Skip to main content
FQHC Talent

Privacy Policy

Last updated: September 20, 2026

FQHC Talent ("we," "us," or "our") operates the fqhctalent.com website. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our platform. We are committed to being transparent and direct about our data practices. Your trust matters to us, and we take reasonable steps to protect the information you share with us.

1. Information We Collect

Academy practice courses: Responses, assistance notes, reviews, revisions and changed-case attempts stay in the open course. Save locally stores a separate draft for each course and guest or signed-in account in ordinary, unencrypted browser localStorage. It does not send that draft to our server, an employer or AI. Saved work stays hidden until you choose Resume. Drafts last saved 30 or more days ago cannot be reopened; the original local data stays available for recovery download or deletion until you delete it or clear browser storage. Temporary recovery keeps unsaved course work in this tab when you navigate within the website; it remains hidden until you resume. Reloading, closing the tab or changing sign-in clears that temporary recovery. Close course clears the open work and its temporary recovery; the saved copy is separate. A sign-in change also clears visible work. Downloaded copies stay wherever you save them. Use the course case details and leave out patient, personnel and identifying information.

Academy Practice Studio preview: Fictional-case responses, plans, feedback notes, revisions and self-ratings stay in this tab. Temporary recovery can survive navigation within the website, but clears on reload, tab close or a change of sign-in state. Choosing Save stores a separate guest- or account-scoped draft in ordinary, unencrypted localStorage; it does not sync to our server, another device, an employer or AI. Saved drafts are hidden until you choose to open them. On opening the studio, drafts last saved 30 or more days ago cannot be reopened; their raw local data remains until you delete it or clear browser storage, and can be downloaded for recovery. Delete saved draft removes the stored copy, while Close and hide clears the current temporary session; neither deletes downloaded files. These controls are on the studio page. Do not enter patient, personnel, identifying or grievance information. Anyone with access to the browser profile can inspect ordinary local storage.

We collect the following categories of personal information when you use FQHC Talent:

Identifiers: Your name, email address, and optionally your organization and city/region. This is collected when you join the mobile beta, subscribe to a newsletter, request optional report updates, submit an intelligence tip or a leader-profile claim, or save your progress in a tool.

Professional information: Job titles, work history, employer names, education history, skills, EHR system experience, certifications, language abilities, and professional objectives. This is collected when you use our resume builder tool.

Resume files: If you upload a resume (PDF, DOCX, or TXT format) in the web resume builder, we parse it in memory to pre-fill your draft and do not retain the original uploaded file. Browser drafts are not server-persisted automatically. If you sign in and explicitly save, we store the reviewed profile fields, extracted resume text, and reflection summaries under your authenticated account; the resume email must match that account.

Website Career Case: The resume, interview, and First 90 Days engines share one browser-local Career Case. It can contain the full pasted target posting; exact requirement excerpts; proof and source excerpts; complete typed interview answers; Stories; manager-confirmed wins; and saved resume variants. These deterministic engines store those Career Case fields in ordinary, unencrypted localStorage and do not send them to our server or an AI service. Importing a resume file for deterministic parsing and choosing signed-in Save profile are separate actions that disclose the fields sent to our server. Anyone with access to the same browser profile may be able to read local content, so do not use these tools for sensitive content on a shared device.

Career Workspace: The Workspace stores job-target metadata, application stage and checklist state, artifact names/status, interview self-ratings and optional notes, offer and First 90 planning notes, goals, saved events, and Career Radar preferences. Signed-out data stays in ordinary, unencrypted localStorage. If you sign in, account-scoped Workspace data syncs to our database under your authenticated user ID; guest data is never merged unless you explicitly choose to merge it. The Workspace does not sync the full pasted posting, résumé or cover-letter text, complete interview answers, or Career Case evidence. Avoid sensitive notes on shared devices. If you enable Career Radar email, only the explicit target, goal, event, follow, role, location, and cadence fields needed to personalize delivery are copied into your newsletter preferences; we do not create an employability score or candidate ranking.

Website onboarding data: The onboarding planner stores checklist progress for each track, role, and audience plus your saved start date in ordinary, unencrypted localStorage. It stays in that browser and is not a credential, completion determination, readiness score, or server-synced employee record.

Role-description worksheet information: Organization name, role details, salary context, benefits, and screening prompts entered into the local worksheet. The worksheet is designed for your own ATS, careers page, or internal planning process; it does not publish roles on FQHC Talent.

Career reflection responses: Your answers to our Career Insights self-reflection questions and the resulting tool summaries. This helps provide planning content, compare role expectations, and prepare examples; it is not a credential or hiring assessment.

Manager and team planning data: If you use our Team Readiness or OKR planning tools, we may collect your responses, tool summaries, domain summaries, and session identifiers to provide planning content and track saved tool history over time. Team Readiness full reports are saved in your browser by default; if you are signed in, or if you explicitly save a browser result to your dashboard, the report may be linked to your account.

