Privacy notice
Version: 2026-09-19.3. Check the home page for current service availability. Account and privacy support remain available.
Operator: Jeremy Fusilier, an individual operating in Florida. Contact for privacy requests or accessibility assistance: thefusiliercorporation@gmail.com.
What we collect and why
We use the following information to provide your account, answer questions, prevent abuse, and enforce usage limits. Choose a nickname. When email login is enabled, you can choose email and password or a passkey. Passkey-only accounts do not require email or password. We do not require a phone number, real name, date of birth, or payment details.
| Information | Use and retention |
|---|---|
| Nickname, account identifier, plan, state of residence, public-enrollment status, invitation hash if applicable, access status, and terms/age affirmation records | Account administration and eligibility, until account deletion. Acceptance records include policy version, time, and the operator/contact details shown at acceptance. They are not proof of identity or verified age. |
| Invitation hash, approved state, expiry, redemption time, revocation flag | If invitation-only access is used, these records enforce single-use invitations and eligibility. Public signup does not collect an invitation. Invitation-table records expire about 35 days after the invitation expiry date. No recipient email or name is stored in that table. The linked hash remains in an active account until deletion. Unlinked aggregate enrollment totals remain to enforce the beta cap. |
| Passkey public keys and counters; a one-way recovery-code hash | Authenticate your account until deletion or replacement. We never receive your device biometrics or passkey private key. |
| Optional email-login credentials and provider account identifier | Email and password pass through our Cloudflare Worker over encrypted connections to Google Firebase Authentication. We do not save passwords, email addresses, or Firebase ID/refresh tokens in the application database or application logs. Firebase stores authentication information to provide login, verification and recovery. Our database links its account identifier to your account until deletion. Email is used for account access and service support, not mailing-list enrollment or advertising. |
| Pending email setup and deletion records | Setup records contain a provider identifier, purpose, eligibility/acceptance version, timestamps, and nickname or existing account link, but no email or password. Setup expires after 24 hours. Daily maintenance then requests removal of unfinished Firebase accounts. A separate provider identifier and start time track account creation while it is in progress or its outcome is uncertain. These minimal records can remain beyond setup expiry until the outcome is reconciled, including through operator review. Failed external deletion is retried; a minimal provider identifier and retry metadata remain until deletion is confirmed and any uncertain creation is resolved. Failures or a backlog can delay removal and require operator intervention. |
| Session and sign-in challenge records | Keep you signed in for up to 7 days. Challenges expire in 5 minutes. Expired records are removed during daily maintenance. |
| Monthly question counts | Enforce allowances. Retained for roughly 100–131 days, unless you delete your account sooner. |
| Request identifier, time, status, account identifier and estimated compute reservation | Prevent duplicate charges, reserve daily service capacity and handle failed requests. Removed after about 35 days during daily maintenance. |
| Salted one-way network/account identifiers and attempt counts | Prevent abuse. Kept for no more than roughly 3 days. Raw IP addresses are not saved in our application database. |
| History-saving preference and preference-change counter | Off by default. Retained until account deletion. Changes prevent in-progress requests from saving after you turn saving off or delete history. |
| Personalized-question consent state and the last 50 changes | Off by default, including for existing accounts when this choice is introduced. We retain the current choice, consent version, change counter and time, plus up to 50 changes recording those details and the accepted policy version. These account-linked records demonstrate and enforce your choices; they contain no question text or sensitive traits. They are included in account export and removed on account deletion. |
| Optional saved questions and answers, entry identifiers and timestamps | Only successful answers generated while saving is enabled are saved. Up to 50 pairs per account, accessible for up to 30 days from creation; older entries may be removed sooner to enforce the cap. Expired entries stop being accessible immediately and are removed from the active database during daily maintenance. If maintenance fails, physical removal can be delayed; the operator must investigate overdue cleanup. You can delete them sooner. |
Your questions and AI processing
Personalized questions require a separate, unchecked consent choice, not just acceptance of terms. Jeremy Fusilier and Cloudflare, our hosting, database and AI processor, process your question and recent current-tab context to screen it and provide career guidance. Depending on what you submit, this can include incidental relevant facts about health or disability, race or ethnicity, religion, sex or gender, sexual orientation, or citizenship or immigration status. Health facts can include physical or mental health, pregnancy or other reproductive or sexual health circumstances, or health care you mention. Do not provide unnecessary sensitive details. The Consumer Health Data Privacy Notice explains health-related processing.
