Privacy Policy
Last updated: August 5, 2026
FQHC Talent ("we," "us," or "our") operates the fqhctalent.com website. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our platform. We are committed to being transparent and direct about our data practices. Your trust matters to us, and we take reasonable steps to protect the information you share with us.
1. Information We Collect
We collect the following categories of personal information when you use FQHC Talent:
Identifiers: Your name, email address, and optionally your organization and city/region. This is collected when you subscribe to a newsletter, request optional report updates, submit an intelligence tip or a leader-profile claim, or save your progress in a tool.
Professional information: Job titles, work history, employer names, education history, skills, EHR system experience, certifications, language abilities, and professional objectives. This is collected when you use our resume builder tool.
Resume files: If you upload a resume (PDF, DOCX, or TXT format) in the web resume builder, we parse it in memory to pre-fill your draft and do not retain the original uploaded file. Browser drafts are not server-persisted automatically. If you sign in and explicitly save, we store the reviewed profile fields, extracted resume text, and reflection summaries under your authenticated account; the resume email must match that account.
Website Career Case: The resume, interview, and First 90 Days engines share one browser-local Career Case. It can contain the full pasted target posting; exact requirement excerpts; proof and source excerpts; complete typed interview answers; Stories; manager-confirmed wins; and saved resume variants. These deterministic engines store those Career Case fields in ordinary, unencrypted localStorage and do not send them to our server or an AI service. Importing a resume file for deterministic parsing and choosing signed-in Save profile are separate actions that disclose the fields sent to our server. Anyone with access to the same browser profile may be able to read local content, so do not use these tools for sensitive content on a shared device.
Career Workspace: The Workspace stores job-target metadata, application stage and checklist state, artifact names/status, interview self-ratings and optional notes, offer and First 90 planning notes, goals, saved events, and Career Radar preferences. Signed-out data stays in ordinary, unencrypted localStorage. If you sign in, account-scoped Workspace data syncs to our database under your authenticated user ID; guest data is never merged unless you explicitly choose to merge it. The Workspace does not sync the full pasted posting, résumé or cover-letter text, complete interview answers, or Career Case evidence. Avoid sensitive notes on shared devices. If you enable Career Radar email, only the explicit target, goal, event, follow, role, location, and cadence fields needed to personalize delivery are copied into your newsletter preferences; we do not create an employability score or candidate ranking.
Website onboarding data: The onboarding planner stores checklist progress for each track, role, and audience plus your saved start date in ordinary, unencrypted localStorage. It stays in that browser and is not a credential, completion determination, readiness score, or server-synced employee record.
Role-description worksheet information: Organization name, role details, salary context, benefits, and screening prompts entered into the local worksheet. The worksheet is designed for your own ATS, careers page, or internal planning process; it does not publish roles on FQHC Talent.
Career reflection responses: Your answers to our Career Insights self-reflection questions and the resulting tool summaries. This helps provide planning content, compare role expectations, and prepare examples; it is not a credential or hiring assessment.
Manager and team planning data: If you use our Team Readiness or OKR planning tools, we may collect your responses, tool summaries, domain summaries, and session identifiers to provide planning content and track saved tool history over time. Team Readiness full reports are saved in your browser by default; if you are signed in, or if you explicitly save a browser result to your dashboard, the report may be linked to your account.
Newsletter subscription data: When you request our newsletters (Intel Brief for FQHC leaders and/or The Pulse for job seekers), we temporarily collect your email address, audience preference, locale and request source, confirmation credentials, and optionally your region, role type, primary challenge, organization size, and content preferences in a pending request. We do not create, reactivate, or change a subscription until the mailbox owner confirms. An unconfirmed request expires after 24 hours; the next hourly privacy cleanup normally minimizes every submitted request field and both request credentials. Confirmation copies the confirmed delivery fields into the subscriber record and immediately minimizes the temporary request row. After confirmation, we track subscription status (active, bounced, or unsubscribed) and position in any automated email drip sequence.