Optional AI-assisted OKR feedback: The OKR Capstone and OKR Team Readiness flows show a disclosure and require your explicit acknowledgment before an AI request. The Capstone request contains only the selected OKR domain, Objective text, and non-empty Key Result text. The Team Readiness request contains only each OKR domain, Objective text, and Key Result text; it excludes owner names, IDs, comments, separate metric/target metadata fields, and sprint identifiers. Any metric or target written inside Objective or Key Result text remains part of the text sent. Do not submit protected health information (PHI), patient data, personnel-sensitive information, or confidential strategy.

Newsletter subscription data: When you sign up for our newsletters (Intel Brief for FQHC leaders and/or The Pulse for job seekers), we collect your email address, audience preference, locale and signup source, and optionally your region, role type, primary challenge, organization size, and content preferences. Signup is single opt-in: submitting the form creates or updates the subscription in the same operation, with no confirmation email. The subscriber record labels this consent basis as a direct form submission; it is never labeled mailbox-verified. A form submission can never override a stronger prior signal: it does not clear the verified-deletion suppression value described below, and it does not reactivate an unsubscribed or bounced subscription — in those cases nothing changes. An internal request row is used to serialize and normalize the submission; its personal fields are minimized in the same operation, while its terminal non-PII lifecycle metadata is retained as described in Section 6. Current signup creates no mailbox-confirmation delivery attempt. During the recorded legacy grace window, late signed provider events may still be recorded for confirmation emails already sent by the legacy flow; those remaining confirmation-delivery events contain no recipient address and age out on the 30-day schedule described in the retention section. After signup, we track subscription status (active, bounced, or unsubscribed) and position in any automated email drip sequence.

Mobile beta waitlist data: When you request mobile app testing access, we temporarily store your normalized email, language, the fixed get-the-app request source, lifecycle timestamps, and SHA-256 hash of a random confirmation token. We send the raw token through our email provider; our database stores only its hash. Beta interest is a functional testing purpose and does not subscribe you to The Pulse or another newsletter. The optional Pulse checkbox starts unchecked and, only if selected, separately submits the current single opt-in newsletter signup: an eligible address is subscribed immediately with no Pulse confirmation email, while a prior unsubscribe, verified deletion, or bounce is not overridden. The beta request remains separate and still requires its own mailbox confirmation. An unconfirmed beta request expires after 72 hours; the next hourly privacy cleanup normally redacts every submitted field and token hash. Confirmation removes the confirmation hash, then retains your email, language, request source, confirmed time, and only a SHA-256 hash of a newly generated personal manage token. The raw manage token is returned once in the confirmation receipt and lets you immediately remove the active beta record; removal redacts the email, language, source, and both token fields.

Team brief request data: If you request a free team brief, we collect your email, organization, optional name, title, state or region, focus areas, notes you choose to share, and, when available, the saved homepage brief preference and Following watchlist included by the request form so the brief can be contextualized.

Learning and course progress: When you use our Academy courses (including the OKR Course), learning pathways, or interactive simulators while signed out, progress stays in a guest namespace in ordinary, unencrypted browser localStorage. When you are signed in, course progress is stored in a separate account namespace and synchronizes under your authenticated account so it can follow you across devices. Server-synced rows may contain your account ID and current account email, course or pathway ID, completed modules or steps, exercise scores, total XP, current position, saved capstone data, and last-active timestamps. Account progress is hidden while authentication is unresolved; changing accounts changes the visible namespace. Guest or older unassigned progress is never attributed to an account automatically: moving it requires an explicit one-time action, and a failed or unavailable server read is not treated as an empty account. You can use Academy while signed out without server sync.

Habit streaks: When you read the Daily Brief or use future habit loops, we may store a small streak record locally in your browser, including the habit ID, active dates, current streak, longest streak, and last active date. If you sign in, those streak records may sync to your account so your habit progress can follow you across devices.

Tool usage data: Unless you decline analytics, use of our interactive tools (simulators, OKR templates, resume builder, career reflection, learning pathways) may produce pseudonymous or aggregated usage events — such as which tool you used, which template you downloaded, or which simulator scenario you ran. This helps us understand which tools are most valuable so we can keep improving them. If you provide your email for a functional save or download, that requested record may be associated with your email whether or not you accept optional analytics. We may also record first-party product events for certain content or profile views unless you have refused analytics. These events are not sold, shared with advertisers, or used to evaluate users for employment outcomes.

Brief preference and feed interaction data: Unless you decline analytics, use of the homepage brief builder, filters, save/share controls, public directory export/download controls, source links, correction links, newsletter archive links, saved-job workspace, tool handoffs, or external job-application links may produce pseudonymous or aggregated product events such as selected state, selected role, filter used, item opened, source domain opened, correction form started, item saved, item shared, issue read, directory export opened/downloaded, saved-job stage changed, or employer ATS exit clicked. We do not collect resume text, application notes, correction text, or free-text field contents in these analytics events. These events are used to improve the usefulness and cadence of the site. They are not sold, shared with advertisers, or used to evaluate users for employment outcomes.

Feedback: If you use our feedback widget, we collect the page URL, feedback type, your message, and optionally your email address.