You can decline and use general career resources without an account or this consent. Personalized free-text questions are unavailable without the choice because the service must process the text to screen and answer it. Consent does not enable History or authorize advertising, data sale or model training. Account and privacy rights remain available if you decline or withdraw.
Basic browser screening runs before submission. Detected restricted text is not submitted to our API by the normal interface. If submitted, the Worker also screens it before invoking the AI. Questions that pass are transmitted to Cloudflare Workers AI to produce a response. Screening is limited, especially for indirect wording and languages other than English, and does not guarantee removal of personal or sensitive data. Submitted text is processed even when we do not store it.
Follow-up questions include up to three recent question-and-answer pairs from the current browser tab, limited to 8 KB in total. That context is sent again to Cloudflare Workers AI with your new question and is screened again. Older pairs are dropped when the limit is reached. Current-tab context is held in page memory, not browser persistent storage, and is cleared on refresh, sign-out, closing the page, or New conversation. The AI may misunderstand or forget details. Saved account History is separate and is never automatically added to a new conversation.
Account History is optional and off by default. Turning it on saves future successful questions and answers, not earlier exchanges or withheld answers. Stored text is encrypted in our database using an application key held by the service. This is not end-to-end encryption: the service and authorized operator access can decrypt it to provide history and exports. Text is not written to application logs; we do not store text hashes or sensitive-topic screening histories. If a submitted question indicates the account holder is a minor, server screening can pause assistant access without storing that question or an age value.
Cloudflare processes network and security information to host and protect the service, including through Turnstile. Its handling is governed by the applicable Cloudflare terms, Data Processing Addendum and Privacy Policy. Cloudflare's Workers AI data usage documentation states that it does not use customer inputs and outputs to train models or improve its or third-party services without the customer's explicit consent. We do not authorize that use for your career conversations. Optional D1 History storage, backups and provider service/security records are separate from that training restriction. We do not represent this service as anonymous or promise that no provider ever processes or retains any data.
Do not include names, contact details, government identifiers, health or financial records, unnecessary sensitive details, confidential employer information, or personal information about someone else. Use redacted resume excerpts. We do not use your questions or answers to train an AI model or create advertising profiles. We do not intentionally build health or protected-trait profiles; an AI answer can nonetheless reflect or infer information from your text and may be wrong.
Cookies, tracking, and sharing
We use essential secure cookies to authenticate sessions and bind sign-in challenges. Turnstile processes security signals. There are no advertising cookies, marketing analytics, third-party fonts, or cross-site advertising integrations in this app. We do not sell personal data or share it for targeted advertising. Our behavior does not change when a browser sends Do Not Track or Global Privacy Control because those advertising uses are already disabled.
Cloudflare is our hosting, database, security, and AI service provider. It receives only the service data needed for those functions; optional History uses its D1 database. It is not an independent advertising recipient. Your browser also uses whichever passkey provider you choose. Disclosure for a legal obligation or security incident is limited to what applicable law permits or requires; it is not permission for a new commercial use. Service providers may process data internationally; this app does not promise storage in a particular country.
Google Firebase Authentication is an additional provider only for email login. We send it authentication information, not your career questions, answers, saved History or state of residence. Verification and reset links open Google's authentication pages, which also process browser/network information. We do not enable Google Analytics for this integration. Firebase describes logged IP retention as a few weeks and removal of other authentication information from live and backup systems within 180 days after customer-initiated deletion. See Firebase privacy and security information and its linked processing terms. Provider retention is separate from our app's 30-day History limit.
Career conversations and profiles derived from them are excluded from advertising and data-sale uses. Adding email login does not authorize any new marketing use.
For service eligibility, we compare your declared state with the allowed states and check Cloudflare's network country/state estimate. We do not ask your browser for precise location or save the network's location estimate in the application database. Network estimates can be wrong and are not proof of residency.