Team brief request data: If you request a free team brief, we collect your email, organization, optional name, title, state or region, focus areas, notes you choose to share, and, when available, the saved homepage brief preference and Following watchlist included by the request form so the brief can be contextualized.
Learning and course progress: When you use our Academy courses (such as the OKR Course), learning pathways, or interactive simulators, your progress, completed modules, and earned XP are stored locally in your browser (localStorage). If you choose to save your progress (by providing your email), we sync this data to our servers so you can pick up where you left off on any device. You are never required to sync — local-only progress works just fine.
Habit streaks: When you read the Daily Brief or use future habit loops, we may store a small streak record locally in your browser, including the habit ID, active dates, current streak, longest streak, and last active date. If you sign in, those streak records may sync to your account so your habit progress can follow you across devices.
Tool usage data: Unless you decline analytics, use of our interactive tools (simulators, OKR templates, resume builder, career reflection, learning pathways) may produce pseudonymous or aggregated usage events — such as which tool you used, which template you downloaded, or which simulator scenario you ran. This helps us understand which tools are most valuable so we can keep improving them. If you provide your email for a functional save or download, that requested record may be associated with your email whether or not you accept optional analytics. We may also record first-party product events for certain content or profile views unless you have refused analytics. These events are not sold, shared with advertisers, or used to evaluate users for employment outcomes.
Brief preference and feed interaction data: Unless you decline analytics, use of the homepage brief builder, filters, save/share controls, public directory export/download controls, source links, correction links, newsletter archive links, saved-job workspace, tool handoffs, or external job-application links may produce pseudonymous or aggregated product events such as selected state, selected role, filter used, item opened, source domain opened, correction form started, item saved, item shared, issue read, directory export opened/downloaded, saved-job stage changed, or employer ATS exit clicked. We do not collect resume text, application notes, correction text, or free-text field contents in these analytics events. These events are used to improve the usefulness and cadence of the site. They are not sold, shared with advertisers, or used to evaluate users for employment outcomes.
Feedback: If you use our feedback widget, we collect the page URL, feedback type, your message, and optionally your email address.
Newsletter engagement: Our email provider (Resend) notifies us when a newsletter we sent you is delivered, opened, clicked, bounced, or reported. Historical active subscriptions created through the former direct form carry a legacy form-submission delivery basis but are not labeled mailbox-verified; new subscriptions and preference changes require mailbox confirmation. We always process eligible bounce and complaint events so unsafe future delivery stops. Other engagement events are stored only for mailbox-confirmed subscriptions (your email address, the email subject, and the clicked link path, if any) to understand which stories are useful. This engagement data stays in our systems and is not sent to Google Analytics or an advertising platform. After verified deletion, we retain only a secret-keyed HMAC suppression value—not the plaintext email—so delayed provider events cannot recreate deleted email data; a fresh mailbox-owner confirmation is required to clear it.
Completion records: If you complete an Academy course and add your name to the record, the name you enter is stored with the completion record and is visible to anyone who looks up that record's unique verification ID. This confirms a site completion record only; it is not a credential, license, accredited CE/CME, or hiring assessment. New records also keep a holder-only revocation key in your browser so you can remove public verification from the My Records page on that device. For older records without that key, email privacy@fqhctalent.com with the record ID for manual public-verification removal. Use a preferred name if you wish.