Newsletter engagement: Our email provider (Resend) notifies us when a newsletter we sent you is delivered, opened, clicked, suppressed, bounced, or reported. Each subscription carries a recorded consent basis — a direct form submission (whether recorded by the current single-opt-in signup or an earlier direct-submission form) or a mailbox confirmation — and no form-submission basis is ever labeled mailbox-verified. We always process eligible suppression, bounce, and complaint signals so unsafe future delivery stops; a suppression updates delivery status without creating a second recipient-linked engagement row. Other engagement events are stored only for mailbox-confirmed subscriptions (your email address, the email subject, and the clicked link path, if any) to understand which stories are useful. This engagement data stays in our systems and is not sent to Google Analytics or an advertising platform. After verified deletion, we retain only a secret-keyed HMAC suppression value—not the plaintext email—so delayed provider events cannot recreate deleted email data. Only a separately verified and reviewed mailbox-owner re-consent flow may clear it; the current signup form cannot.

Completion records: If you complete an Academy course and add a learner name, that name remains only in the guest- or account-scoped wallet in this browser and prints on the local view and PDF. We do not include the learner name in the public issuance request, and public verification is nameless and generic. It confirms a self-attested site completion record only; it is not a credential, license, accredited CE/CME, or hiring assessment. New records keep a holder-only revocation key in the same scoped browser wallet so that identity can remove public verification from the My Records page on that device. Guest records and names remain separate after sign-in unless you explicitly choose the one-time move into the current account; they are never automatically assigned to an account. For older records without a revocation key, email privacy@fqhctalent.com with the record ID for manual public-verification removal.

Mobile app data: If you use our mobile app and enable notifications, we store your device push token and notification preferences (a closed role ID, a state or named California region, and topics). Every push registration is bound to the stable, pseudonymous device-scoped ID used for signed mobile writes; the server stores only a hash of the device secret used for request signing and abuse prevention. Exact clinic identity and uncontrolled role or location text are not accepted in push registration. The in-app Delete my data flow selects the signed device ID—not a caller-supplied push token—and removes every push registration owned by that device plus its delivery de-duplication records. To prevent a signed request already in transit from recreating those deleted records, we retain only a SHA-256 digest of the device ID—never the raw ID or signing secret—as a deletion safety marker active for exactly 15 minutes. Registration and deletion check that marker under the same database lock; the next successful daily retention cleanup physically removes expired markers. Otherwise, inactive push registrations are retained for no more than 180 days and delivery de-duplication records for no more than 90 days. The app also can keep a server-side mirror of device-scoped favorites and watchlist items for that same signed installation; this device-bound identity is not an account and is not promised to follow an uninstall, reinstall, or different phone. These records contain item IDs and follow labels, not your name or email. Minimized first-party mobile product events are sent under the stable, pseudonymous device-scoped ID and may include an event name, time, app version, language, a parameter-free route family, and only the closed value required for that event—for example a setup goal, next-step type, practice mode, or a reviewed public signal's broad region, category, and impact. They do not include points, readiness, worker role, exact item, job, or reference IDs, application status, contact, résumé, interview, wage, private notes, or exact clinic context. Mobile product events are deleted through the in-app Delete my data flow and otherwise retained for no more than 24 months. Resume drafts, interview-practice notes, proof records, and generated documents otherwise stay in app-controlled storage on your device or browser. If you explicitly consent to résumé import, the selected file or pasted text is sent to FQHC Talent for deterministic parsing or OCR in memory; the original file is not retained. Interactive content requests send only the context needed to return the requested material—for example a selected interview role, first-90 role/situation, authored search query, or selected Today region—and do not include your résumé, proof records, or interview answer. Mobile résumé cloud save is currently unavailable, and its server endpoint does not read or persist submitted résumé/profile data. Cloud save will remain disabled until we can verify that the signed-in user or email owner is authorized to save the profile.

Mobile diagnostics, feedback, and support email: The app keeps a local error log and local performance marks on your device for troubleshooting. The error log leaves your device only if you choose to email it. The app sanitizes obvious contact strings, tokens, URLs with query strings, and sensitive resume/interview context keys before local storage and sanitizes stored entries again immediately before email export, including entries created by older app versions. If you choose Send feedback, Email support, or Send error log, your device mail app may include your sender address, display name, signature, and any message content you leave in the draft. These optional user-sent logs may be treated as Crash Data/Crash logs in app-store privacy forms. Local performance marks stay on your device and are not automatically collected unless we add a future telemetry service and update this policy and store answers first.

Browser alert data: If you enable web alerts from Following, we store a browser push endpoint, the cryptographic keys required by Web Push, your locale, and the FQHCs, regions, counties, or topics you chose to follow. This lets us notify that browser only when there are matching signals. No name or email is required for browser alerts.

Voice input: Our mobile app lets you speak instead of type. On iPhone/iPad, speech is transcribed on-device by Apple's on-device speech recognition. On Android, your device's built-in speech service (which may be provided by Google) processes the audio under your device maker's policy. We do not record, store, or transmit your voice to our servers — we receive only the resulting text you choose to keep.

Account information: If you create an account using our authentication system (passwordless email link, email/password, or a configured OAuth provider), we store your user ID, display name, professional role, organization, region, and onboarding status. Supabase manages authentication tokens and session cookies.

