Privacy · updated 6 September 2026
Your learning.
Your choice.
Pre-launch information: the verified seller/data-controller identity, postal address and support contact must be completed before registration, shared contributions or live sales open.
What nika stores
Your account email and authentication records are managed by Supabase. Our server stores your account identifier, subscription and payment references, credit grants, and AI usage metadata such as model, token counts, cost and request status. These records operate your account, prevent misuse and account for credits. They are not a shared training dataset. Stripe handles card details; nika does not store your card number.
What happens when you use AI
The content needed for a task is sent through nika’s server to OpenAI to generate the result. Request content is not deliberately stored in our billing/usage tables. OpenAI API data is not used to train OpenAI’s models by default. Our requests use store:false; this is not zero retention, and provider abuse-monitoring logs can generally be retained for up to 30 days. See OpenAI’s API data controls.
Do not submit patient data, confidential records or personal information about other people. Review AI output: it can be wrong and is not medical advice.
Your preferences and local personalisation
Your original onboarding answers and versioned study preferences are saved privately to your account, so they survive signing in on another device. Only your authenticated account can access them. AI interpretation sends the answers to our pretrained provider to extract your preferences; it does not train a model. You can skip it, edit the summary yourself or change your preferences later.
The desktop app keeps card history, edits, source references, review feedback and learning-model files on your computer in your own account workspace. Relevant reviewed examples and saved preferences can be included with your source in future AI requests. The reviewed-example history does not currently sync to another device. You can pause personal learning in Settings without turning off card generation.
Feedback is recorded for quality review, not as proof that an accepted card is factually correct. No automatic retraining or separate model per user is created. Server feedback records, if explicitly submitted through the authenticated service, remain private to your account and are included in your data export. The desktop does not automatically upload this history to that service or create Excel training sheets. Choosing not to contribute to shared training does not change your plan.
Optional shared training
This starts off. If you opt in, you may review and submit individual card questions, answers, edits or preference pairs for nika to evaluate and train future shared card-generation or ranking models. Each contribution requires confirmation that it contains no personal or patient information and that you have permission to share it for this purpose. Do not submit copied question-bank material, raw PDFs or screenshots.
We store each submitted example with a pseudonymous account identifier, timestamp, consent receipt and policy version. Pseudonymous does not mean anonymous. Shared contribution access is restricted; other users cannot browse your examples. There are no automatic shared-model training jobs at present.
Changing your mind
Use Account → Withdraw & delete shared examples. This immediately turns sharing off and deletes your examples from the active contribution database. Future datasets must exclude withdrawn examples. It cannot automatically undo the influence of material on a model already trained. Before any shared-model release, the operator must verify consent again and implement a reviewed deletion/retraining process. Backup retention and the final retention schedule remain launch checks.
The contribution page lets you inspect and download recent shared examples. Account-wide access, correction, export and deletion requests must be handled by the verified contact above once launch opens. Some billing records may need retention for legal obligations.
Access and account deletion
In Your data and privacy, download a paginated JSONL export of your server-held account data or submit a verified account-erasure request. We record a reference and a one-month response target. Submitting erasure immediately withdraws shared contributions, but it does not itself delete your account, cancel billing or erase local files. Support reviews outstanding billing, statutory retention and provider-held copies before closure. Records that must legally be retained are restricted and excluded from training. Contact support for a complete access request or correction.
Service providers and international processing
Supabase provides authentication/database services, Railway hosts the portal/API, Stripe processes payments, Cloudflare Turnstile protects account forms, and OpenAI provides AI inference. A European hosting region does not guarantee that every provider processes data only in the UK or Europe. Provider agreements, transfer safeguards, retention schedules and the final privacy review must be completed before public launch.