Mobile app data: If you use our mobile app and enable notifications, we store your device push token and notification preferences (role, region, topics). Push registration and other signed mobile writes may register a stable device-scoped ID plus hashed device secret for request signing and abuse prevention. The app also can sync device-scoped favorites and watchlist items using a stable device ID and signed API requests so saved items survive reinstall or device changes; these records contain item IDs and follow labels, not your name or email. Minimized first-party mobile product events may include an event name, time, app version, language, static route, readiness, points, or coarse role/region context. The app and server remove exact item, job, and reference IDs; application status; contact, résumé, and interview fields; and exact clinic context before storage. Mobile product events are deleted through the in-app Delete my data flow and otherwise retained for no more than 24 months. Resume drafts, interview-practice notes, proof records, and generated documents otherwise stay in app-controlled storage on your device or browser. If you explicitly consent to résumé import, the selected file or pasted text is sent to FQHC Talent for deterministic parsing or OCR in memory; the original file is not retained. Interactive content requests send only the context needed to return the requested material—for example a selected interview role, first-90 role/situation, authored search query, or selected Today region—and do not include your résumé, proof records, or interview answer. Mobile résumé cloud save is currently unavailable, and its server endpoint does not read or persist submitted résumé/profile data. Cloud save will remain disabled until we can verify that the signed-in user or email owner is authorized to save the profile.
Mobile diagnostics, feedback, and support email: The app keeps a local error log and local performance marks on your device for troubleshooting. The error log leaves your device only if you choose to email it. The app sanitizes obvious contact strings, tokens, URLs with query strings, and sensitive resume/interview context keys before local storage and sanitizes stored entries again immediately before email export, including entries created by older app versions. If you choose Send feedback, Email support, or Send error log, your device mail app may include your sender address, display name, signature, and any message content you leave in the draft. These optional user-sent logs may be treated as Crash Data/Crash logs in app-store privacy forms. Local performance marks stay on your device and are not automatically collected unless we add a future telemetry service and update this policy and store answers first.
Browser alert data: If you enable web alerts from Following, we store a browser push endpoint, the cryptographic keys required by Web Push, your locale, and the FQHCs, regions, counties, or topics you chose to follow. This lets us notify that browser only when there are matching signals. No name or email is required for browser alerts.
Voice input: Our mobile app lets you speak instead of type. On iPhone/iPad, speech is transcribed on-device by Apple's on-device speech recognition. On Android, your device's built-in speech service (which may be provided by Google) processes the audio under your device maker's policy. We do not record, store, or transmit your voice to our servers — we receive only the resulting text you choose to keep.
Account information: If you create an account using our authentication system (passwordless email link, email/password, or a configured OAuth provider), we store your user ID, display name, professional role, organization, region, and onboarding status. Supabase manages authentication tokens and session cookies.
Content reading progress: When you view, mark as read, or save content for later while signed out, we store a small reading-history record in your browser's localStorage so the site can remember useful content on that device. This local record includes content type, content ID, read/save status, progress, and last-read time. If you later sign in, those local records may sync into your account Library so your saved and read content follows you across devices. When you are logged in, we store reading progress in your account. You can manage account reading history in your dashboard, clear local-only reading history through your browser storage controls, or request deletion of synced account data.
Saved jobs and Following ownership: New signed-out saved jobs, application notes, and watchlist follows are stored in a browser guest scope. Signed-in browser caches are separately namespaced by authenticated user ID and sync only with that user's account rows. While authentication is unresolved, these stores remain masked. Changing from account A to account B or signing out changes the visible namespace; one account's browser cache is not displayed or merged into another account or the guest space. Older unscoped browser data and guest data found after sign-in stay hidden until you explicitly move them into the current account or discard them. Clearing the current list deletes only the current guest/account namespace and, when signed in, that account's matching server rows.
Usage data: Analytics runs unless you refuse it — by choosing Decline in the cookie notice, saving an opt-out, or sending Global Privacy Control or Do Not Track. Unless you have refused, we use Google Analytics 4 to collect pseudonymous and aggregated information about how visitors interact with our site, including pages visited, time on site, general geographic region, device type, referral source, and first-party analytics identifiers such as client IDs. We also use Vercel Web Analytics for anonymous aggregate page-view data and Vercel Speed Insights for anonymous real-user Web Vitals and performance data. We do not send these analytics providers your name, email address, resume content, or career-tool responses.