Content reading progress: When you view, mark as read, or save content for later while signed out, we store a small reading-history record in your browser's localStorage so the site can remember useful content on that device. This local record includes content type, content ID, read/save status, progress, and last-read time. If you later sign in, those local records may sync into your account Library so your saved and read content follows you across devices. When you are logged in, we store reading progress in your account. You can manage account reading history in your dashboard, clear local-only reading history through your browser storage controls, or request deletion of synced account data.

Saved jobs and Following ownership: New signed-out saved jobs, application notes, and watchlist follows are stored in a browser guest scope. Signed-in browser caches are separately namespaced by authenticated user ID and sync only with that user's account rows. While authentication is unresolved, these stores remain masked. Changing from account A to account B or signing out changes the visible namespace; one account's browser cache is not displayed or merged into another account or the guest space. Older unscoped browser data and guest data found after sign-in stay hidden until you explicitly move them into the current account or discard them. Clearing the current list deletes only the current guest/account namespace and, when signed in, that account's matching server rows.

Usage data: Analytics runs unless you refuse it — by choosing Decline in the cookie notice, saving an opt-out, or sending Global Privacy Control or Do Not Track. Unless you have refused, we use Google Analytics 4 to collect pseudonymous and aggregated information about how visitors interact with our site, including pages visited, time on site, general geographic region, device type, referral source, and first-party analytics identifiers such as client IDs. We also use Vercel Web Analytics for anonymous aggregate page-view data and Vercel Speed Insights for anonymous real-user Web Vitals and performance data. We do not send these analytics providers your name, email address, resume content, or career-tool responses.

Technical data: IP addresses are temporarily processed for rate limiting and abuse prevention. We do not associate IP addresses with your profile. If you submit a data-deletion request, we store a limited request audit log with IP address and user-agent so we can verify, troubleshoot, and document the privacy request.

2. How We Use Your Information

We use the information we collect for these specific purposes:

Career tools and resources: To provide free career tools, aggregated job postings, salary intelligence, and strategic resources for community health professionals exploring opportunities at Federally Qualified Health Centers (FQHCs) across the United States.

Resume generation: To generate a formatted resume document (PDF) based on the information you provide in our resume builder. The resume is generated locally in your browser — your resume PDF is not stored on our servers.

Newsletter delivery: To send you our newsletter publications based on your subscription preferences. We operate two newsletter tracks: Intel Brief (strategic intelligence for FQHC leaders) and The Pulse (career updates for job seekers). We may also send you a short automated welcome sequence (drip emails) over 2-3 weeks after you subscribe to help you get the most value from the platform. Every email includes a one-click unsubscribe link.

Mobile beta testing: To verify that the mailbox owner requested app testing access, send real iOS or Android testing invitations and functional beta notices when available, and provide a personal removal link. This purpose is separate from newsletter delivery and does not promise a testing date.

Team brief requests: To prepare and follow up about the free brief you requested, using the organization, state or region, focus areas, notes, saved brief preference, and Following watchlist you provided through the request form.

Academy and learning tools: To provide interactive courses, simulators, educational content, and habit loops through our FQHC Academy and Daily Brief. Signed-out Academy progress is tracked in the guest browser namespace. Signed-in course progress synchronizes under the authenticated account so it can resume across devices; guest progress moves only through an explicit one-time action. Team Readiness reports are browser-local by default and are stored server-side only through a disclosed account or email save. Reflection and planning outputs from tools like Career Insights and Team Readiness may be stored to provide saved summaries and selected follow-up content.

Optional AI-assisted OKR feedback: After you acknowledge the in-product disclosure and request feedback, we process the minimized OKR fields listed in Section 1 solely to generate the critique or readiness assessment you requested. The endpoint uses FQHC Talent's deterministic rules-based review when the Anthropic integration is not configured or available.

Tool improvement: To understand which tools, templates, and features are most used and most valuable. We analyze pseudonymous or aggregated tool usage patterns (such as: which OKR templates are downloaded most, which simulator scenarios are run most often) to prioritize improvements. When a pattern is tied to an email or account because you asked us to save or sync something, we use it to support that feature and improve reliability, not for advertising or employment evaluation.

Requested functional communications: To send confirmations, alerts, testing notices, report or team-brief follow-up, and other delivery you explicitly request. Newsletter marketing, career updates, and welcome sequences are sent only under the separate newsletter subscription described above.

Submission notifications: To notify our team when someone submits a form (an intelligence tip, a feedback message, a leader-profile claim) so we can review and respond.

Platform improvement: To understand how people use our site so we can make it more helpful. We analyze aggregated usage patterns, not individual behavior.

Abuse prevention: To enforce rate limits and prevent spam or automated abuse of our forms.

3. Information Sharing and Disclosure

We do not sell your personal information. We have never sold personal information, and we have no plans to do so.

We do not share your data with advertisers, data brokers, or any third parties for marketing purposes.

We do not provide your career-tool profile to organizations for employment evaluation. The information you provide through our career tools (resume builder, reflection tools) is used solely to generate your career documents, self-reflection summaries, and planning content. Your data stays with you.

We use the following third-party service providers to operate our platform. These providers process data on our behalf and are contractually obligated to protect it:

Supabase: Database hosting and limited private file storage (servers located in the United States). Stores profile information you choose to submit, saved-account records, and legacy private files if they exist.

