Privacy Policy
Effective February 21, 2026 · Version 1.0
This document explains what data Fynd collects, why we collect it, who we share it with, how long we keep it, and the controls you have. It applies to the Fynd web application at https://fynd.llc and the Fynd mobile apps that connect to the same backend.
§1Who we are
“Fynd” is the product name of the consent-first job-application platform operated by Purpose Healthcare Labs (the “Operator”). The Operator is the data controller for the personal data described below. You can reach the Operator at privacy@fynd.llc.
§2Scope of this policy
This policy covers personal data you provide directly to Fynd, data generated by your use of Fynd (application receipts, drafts, audit trails), and data received from third-party sign-in providers you choose to link (Google, Apple).
It does not cover the practices of employers you apply to through Fynd, or of any external site you navigate to from a job link.
§3What data we collect
We only collect data that maps to a service you have explicitly consented to.
- Account identity. Email address, display name, hashed password (bcrypt), and any linked third-party identity records (Google subject id, Apple user id) — collected only if you sign in with the corresponding provider.
- Career Passport. Résumé content, skill claims, project descriptions, education/employment history — only the values you explicitly enter or approve.
- Preferences & eligibility signals. Locations, seniority range, work authorization, salary expectations, deal-breakers — used to score your Opportunity Feed.
- Application activity. Jobs you import, resumes and cover letters you draft in-app, approvals you record, submission receipts, interview notes.
- Consent & audit trail. Every consent grant, revocation, and material action against your account is timestamped and stored so we — and you — can inspect the history of any release.
- Notification subscriptions. If you opt in to Web Push, we store your browser’s VAPID push subscription; if you opt in to SMS OTP, we store your phone number for the sole purpose of delivering the OTP code.
- Billing (only if you subscribe). Subscription plan, coupon usage, and Stripe customer/session ids. Fynd does not store full card numbers; card processing is handled entirely by Stripe.
- Technical telemetry. Request-scoped diagnostics (route, response code, latency, session id) required to run the service. We do not load third-party analytics trackers or advertising SDKs.
§4Why we collect it — the consent scopes
Every data category above is bound to at least one of the five consent scopes you accept at signup. You can revoke any non-required scope at any time from the authenticated /privacy console; revocation stops future processing under that scope immediately.
process_career_data(required) — lets Fynd process the résumé data, claims, and projects you approve so that you can build a verified Career Passport. Without this scope Fynd cannot function; declining it prevents account creation.discover_jobs— lets Fynd discover job openings that match your approved Passport.generate_materials— lets Fynd help you draft résumés and cover letters that are grounded strictly in your approved Passport. Every draft is reviewed by you before it leaves your account. Fynd never fabricates claims.track_applications— records the status of applications you explicitly submit so you can see the pipeline in one place.email_me— allows periodic email updates about relevant opportunities and account changes.
§5Legal basis for processing
Where GDPR applies, our legal basis for every category above is your freely given, specific, informed, and unambiguous consent (Article 6(1)(a) GDPR), captured at signup and re-affirmed each time the policy text version changes. Where you sign a Stripe checkout, the legal basis for processing your payment information is performance of a contract (Article 6(1)(b) GDPR).
§6Who we share data with
Fynd only releases data to a third party when the release is:
- necessary to deliver a scope you have consented to, and
- logged in your data-release audit trail with a materials hash you can inspect.
The categories of recipients are:
- Employers — receive the exact application materials (résumé, cover letter, screener answers) you explicitly approve for each submission. Fynd never sends materials without your click-through approval on a per-application basis.
- Stripe — processes subscription payments; receives your email and billing metadata. See stripe.com/privacy.
- Emergent Google Sign-In — if you sign in with Google, Emergent’s managed OAuth service handles the OAuth handshake. Fynd never sees your Google password. See emergent.sh/privacy.
- Apple — if you sign in with Apple, Apple handles the OIDC handshake. Fynd receives the pseudonymous Apple user id and, if you allow it, your email relay.
- Twilio — if you enable phone sign-in, Twilio Verify delivers your OTP code. Twilio receives only the phone number and the verification challenge.
- Push service providers — if you enable Web Push, your browser vendor’s push service (Apple, Google, Mozilla) receives the encrypted notification payload for delivery to your device.
Fynd does not sell personal data, does not share personal data with advertising networks, and does not permit third parties to derive their own profiles of you from your Fynd data.
§7Your rights and controls
You can exercise all of the following from the authenticated /privacy console once you sign in:
- Access & portability. One-click JSON export of every record we hold on you.
- Rectification. Edit your Passport, preferences, eligibility, and application drafts at any time.
- Erasure. Start a 30-day soft-delete window; sign in during that window to restore, or let it expire for permanent deletion. See the standalone Delete account guide for the exact in-app and email routes.
- Restriction & objection. Revoke any non-required consent scope; future processing under that scope stops immediately.
- Withdraw consent. Revocation is one click; historical audit rows are retained as legally required, but no further processing occurs under a revoked scope.
You may also contact us at privacy@fynd.llc to exercise any right. We respond within 30 days.
§8How long we keep data
- Active account: retained until you delete the account or a consent is revoked.
- Soft-deleted account: 30 days. During that window you can restore by signing in.
- Permanent deletion: after the 30-day window expires, all personal data associated with your account is erased from primary storage; audit-log entries required for legal defense are retained in pseudonymized form for up to 24 months.
- Application receipts & materials hashes: retained for 24 months after the submission so you can prove what was sent, then purged.
§9Security
Passwords are hashed with bcrypt at cost 12. Sessions are cookie-based, HttpOnly, Secure, SameSite=Lax, with a rotating CSRF token double-submit protection on all state-changing requests. All traffic between your browser or device and Fynd is served over HTTPS. Access to production data is limited to the Operator’s founding team under least-privilege discipline and every access is audited.
No system is impregnable. If we ever discover a breach that materially affects your data, we will notify you and (where required) the relevant regulator within 72 hours.
§10International transfers
Fynd’s primary infrastructure runs in United States data centers. If you access Fynd from outside the United States, your data will be transferred to and processed in the United States. Where required by GDPR, we rely on the European Commission’s Standard Contractual Clauses (2021/914) as the transfer mechanism.
§11Cookies and similar technologies
Fynd sets only the following cookies:
oppos_session— HttpOnly, Secure, SameSite=Lax. Session identifier. Required for you to be signed in.oppos_csrf— Secure, JS-readable. CSRF double-submit token. Required for state-changing requests.
Fynd does not load third-party tracking pixels, advertising tags, or web analytics scripts.
§12Changes to this policy
When we make a material change to this policy we bump the version string above and prompt you to accept the new version the next time you sign in. You will not be denied access to your data if you decline a new version — you can always export your data and delete your account. Non-material changes (typo fixes, formatting) do not bump the version.
Current version: 1.0. Effective: February 21, 2026.