Technical data: IP addresses are temporarily processed for rate limiting and abuse prevention. We do not associate IP addresses with your profile. If you submit a data-deletion request, we store a limited request audit log with IP address and user-agent so we can verify, troubleshoot, and document the privacy request.
2. How We Use Your Information
We use the information we collect for these specific purposes:
Career tools and resources: To provide free career tools, aggregated job postings, salary intelligence, and strategic resources for community health professionals exploring opportunities at Federally Qualified Health Centers (FQHCs) across the United States.
Resume generation: To generate a formatted resume document (PDF) based on the information you provide in our resume builder. The resume is generated locally in your browser — your resume PDF is not stored on our servers.
Newsletter delivery: To send you our newsletter publications based on your subscription preferences. We operate two newsletter tracks: Intel Brief (strategic intelligence for FQHC leaders) and The Pulse (career updates for job seekers). We may also send you a short automated welcome sequence (drip emails) over 2-3 weeks after you subscribe to help you get the most value from the platform. Every email includes a one-click unsubscribe link.
Team brief requests: To prepare and follow up about the free brief you requested, using the organization, state or region, focus areas, notes, saved brief preference, and Following watchlist you provided through the request form.
Academy and learning tools: To provide interactive courses, simulators, educational content, and habit loops through our FQHC Academy and Daily Brief. Course progress, streaks, and Team Readiness reports are tracked locally in your browser by default. If you choose to save your progress or Team Readiness report with your email or account, we store it server-side so you can resume on any device. Reflection and planning outputs from tools like Career Insights and Team Readiness may be stored to provide saved summaries and selected follow-up content.
Tool improvement: To understand which tools, templates, and features are most used and most valuable. We analyze pseudonymous or aggregated tool usage patterns (such as: which OKR templates are downloaded most, which simulator scenarios are run most often) to prioritize improvements. When a pattern is tied to an email or account because you asked us to save or sync something, we use it to support that feature and improve reliability, not for advertising or employment evaluation.
Communications: To send you a confirmation email when you sign up, and to send relevant job opportunities, platform updates, and career resources. Every email includes an unsubscribe option.
Submission notifications: To notify our team when someone submits a form (an intelligence tip, a feedback message, a leader-profile claim) so we can review and respond.
Platform improvement: To understand how people use our site so we can make it more helpful. We analyze aggregated usage patterns, not individual behavior.
Abuse prevention: To enforce rate limits and prevent spam or automated abuse of our forms.
3. Information Sharing and Disclosure
We do not sell your personal information. We have never sold personal information, and we have no plans to do so.
We do not share your data with advertisers, data brokers, or any third parties for marketing purposes.
We do not provide your career-tool profile to organizations for employment evaluation. The information you provide through our career tools (resume builder, reflection tools) is used solely to generate your career documents, self-reflection summaries, and planning content. Your data stays with you.
We use the following third-party service providers to operate our platform. These providers process data on our behalf and are contractually obligated to protect it:
Supabase: Database hosting and limited private file storage (servers located in the United States). Stores profile information you choose to submit, saved-account records, and legacy private files if they exist.
Resend: Email delivery service. Processes your email address and name to send confirmation and notification emails.
Vercel: Website hosting, server-side processing, Web Analytics, and Speed Insights. Only when analytics has not been refused, after trusted human input, and only on our canonical production domains, Vercel Web Analytics may receive an event timestamp, path and dynamic route, referrer, general geolocation, browser/OS/device type, and script version for anonymous aggregate reporting. Vercel says its request-derived visitor hash is not tied to an individual or IP address and is discarded after 24 hours. Speed Insights may receive route and path, network class, browser, device/OS, country, Web Vital and attribution, SDK version, and server-received time. The application removes query strings and fragments before either collector transmits, and Speed Insights samples 50% of eligible traffic. These collectors do not load on preview/local hosts or when analytics is declined or blocked by GPC, DNT, or another saved browser opt-out.