Resend: Email delivery service. Processes your email address and name to send confirmation and notification emails.

Upstash: Redis-backed abuse prevention. Processes short-lived IP-based rate-limit keys and, for newsletter signup and mobile beta requests, a truncated selector derived from a secret-keyed email HMAC rather than the plaintext email. Newsletter activation fails closed before subscription mutation if the shared Upstash limiter is unavailable; other eligible routes may temporarily use server memory instead.

Vercel: Website hosting, server-side processing, Web Analytics, and Speed Insights. Only when analytics has not been refused, after trusted human input, and only on our canonical production domains, Vercel Web Analytics may receive an event timestamp, path and dynamic route, referrer, general geolocation, browser/OS/device type, and script version for anonymous aggregate reporting. Vercel says its request-derived visitor hash is not tied to an individual or IP address and is discarded after 24 hours. Speed Insights may receive route and path, network class, browser, device/OS, country, Web Vital and attribution, SDK version, and server-received time. The application removes query strings and fragments before either collector transmits, and Speed Insights samples 50% of eligible traffic. These collectors do not load on preview/local hosts or when analytics is declined or blocked by GPC, DNT, or another saved browser opt-out.

Anthropic (Claude API): Only after you explicitly acknowledge the in-product disclosure and request optional AI feedback in the OKR Capstone or Team Readiness flow, we may send the minimized OKR fields listed in Section 1 to generate the requested critique or readiness assessment. The two OKR AI endpoints do not write the submitted text or Claude output to FQHC Talent's application database or application logs. Provider-side handling is governed by the applicable Anthropic API agreement; this policy does not promise a specific provider-side retention period or model-use treatment.

Google Analytics 4: Pseudonymous and aggregated website analytics. It runs unless you refuse it. Only when the audited GA Admin safety gate is open may it collect usage data via first-party cookies; it is not loaded when you decline analytics, opt out, or send a recognized browser opt-out signal. We do not send Google Analytics your name, email, resume content, or career-tool responses. Analytics data may be shared across our domains (fqhctalent.com and healthcaretalent.org) for a unified understanding of site usage.

Cloudflare: DNS and email routing services. Processes domain-level traffic and routes incoming emails to our team.

Mobile push delivery (Expo, with Apple Push Notification service and Firebase Cloud Messaging): If you use our mobile app and opt into notifications, a device push token is sent to these services to deliver the alerts you requested. No name or email is associated with the push token unless you separately choose an account or email-backed feature, and the token is used only for requested alerts.

Browser push delivery (standard Web Push through your browser vendor's push service): If you enable web alerts, your browser push endpoint is used to deliver the alerts you requested. No name or email is associated with the browser endpoint.

For more information about how our service providers handle your data, you can review their respective privacy policies: Supabase (supabase.com/privacy), Resend (resend.com/legal/privacy-policy), Upstash (upstash.com), Vercel (vercel.com/legal/privacy-policy), Anthropic (anthropic.com/legal/privacy), Cloudflare (cloudflare.com/privacypolicy), Expo (expo.dev/privacy), and Google Analytics (policies.google.com/privacy). Browser push delivery is also subject to your browser vendor's privacy policy.

We may disclose your information if required by law — for example, in response to a valid court order, subpoena, or government request — or if we believe disclosure is necessary to protect the safety of our users, the public, or our platform.

4. Your Rights Under California Law (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give you specific rights regarding your personal information:

Right to know: You can request that we disclose what personal information we have collected about you, the categories of sources, the purpose for collecting it, and the categories of third parties we have shared it with.

Right to delete: You can request that we delete the personal information we have collected from you. Upon receiving a verified request, we will delete your information from our systems within 45 days, except where we are required by law to retain it. You can start a deletion request at /delete-data or directly in our mobile app (You → "Delete my data"). The mobile flow wipes data stored on your device and sends an email-verified request to delete server-side records tied to that email, including mobile beta interest, newsletter, résumé, saved tool, course-progress, submission, feedback, request, and matching account data where present.

Right to correct: You can request that we correct inaccurate personal information we have about you.

Right to opt out of sale or sharing: We do not sell your personal information. As described in Section 5, our use of Google Analytics may qualify as "sharing" under the CCPA/CPRA, and you can opt out at any time via /do-not-sell, the Global Privacy Control signal, or email.

Right to non-discrimination: We will not discriminate against you for exercising any of your privacy rights. You will receive the same quality of service regardless of whether you exercise your rights.

Right to limit use of sensitive personal information: We do not intentionally request sensitive personal information as defined by the CPRA. Please avoid adding sensitive details to resumes, profiles, or free-text fields unless they are necessary for the feature you are using. If you choose to include sensitive information in a resume, profile, message, or other free-text submission, we process it only to provide the requested feature, protect the service, and honor deletion, correction, and privacy-rights requests.

To exercise any of these rights, email us at privacy@fqhctalent.com with the subject line "Privacy Rights Request." We will verify your identity by confirming the email address associated with your account. We will respond to your request within 45 days as required by California law. You may also designate an authorized agent to make a request on your behalf.

