to you in a portable form, or stop processing where we rely on legitimate interest. You can withdraw consent for analytics and advertising at any time from the Cookie settings control, which does not affect what was lawfully done before you withdrew it.

Send the request through the contact form or to the email address at the top of this page. We answer within one month, and tell you if a complicated request needs up to two months more. There is no charge.

One honest limitation: the readiness check is anonymous, so for most sessions we genuinely cannot tell which one is yours. If you want us to act on a readiness check, send us the link to your report — that is the only way to identify the session. Article 11 GDPR allows us to decline a request we cannot connect to you, and this is what that means in practice.

A second: we cannot delete the accounting record of a payment while the law requires us to keep it. We can delete everything around it that is not part of that record.

If you think we have got this wrong, you can complain to the Lithuanian supervisory authority — the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt) — or to the data-protection authority of the country where you live. In the Philippines that is the National Privacy Commission.

10. Cookies

We use necessary storage to run the site and, only with your consent, analytics and advertising storage. Our Cookie Policy lists every category, provider, purpose, duration and trigger.

11. We do not sell your data

We do not sell personal data, we do not pass it to data brokers, and we do not add you to anyone's advertising list. The only data that reaches an advertising platform is consented measurement — whether an advertisement led to a completed check or a preorder — as described in the Cookie Policy.

12. Security

Traffic to and from the site is encrypted. The readiness-check and preorder tables have no public access at all and are reachable only from our own server, never from your browser. Card data never touches our systems.

Your report link is a long random token, which means anyone you send it to can read that report. Treat it as private.

No system is perfectly secure. If a breach ever affects your personal data we will notify you and the supervisory authority as the GDPR requires.

13. Children

The service is intended for people aged 18 or over and is not directed at children. We do not knowingly collect data from anyone under 18.

14. Changes to this policy

We may update this policy and will change the version and effective date at the top of the page when we do. If a change materially affects Founding Members, we will tell them by email rather than relying on you to notice.