Google Analytics 4: Pseudonymous and aggregated website analytics. It runs unless you refuse it. Only when the audited GA Admin safety gate is open may it collect usage data via first-party cookies; it is not loaded when you decline analytics, opt out, or send a recognized browser opt-out signal. We do not send Google Analytics your name, email, resume content, or career-tool responses. Analytics data may be shared across our domains (fqhctalent.com and healthcaretalent.org) for a unified understanding of site usage.
Cloudflare: DNS and email routing services. Processes domain-level traffic and routes incoming emails to our team.
Mobile push delivery (Expo, with Apple Push Notification service and Firebase Cloud Messaging): If you use our mobile app and opt into notifications, a device push token is sent to these services to deliver the alerts you requested. No name or email is associated with the push token unless you separately choose an account or email-backed feature, and the token is used only for requested alerts.
Browser push delivery (standard Web Push through your browser vendor's push service): If you enable web alerts, your browser push endpoint is used to deliver the alerts you requested. No name or email is associated with the browser endpoint.
For more information about how our service providers handle your data, you can review their respective privacy policies: Supabase (supabase.com/privacy), Resend (resend.com/legal/privacy-policy), Vercel (vercel.com/legal/privacy-policy), Cloudflare (cloudflare.com/privacypolicy), Expo (expo.dev/privacy), and Google Analytics (policies.google.com/privacy). Browser push delivery is also subject to your browser vendor's privacy policy.
We may disclose your information if required by law — for example, in response to a valid court order, subpoena, or government request — or if we believe disclosure is necessary to protect the safety of our users, the public, or our platform.
4. Your Rights Under California Law (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give you specific rights regarding your personal information:
Right to know: You can request that we disclose what personal information we have collected about you, the categories of sources, the purpose for collecting it, and the categories of third parties we have shared it with.
Right to delete: You can request that we delete the personal information we have collected from you. Upon receiving a verified request, we will delete your information from our systems within 45 days, except where we are required by law to retain it. You can start a deletion request at /delete-data or directly in our mobile app (You → "Delete my data"). The mobile flow wipes data stored on your device and sends an email-verified request to delete server-side records tied to that email, including newsletter, résumé, saved tool, course-progress, submission, feedback, request, and matching account data where present.
Right to correct: You can request that we correct inaccurate personal information we have about you.
Right to opt out of sale or sharing: We do not sell your personal information. As described in Section 5, our use of Google Analytics may qualify as "sharing" under the CCPA/CPRA, and you can opt out at any time via /do-not-sell, the Global Privacy Control signal, or email.
Right to non-discrimination: We will not discriminate against you for exercising any of your privacy rights. You will receive the same quality of service regardless of whether you exercise your rights.
Right to limit use of sensitive personal information: We do not intentionally request sensitive personal information as defined by the CPRA. Please avoid adding sensitive details to resumes, profiles, or free-text fields unless they are necessary for the feature you are using. If you choose to include sensitive information in a resume, profile, message, or other free-text submission, we process it only to provide the requested feature, protect the service, and honor deletion, correction, and privacy-rights requests.
To exercise any of these rights, email us at privacy@fqhctalent.com with the subject line "Privacy Rights Request." We will verify your identity by confirming the email address associated with your account. We will respond to your request within 45 days as required by California law. You may also designate an authorized agent to make a request on your behalf.
5. Do Not Sell or Share My Personal Information
We do not sell your personal information for money. We do not participate in data broker networks, run targeted ad campaigns, or build advertising profiles.
However, under California law (CCPA/CPRA), our use of Google Analytics may qualify as "sharing" personal information for cross-context behavioral advertising. To opt out, visit /do-not-sell for our full opt-out page, or email privacy@fqhctalent.com.