5. Do Not Sell or Share My Personal Information

We do not sell your personal information for money. We do not participate in data broker networks, run targeted ad campaigns, or build advertising profiles.

However, under California law (CCPA/CPRA), our use of Google Analytics may qualify as "sharing" personal information for cross-context behavioral advertising. To opt out, visit /do-not-sell for our full opt-out page, or email privacy@fqhctalent.com.

Automated signals we honor: We respect the Global Privacy Control (GPC) header that browsers and extensions can send on your behalf. California law (§ 1798.135(b)) treats GPC as a legally valid opt-out request. When we detect GPC, we do not load Google Analytics, Vercel Web Analytics, or Vercel Speed Insights, and we do not record first-party product analytics events for that session. We also honor the legacy Do Not Track (DNT) browser signal.

If our practices ever change, we will update this policy and provide you with the opportunity to opt out before any sale or sharing occurs.

6. Data Retention

We retain your personal information only as long as necessary for the purposes described in this policy:

Profiles and saved tool data: Retained for as long as you wish to keep using the platform. You may request deletion at any time.

Resume builder: Original resume uploads in the web builder are parsed in memory and are not retained. Saved resume profile fields, extracted resume text, and reflection summaries are retained for as long as your profile exists. Legacy uploaded resume files tied to a saved profile, if any, are deleted when you request profile deletion.

Browser-local career retention: The website Career Case is physically deleted from localStorage 30 days after its last saved activity. If active data is corrupt or from a future schema, that blocked raw data and its recovery copy are physically deleted 30 days after first detection; repeated loads do not restart that period. Onboarding checklist progress and the saved onboarding start date are each physically deleted 30 days after their last saved change. The separate resume-builder draft is physically deleted after 7 days. Every website page checks at startup, every 60 seconds while open, and when the page becomes visible or focused again. A closed browser cannot execute deletion at the deadline, so expired content is deleted on the next visit to the website. The footer's Career data control lets you delete the Career Case, recovery copies, resume draft, onboarding progress, and saved start date immediately.

Newsletter requests and subscriptions: Signup is single opt-in — submitting the form atomically activates an eligible subscription and minimizes the personal fields in its internal request row in the same operation. A current failed submit rolls back rather than leaving a pending request. Only a mailbox-confirmation request created by the pre-cutover flow around the recorded routing cutover can remain pending, and it may remain usable for up to 72 hours after creation. The owner deployment receipt records the routing cutover UTC, the verified last legacy-request creation bound from two post-drain aggregate reads, and the legacy grace-end UTC 72 hours after that bound (or after the routing cutover if no legacy request exists). The next hourly privacy cleanup normally minimizes every submitted field and both request credentials after expiry — 72 hours is the legacy confirmation deadline, not a guaranteed cleanup timestamp. Legacy confirmation endpoints accept only those already-pending links; current forms do not create new confirmation requests or links. Current signup creates no confirmation-delivery attempt. During the legacy grace window, late signed delivery events may still be recorded for already-sent legacy requests; any remaining events are deleted after 30 days. A verified deletion while a legacy request is pending deletes that request and any attached delivery events. After activation or expiry, the terminal request row is retained as non-PII lifecycle metadata unless a covered deletion removes it; its submitted personal fields, confirmation credentials, and direct recipient selectors are minimized. That terminal request row does not currently age out automatically. Only confirmation-delivery events age out after 30 days. Subscriber email and preferences are retained while the subscription record exists. When you unsubscribe, we set the status to "unsubscribed" to prevent further sends, and the signup form cannot reverse that. You may request deletion of the plaintext subscriber, pending-request, and engagement records at any time. Verified deletion keeps only a secret-keyed HMAC suppression tombstone with no plaintext email so an at-least-once provider webhook cannot recreate deleted email data. Only a separately verified and reviewed mailbox-owner re-consent flow may clear that tombstone; the current signup form cannot.

A legacy newsletter confirmation cannot reactivate a subscription or clear its suppression tombstone while a verified deletion is still in progress.

Mobile beta requests: A pending request expires after 72 hours. The next hourly privacy cleanup normally redacts its email, language, fixed source, and hashed confirmation token; 72 hours is the confirmation deadline, not a guaranteed cleanup timestamp. Confirmed beta interest retains the email, language, fixed source, confirmation time, and hashed manage token only while the active record exists. Using the personal removal link immediately redacts those fields. The general /delete-data flow also covers pending and confirmed mobile beta records.

Browser alert subscriptions: Browser push endpoints and watch preferences are retained while the alert subscription is active. When you turn off browser alerts from Following, or when the browser endpoint expires or returns an unavailable response, we mark the subscription inactive. If you revoke notification permission in browser settings, delivery should stop in that browser; our server record is updated when you use the off button or when the browser push service reports the endpoint is no longer available. Web push sent logs are retained for deduplication and delivery troubleshooting.