Your choices
In Account, choose Stop personal questions and delete saved History and confirm to withdraw personalized-question processing consent. This stops new personalized questions, turns History saving off and deletes all saved History from the active database. It clears the current conversation in that tab and prevents stale in-progress work from being returned or saved after the server detects the change. A request already sent to the AI cannot be recalled, and copies already displayed or downloaded are not erased. Provider processing already performed and backup expiry are separate. Your account, general resources, export, correction and deletion rights remain available. Contact Support if you cannot use the control.
Open History to choose whether future answers are saved, review or delete an entry, or delete all saved history. Turning saving off does not delete earlier entries; use Delete saved history for that. New conversation clears current-tab AI context but does not delete saved History. Deleting saved history in the interface also clears that tab's current conversation. Export downloads readable questions and answers along with account data; protect the downloaded file on shared devices. A saving failure does not prevent an answer from being shown, so do not rely on History as your only copy.
When the separate processing choice is introduced, existing accounts start with processing consent and History saving off. Existing saved entries are preserved for access, export, deletion and their normal expiry; they are not sent to the AI. Granting processing consent does not turn saving on or backfill old conversations. An explicit withdrawal through the combined control deletes all saved entries, including earlier ones.
Sign in and open Account to download stored account data or delete your account and its linked data. Deletion removes it from the active application database; Cloudflare documents a seven-day D1 Time Travel backup window on Workers Free. Other provider security records have their own retention schedules. A restore must reapply intervening deletion requests before the service reopens. Short-lived abuse counters and aggregate daily capacity totals may remain until expiry. If you cannot sign in, use your recovery code or contact the operator above. Do not send passwords, recovery codes, identity documents, or sensitive question text to support.
For linked email accounts, deletion also requests removal of the Firebase login. After successful account authentication, a failure of the Firebase deletion request does not prevent local deletion; the interface reports that provider deletion is pending. An authentication outage can prevent password users from reaching that step, requiring a later retry, an existing passkey, or help from Support. The daily retry queue retains only the provider identifier and attempt metadata until deletion succeeds and any uncertain creation is resolved. Contact support for confirmation or correction of an email address. Password recovery replaces legacy recovery-code use after email is linked; password resets invalidate prior password sessions when next used, but do not remove independent passkeys or passkey sessions. Report a compromised passkey or device to Support.
Contact the operator to request access, correction, deletion, or assistance exercising applicable privacy rights. These controls are available for every account; additional legal rights depend on your location. We will verify control of the account without unnecessarily collecting more personal information. We do not penalize users for exercising applicable privacy rights.
You can correct your nickname and state in Account. A state change may affect eligibility. To appeal a privacy-request decision, contact the same operator and identify it as an appeal. We will explain our decision and provide regulator-contact information where required. See Support and privacy requests. There is no fee for ordinary self-service access or deletion.
If you voluntarily contact support at the Gmail address above, Jeremy Fusilier and Google (Gmail) receive the information you send, your reply address, and request-handling records. Send only what is needed; no chat transcript is attached automatically. Routine support records should be removed within 90 days of closure, except where a legal obligation or documented preservation need requires longer retention. Email support is separate from the app database; deleting an app account does not automatically delete prior support email. See Google's Privacy Policy. The operator monitors this support mailbox, restricts access, handles requests using minimum necessary information, and applies the retention period above. These practices do not make email an appropriate channel for health narratives or authentication secrets.
Adults and policy changes
This service is intended for adults 18 and older. It is not directed to children. If we learn that an account belongs to a child, we will investigate and remove the account and associated information as required. A checkbox is not a guarantee that every user's age has been verified.
Material changes will be announced on this website before taking effect where required, with a revised version date. Active acceptance of the current terms and acknowledgement of this notice are required before further AI use, separately from processing consent. The current processing-consent identifier is career-processing-2026-09-19.1. New categories or purposes requiring consent will require a new affirmative choice before that processing begins. Continuing to use the site is not that consent. Declining changed terms does not block withdrawal, export or deletion. Prior versions are available.
Consumer Health Data Privacy Notice · Terms & AI disclaimer · General resources · Return to Career AI