Automated signals we honor: We respect the Global Privacy Control (GPC) header that browsers and extensions can send on your behalf. California law (§ 1798.135(b)) treats GPC as a legally valid opt-out request. When we detect GPC, we do not load Google Analytics, Vercel Web Analytics, or Vercel Speed Insights, and we do not record first-party product analytics events for that session. We also honor the legacy Do Not Track (DNT) browser signal.
If our practices ever change, we will update this policy and provide you with the opportunity to opt out before any sale or sharing occurs.
6. Data Retention
We retain your personal information only as long as necessary for the purposes described in this policy:
Profiles and saved tool data: Retained for as long as you wish to keep using the platform. You may request deletion at any time.
Resume builder: Original resume uploads in the web builder are parsed in memory and are not retained. Saved resume profile fields, extracted resume text, and reflection summaries are retained for as long as your profile exists. Legacy uploaded resume files tied to a saved profile, if any, are deleted when you request profile deletion.
Browser-local career retention: The website Career Case is physically deleted from localStorage 30 days after its last saved activity. If active data is corrupt or from a future schema, that blocked raw data and its recovery copy are physically deleted 30 days after first detection; repeated loads do not restart that period. Onboarding checklist progress and the saved onboarding start date are each physically deleted 30 days after their last saved change. The separate resume-builder draft is physically deleted after 7 days. Every website page checks at startup, every 60 seconds while open, and when the page becomes visible or focused again. A closed browser cannot execute deletion at the deadline, so expired content is deleted on the next visit to the website. The footer's Career data control lets you delete the Career Case, recovery copies, resume draft, onboarding progress, and saved start date immediately.
Newsletter requests and subscriptions: A pending request expires 24 hours after creation unless confirmed. The next hourly privacy cleanup normally minimizes every submitted field and both request credentials; 24 hours is the confirmation deadline, not a guaranteed cleanup timestamp. A confirmation submitted after that deadline cannot activate the request, but merely opening or attempting an expired link does not promise an immediate cleanup run. A successful confirmation immediately minimizes the temporary request row after copying the confirmed delivery fields into the subscriber record. Confirmed email and preferences are retained while the subscription record exists. When you unsubscribe, we set the status to "unsubscribed" to prevent further sends. You may request deletion of the plaintext subscriber, pending-request, and engagement records at any time. Verified deletion keeps only a secret-keyed HMAC suppression tombstone with no plaintext email so an at-least-once provider webhook cannot recreate deleted data. A new mailbox-owner confirmation is the only action that clears that tombstone.
Browser alert subscriptions: Browser push endpoints and watch preferences are retained while the alert subscription is active. When you turn off browser alerts from Following, or when the browser endpoint expires or returns an unavailable response, we mark the subscription inactive. If you revoke notification permission in browser settings, delivery should stop in that browser; our server record is updated when you use the off button or when the browser push service reports the endpoint is no longer available. Web push sent logs are retained for deduplication and delivery troubleshooting.
Reflection and course data: Career reflection summaries, Team Readiness planning outputs, and other tool-generated data are retained as long as your profile exists. Locally stored course progress and Team Readiness reports (in your browser) persist until you clear your browser data. Server-synced course progress and account-linked Team Readiness report history are retained until you request deletion.
Tool and product usage events: Pseudonymous or aggregated tool usage and product interaction data (which tools, templates, filters, state/role brief preferences, saved/shared items, source domains opened, correction starts, saved-job stages, external job-application exits, or newsletter issues you used) is retained for up to 24 months for product improvement analytics only when GPC/DNT, browser opt-out, or analytics-decline signals are not present. If you provided your email with a functional tool record, you may request deletion at any time.
Mobile diagnostics: Local error logs and local performance marks are retained on your device until you clear them or clear app data. User-sent support error logs are retained in our support inbox only as long as needed to troubleshoot and then deleted during routine support cleanup.
Feedback submissions: Feedback you submit through our feedback widget is retained indefinitely to help us improve the platform. If you included your email, you may request deletion.