Content-read deletion safety: When you delete a synced reading-history or save-for-later item, we keep a minimal marker containing your account UUID, a SHA-256 item selector derived from that account UUID plus the canonical content type and content ID, and the deletion time. We use it only to prevent stale automatic, account-transfer, guest-transfer, or cache-replay writes from restoring content you deleted. A later-arriving explicit save is intentionally treated as a new restore according to the authoritative database receipt time, even if its client timestamp predates the deletion. The marker does not contain the content type or content ID in readable form, has no fixed TTL, and remains until that later explicit, accepted save supersedes it, or until the account is deleted. A separate global rollout singleton is non-user operational state: it contains only a fixed protocol label, a SHA-256 fingerprint of the installed database routines, and database cutover timestamps; it is not account activity or reading history and is not removed when an account is deleted.

Reflection and course data: Career reflection summaries, Team Readiness planning outputs, and other tool-generated data are retained as long as your profile exists. Guest- and account-scoped course progress and Team Readiness reports stored in your browser persist until you clear the matching browser data. Server-synced course progress is retained while the account or functional email save exists and is covered by verified data deletion; deleting an authenticated account removes course-progress rows owned by that account. Account-linked Team Readiness report history is retained until you request deletion.

Optional AI-assisted OKR requests: The OKR AI endpoints do not write submitted text or Claude output to FQHC Talent's application database or application logs. Provider-side handling follows the applicable Anthropic API agreement; we do not make a provider-side retention or model-use guarantee here. Separately saved course progress or Team Readiness reports follow the retention rules above.

Tool and product usage events: Pseudonymous or aggregated tool usage and product interaction data (which tools, templates, filters, state/role brief preferences, saved/shared items, source domains opened, correction starts, saved-job stages, external job-application exits, or newsletter issues you used) is retained for up to 24 months for product improvement analytics only when GPC/DNT, browser opt-out, or analytics-decline signals are not present. If you provided your email with a functional tool record, you may request deletion at any time.

Mobile diagnostics: Local error logs and local performance marks are retained on your device until you clear them or clear app data. User-sent support error logs are retained in our support inbox only as long as needed to troubleshoot and then deleted during routine support cleanup.

Feedback submissions: Feedback you submit through our feedback widget is retained indefinitely to help us improve the platform. If you included your email, you may request deletion.

Email communications: Transactional email logs (confirmations, notifications, newsletter sends) are retained by our email provider (Resend) for up to 30 days for delivery troubleshooting. We also maintain an internal log of newsletter sends (date, recipient count, track) for operational purposes.

Analytics data: Google Analytics event data is currently configured for two months of retention in pseudonymous and aggregated form. On our current Vercel Pro plan, the Web Analytics reporting window is 12 months and the Speed Insights reporting window is 30 days. Those Vercel windows describe how long reports remain available to us, not guaranteed deletion deadlines for underlying provider records; Vercel handles any additional retention under its privacy policy and our service terms. We use analytics to understand product patterns, not to make employment or user-evaluation decisions.

Rate limiting data: IP-based keys and, for newsletter signup and mobile beta requests, truncated selectors derived from a secret-keyed email HMAC are held in Upstash Redis for their configured request windows—normally minutes and up to one hour for the per-address limits. No plaintext email address is used as a rate-limit key. Newsletter activation fails closed before subscription mutation if the shared limiter is unavailable; other eligible routes may temporarily use server memory instead. A data-deletion confirmation request is usable for 24 hours. If it is not confirmed, the next hourly privacy cleanup normally redacts its email, token, IP address, and user-agent; 24 hours is the confirmation deadline, not a guaranteed cleanup timestamp. The minimized non-PII audit row is deleted after 90 days. A successful confirmation immediately redacts those fields from every matching request row. Other rate-limiting data is not written to an application database.

If you request deletion of your account and data, we will remove covered plaintext information from our active databases within 45 days. The HMAC-only email suppression tombstone described above is retained without the plaintext address to enforce the deletion against delayed delivery events. Some information may persist in encrypted backups for up to 90 days before being permanently deleted, and provider-held delivery logs follow the provider retention described above.

7. Data Security

We take the security of your personal information seriously and implement the following measures:

All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.

Our database uses row-level security policies to restrict access. API routes that handle your data use a secure server-side key that is never exposed to browsers.

Form inputs are validated and sanitized on both the client and server to prevent injection attacks.

We apply rate limiting and other abuse controls to form endpoints based on the risk and protocol requirements of each endpoint.

Security headers are configured on all pages (including protections against clickjacking, content sniffing, and cross-site scripting).

Access to our production database and hosting infrastructure is restricted to authorized personnel only.

While no system is 100% secure, we take reasonable and appropriate measures to protect your data from unauthorized access, loss, misuse, or alteration. If we become aware of a data breach that triggers a legal notice obligation, we will notify affected users and appropriate authorities as required by applicable law, including California Civil Code § 1798.82 where it applies.

8. Cookies and Tracking Technologies

We use the following cookies and tracking technologies:

Vercel Web Analytics and Speed Insights: Their first-party scripts do not load when you decline. After trusted human input, they may load only on our canonical production domains when analytics is not blocked by GPC, DNT, or another saved browser opt-out. Web Analytics does not use third-party cookies; Vercel derives a request hash for anonymous aggregate page views and says the visitor-session state is discarded after 24 hours. Speed Insights reads browser performance APIs to report sampled real-user Web Vitals. Before transmission, our application removes query strings and fragments; preview and local traffic are excluded, and Speed Insights samples 50% of eligible production traffic.

