← Fynd Delete account

Privacy Policy

Effective February 21, 2026 · Version 1.0

This document explains what data Fynd collects, why we collect it, who we share it with, how long we keep it, and the controls you have. It applies to the Fynd web application at https://fynd.llc and the Fynd mobile apps that connect to the same backend.

§1Who we are

“Fynd” is the product name of the consent-first job-application platform operated by Purpose Healthcare Labs (the “Operator”). The Operator is the data controller for the personal data described below. You can reach the Operator at privacy@fynd.llc.

§2Scope of this policy

This policy covers personal data you provide directly to Fynd, data generated by your use of Fynd (application receipts, drafts, audit trails), and data received from third-party sign-in providers you choose to link (Google, Apple).

It does not cover the practices of employers you apply to through Fynd, or of any external site you navigate to from a job link.

§3What data we collect

We only collect data that maps to a service you have explicitly consented to.

§4Why we collect it — the consent scopes

Every data category above is bound to at least one of the five consent scopes you accept at signup. You can revoke any non-required scope at any time from the authenticated /privacy console; revocation stops future processing under that scope immediately.

  1. process_career_data (required) — lets Fynd process the résumé data, claims, and projects you approve so that you can build a verified Career Passport. Without this scope Fynd cannot function; declining it prevents account creation.
  2. discover_jobs — lets Fynd discover job openings that match your approved Passport.
  3. generate_materials — lets Fynd help you draft résumés and cover letters that are grounded strictly in your approved Passport. Every draft is reviewed by you before it leaves your account. Fynd never fabricates claims.
  4. track_applications — records the status of applications you explicitly submit so you can see the pipeline in one place.
  5. email_me — allows periodic email updates about relevant opportunities and account changes.

Where GDPR applies, our legal basis for every category above is your freely given, specific, informed, and unambiguous consent (Article 6(1)(a) GDPR), captured at signup and re-affirmed each time the policy text version changes. Where you sign a Stripe checkout, the legal basis for processing your payment information is performance of a contract (Article 6(1)(b) GDPR).

§6Who we share data with

Fynd only releases data to a third party when the release is:

The categories of recipients are:

Fynd does not sell personal data, does not share personal data with advertising networks, and does not permit third parties to derive their own profiles of you from your Fynd data.

§7Your rights and controls

You can exercise all of the following from the authenticated /privacy console once you sign in:

You may also contact us at privacy@fynd.llc to exercise any right. We respond within 30 days.

§8How long we keep data

§9Security

Passwords are hashed with bcrypt at cost 12. Sessions are cookie-based, HttpOnly, Secure, SameSite=Lax, with a rotating CSRF token double-submit protection on all state-changing requests. All traffic between your browser or device and Fynd is served over HTTPS. Access to production data is limited to the Operator’s founding team under least-privilege discipline and every access is audited.

No system is impregnable. If we ever discover a breach that materially affects your data, we will notify you and (where required) the relevant regulator within 72 hours.

§10International transfers

Fynd’s primary infrastructure runs in United States data centers. If you access Fynd from outside the United States, your data will be transferred to and processed in the United States. Where required by GDPR, we rely on the European Commission’s Standard Contractual Clauses (2021/914) as the transfer mechanism.

§11Cookies and similar technologies

Fynd sets only the following cookies:

Fynd does not load third-party tracking pixels, advertising tags, or web analytics scripts.

§12Changes to this policy

When we make a material change to this policy we bump the version string above and prompt you to accept the new version the next time you sign in. You will not be denied access to your data if you decline a new version — you can always export your data and delete your account. Non-material changes (typo fixes, formatting) do not bump the version.

Current version: 1.0. Effective: February 21, 2026.