Email communications: Transactional email logs (confirmations, notifications, newsletter sends) are retained by our email provider (Resend) for up to 30 days for delivery troubleshooting. We also maintain an internal log of newsletter sends (date, recipient count, track) for operational purposes.
Analytics data: Google Analytics event data is currently configured for two months of retention in pseudonymous and aggregated form. On our current Vercel Pro plan, the Web Analytics reporting window is 12 months and the Speed Insights reporting window is 30 days. Those Vercel windows describe how long reports remain available to us, not guaranteed deletion deadlines for underlying provider records; Vercel handles any additional retention under its privacy policy and our service terms. We use analytics to understand product patterns, not to make employment or user-evaluation decisions.
Rate limiting data: IP-based rate limiting data is stored in temporary server memory and is automatically cleared within minutes. A data-deletion confirmation request is usable for 24 hours. If it is not confirmed, the next hourly privacy cleanup normally redacts its email, token, IP address, and user-agent; 24 hours is the confirmation deadline, not a guaranteed cleanup timestamp. The minimized non-PII audit row is deleted after 90 days. A successful confirmation immediately redacts those fields from every matching request row. Other rate-limiting data is not written to a database.
If you request deletion of your account and data, we will remove covered plaintext information from our active databases within 45 days. The HMAC-only email suppression tombstone described above is retained without the plaintext address to enforce the deletion against delayed delivery events. Some information may persist in encrypted backups for up to 90 days before being permanently deleted, and provider-held delivery logs follow the provider retention described above.
7. Data Security
We take the security of your personal information seriously and implement the following measures:
All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.
Our database uses row-level security policies to restrict access. API routes that handle your data use a secure server-side key that is never exposed to browsers.
Form inputs are validated and sanitized on both the client and server to prevent injection attacks.
We apply rate limiting and other abuse controls to form endpoints based on the risk and protocol requirements of each endpoint.
Security headers are configured on all pages (including protections against clickjacking, content sniffing, and cross-site scripting).
Access to our production database and hosting infrastructure is restricted to authorized personnel only.
While no system is 100% secure, we take reasonable and appropriate measures to protect your data from unauthorized access, loss, misuse, or alteration. If we become aware of a data breach that triggers a legal notice obligation, we will notify affected users and appropriate authorities as required by applicable law, including California Civil Code § 1798.82 where it applies.
8. Cookies and Tracking Technologies
We use the following cookies and tracking technologies:
Vercel Web Analytics and Speed Insights: Their first-party scripts do not load when you decline. After trusted human input, they may load only on our canonical production domains when analytics is not blocked by GPC, DNT, or another saved browser opt-out. Web Analytics does not use third-party cookies; Vercel derives a request hash for anonymous aggregate page views and says the visitor-session state is discarded after 24 hours. Speed Insights reads browser performance APIs to report sampled real-user Web Vitals. Before transmission, our application removes query strings and fragments; preview and local traffic are excluded, and Speed Insights samples 50% of eligible production traffic.
Google Analytics 4: It runs unless you refuse it. When the audited GA Admin safety gate has been verified, it may load only after trusted human input. It does not load when you decline analytics, opt out, send GPC/DNT, or while that safety gate remains closed. It uses first-party cookies to collect pseudonymous usage statistics and client identifiers. These cookies are not used by us for advertising. You can opt out at the browser level by installing the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout), enabling Global Privacy Control in your browser, using the cookie notice's Decline control, or visiting our /do-not-sell page.
Authentication cookies: If you create an account or log in, our authentication provider (Supabase) sets secure session cookies to keep you logged in. These are strictly necessary for account functionality and are not used for tracking.
Essential cookies: We use minimal cookies necessary for site functionality, including language preference (English/Spanish) and cookie consent status. These are strictly necessary and cannot be disabled.