Google Analytics 4: It runs unless you refuse it. When the audited GA Admin safety gate has been verified, it may load only after trusted human input. It does not load when you decline analytics, opt out, send GPC/DNT, or while that safety gate remains closed. It uses first-party cookies to collect pseudonymous usage statistics and client identifiers. These cookies are not used by us for advertising. You can opt out at the browser level by installing the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout), enabling Global Privacy Control in your browser, using the cookie notice's Decline control, or visiting our /do-not-sell page.

Authentication cookies: If you create an account or log in, our authentication provider (Supabase) sets secure session cookies to keep you logged in. These are strictly necessary for account functionality and are not used for tracking.

Essential cookies: We use minimal cookies necessary for site functionality, including language preference (English/Spanish) and cookie consent status. These are strictly necessary and cannot be disabled.

Local storage: We use your browser's localStorage to save guest- or account-scoped Academy course and pathway progress, Daily Brief habit streaks, content reading history and save-for-later status, homepage brief preferences, resume-builder drafts (including profile fields, extracted resume text, and pasted job text), the website Career Case (full target text; exact requirement, proof, and source excerpts; complete interview answers; Stories; manager-confirmed wins; and resume variants), the Career Workspace guest or account-scoped browser cache, onboarding checklist progress and saved start date, saved directory segments and export filters, saved download or generator intents, guest- or account-scoped saved jobs and Following watchlist items, recently viewed FQHCs or pages, Team Readiness result snapshots and full reports, guest- or account-scoped completion-record IDs, browser-local learner names, completion-record public-verification revocation keys, cookie consent preferences, analytics opt-out preferences, modal state, and temporary sync tokens. localStorage is ordinary browser storage and is not encrypted by this application. Academy progress, saved jobs, Following, and completion-record wallets keep guest and authenticated-account namespaces separate on the same browser; legacy unscoped or guest data is moved only through an explicit on-screen action. This data otherwise stays on your device unless you use a separately disclosed account sync/save feature.

Resume print handoff: When you open Print Preview, the full reviewed resume is passed through that tab's sessionStorage rather than its URL. The print page reads and immediately removes the handoff key before validation or rendering, including for malformed content, so it can be consumed only once. The in-memory preview remains visible in that tab until it is refreshed or closed.

We do not use: Third-party advertising cookies, cross-site tracking pixels, social media tracking widgets, fingerprinting technologies, or any form of behavioral advertising technology.

We respect Global Privacy Control (GPC) and legacy Do Not Track (DNT) browser signals. When we detect either signal, no Google Analytics, Vercel Web Analytics, Vercel Speed Insights, or first-party product analytics tracking is initiated for that session. Under California law, GPC is a legally binding opt-out request — you do not need to do anything else if your browser sends it.

9. Children's Privacy

FQHC Talent is a professional career platform intended for adults (18 years of age and older). We do not knowingly collect personal information from children under 13 years of age as defined by the Children's Online Privacy Protection Act (COPPA), or from minors under 16 as defined by the CCPA.

If we discover that we have inadvertently collected information from a child under 13, we will promptly delete that information from our systems. If you believe that a child under 13 has provided us with personal information, please contact us at privacy@fqhctalent.com.

10. International Users

FQHC Talent is operated in the United States and is intended for users in the United States. Our servers and data storage are located in the United States.

If you access our platform from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States. By using our platform, you consent to this transfer. The data protection laws in the United States may differ from those in your country of residence.

11. Third-Party Links

Our platform may contain links to external websites, including FQHC careers pages, job application portals, and professional resources. These third-party sites have their own privacy policies, and we are not responsible for their content or data practices.

When you click a link to an external site, you are leaving FQHC Talent. We encourage you to review the privacy policy of any third-party site before providing your personal information.

12. Contact Us

FQHC Talent is operated by Mundos Vizinhos LLC, a California limited liability company doing business as FQHC Talent. Mundos Vizinhos LLC is the business that determines the purposes and means of processing the personal information described in this policy.

If you have questions about this Privacy Policy, want to exercise your data rights, or have a concern about how we handle your information, please contact us:

Mailing address: Mundos Vizinhos LLC, 2108 N St Ste N, Sacramento, CA 95816

Privacy requests: privacy@fqhctalent.com

Data deletion requests: /delete-data, the mobile app's You → "Delete my data" screen, or privacy@fqhctalent.com

General inquiries: info@fqhctalent.com

Please include "Privacy" in the subject line so we can route your request promptly. We aim to respond to all privacy-related inquiries within 10 business days.

13. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last updated" date at the top of this page.

For significant changes that affect how we use or share your personal information, we will make reasonable efforts to notify you in advance — for example, by posting a notice on our website or sending an email to the address associated with your account.

We encourage you to review this page periodically to stay informed about how we protect your information.

Questions About Your Privacy?

Your privacy matters to us. Don't hesitate to reach out with any questions or requests.

privacy@fqhctalent.com

Cookie notice

We use Google Analytics, Vercel Web Analytics, and Vercel Speed Insights to improve the site. Select Decline to turn them off in this browser. We honor GPC and Do Not Track.

Read our Privacy Policy.