Local storage: We use your browser's localStorage to save learning progress, Daily Brief habit streaks, content reading history and save-for-later status, homepage brief preferences, resume-builder drafts (including profile fields, extracted resume text, and pasted job text), the website Career Case (full target text; exact requirement, proof, and source excerpts; complete interview answers; Stories; manager-confirmed wins; and resume variants), the Career Workspace guest or account-scoped browser cache, onboarding checklist progress and saved start date, saved directory segments and export filters, saved download or generator intents, guest- or account-scoped saved jobs and Following watchlist items, recently viewed FQHCs or pages, Team Readiness result snapshots and full reports, completion-record IDs, names entered in the browser, completion-record public-verification revocation keys, cookie consent preferences, analytics opt-out preferences, modal state, and temporary sync tokens. localStorage is ordinary browser storage and is not encrypted by this application. Saved jobs and Following keep guest and authenticated-account namespaces separate on the same browser; legacy unscoped or guest data is moved only through an explicit on-screen action. This data otherwise stays on your device unless you actively use a separately disclosed sync/save feature.
Resume print handoff: When you open Print Preview, the full reviewed resume is passed through that tab's sessionStorage rather than its URL. The print page reads and immediately removes the handoff key before validation or rendering, including for malformed content, so it can be consumed only once. The in-memory preview remains visible in that tab until it is refreshed or closed.
We do not use: Third-party advertising cookies, cross-site tracking pixels, social media tracking widgets, fingerprinting technologies, or any form of behavioral advertising technology.
We respect Global Privacy Control (GPC) and legacy Do Not Track (DNT) browser signals. When we detect either signal, no Google Analytics, Vercel Web Analytics, Vercel Speed Insights, or first-party product analytics tracking is initiated for that session. Under California law, GPC is a legally binding opt-out request — you do not need to do anything else if your browser sends it.
9. Children's Privacy
FQHC Talent is a professional career platform intended for adults (18 years of age and older). We do not knowingly collect personal information from children under 13 years of age as defined by the Children's Online Privacy Protection Act (COPPA), or from minors under 16 as defined by the CCPA.
If we discover that we have inadvertently collected information from a child under 13, we will promptly delete that information from our systems. If you believe that a child under 13 has provided us with personal information, please contact us at privacy@fqhctalent.com.
10. International Users
FQHC Talent is operated in the United States and is intended for users in the United States. Our servers and data storage are located in the United States.
If you access our platform from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States. By using our platform, you consent to this transfer. The data protection laws in the United States may differ from those in your country of residence.
11. Third-Party Links
Our platform may contain links to external websites, including FQHC careers pages, job application portals, and professional resources. These third-party sites have their own privacy policies, and we are not responsible for their content or data practices.
When you click a link to an external site, you are leaving FQHC Talent. We encourage you to review the privacy policy of any third-party site before providing your personal information.
12. Contact Us
FQHC Talent is operated by Mundos Vizinhos LLC, a California limited liability company doing business as FQHC Talent. Mundos Vizinhos LLC is the business that determines the purposes and means of processing the personal information described in this policy.
If you have questions about this Privacy Policy, want to exercise your data rights, or have a concern about how we handle your information, please contact us:
Mailing address: Mundos Vizinhos LLC, 2108 N St Ste N, Sacramento, CA 95816
Privacy requests: privacy@fqhctalent.com
Data deletion requests: /delete-data, the mobile app's You → "Delete my data" screen, or privacy@fqhctalent.com
General inquiries: info@fqhctalent.com
Please include "Privacy" in the subject line so we can route your request promptly. We aim to respond to all privacy-related inquiries within 10 business days.
13. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last updated" date at the top of this page.
For significant changes that affect how we use or share your personal information, we will make reasonable efforts to notify you in advance — for example, by posting a notice on our website or sending an email to the address associated with your account.
We encourage you to review this page periodically to stay informed about how we protect your information.
Questions About Your Privacy?
Your privacy matters to us. Don't hesitate to reach out with any questions or requests.
privacy@fqhctalent.com