Policy
Privacy Notice
Effective at opening. This policy takes effect when applications open, and may be revised before then. It has no effective date yet.
Applications are not open, and no fee can currently be paid.
1. What is collected, and why
- Identity. Name, contact details, and an external recovery email - to know who is applying, to secure the account, and to deliver required notices.
- Licensure. Jurisdiction and license details - to verify current authorization to practice against official public sources. No photograph is collected.
- Resume. A single PDF - reviewed by an assigned human reviewer for consistency with official sources, then deleted on the schedule below.
- Payment. Handled by Stripe. Admitted stores Stripe identifiers and receipt references, never card numbers.
- Technical. The minimum operational and security records needed to run the service safely: authentication events, webhook events, and audit records, retained as scheduled below.
2. Minimization commitments
- Admitted does not sell personal data.
- Admitted does not use personal data for targeted advertising.
- Admitted does not use applicant or member data to train models.
- Admitted does not run analytics tied to personal data.
3. Resume handling
Resumes are stored in a private, access-controlled Cloudflare R2 bucket dedicated to the environment, under a random object key unrelated to the applicant's name, email, or license number. Every file is scanned for malware before any reviewer may open it; a file that cannot be scanned stays quarantined and is never opened. Resumes are never sent by email, never written to logs, and never stored in the application database. Reviewer access is authorized, time-limited, and logged.
4. Who processes data
No personal data has been collected yet, because applications have not opened. Once they do, personal data will be processed by:
- Vercel - application hosting.
- Cloudflare - DNS, network security, and document storage (R2).
- Neon - the application database.
- Stripe - payment processing.
The mailbox provider, the transactional-notice provider, the malware scanner, and the identity-verification provider have not been selected. Each will be named, with its role, in the subprocessor list published alongside this notice before any personal data flows to it.
5. Retention schedule
These are the retention rules for every class of data the service holds. A documented legal hold can pause deletion for the specific data actually needed, never indefinitely by neglect.
| Data class | Kept while | Deletion or anonymization |
|---|---|---|
| Raw resume and supplemental evidence files | Per the resume schedule: abandoned drafts 14 days after inactivity; withdrawn before review within 7 days; not approved through the 30-day correction window and any timely reconsideration; approved and activated within 35 days after activation; expired approval within 35 days after expiration. | Delete the primary file, derivatives, quarantine copies, and old object versions by the stated deadline. |
| Draft structured application | While the draft is active. | Delete or irreversibly anonymize 30 days after the abandoned-draft notice; no unpaid marketing profile is kept. |
| Final application fields, decision reason, and minimal verification record | Through the decision, correction, and dispute period. | Minimized and retained up to 3 years after the final decision for contract and fairness defense; then anonymized or deleted except narrow payment and consent records. |
| Identity-provider result and reference | The application, plus membership if approved. | Raw artifacts are deleted per the provider immediately or on a short schedule; a minimal result and audit reference is retained through membership plus 3 years only if approved. |
| Member license and verification history | The membership lifetime. | Minimal history retained 3 years after membership ends, then deleted or anonymized unless a legal hold applies. |
| Recurring-payment consent and governing terms | The membership lifetime. | At least 3 years, or 1 year after termination, whichever is longer, under the selected legal baseline. |
| Stripe payment and tax ledger | As required for billing, disputes, tax, and accounting. | Counsel and accountant schedule, commonly longer than product data; no card data or unnecessary personal information. |
| Authentication sessions and tokens | Current operational need only. | Expired and revoked promptly; token material deleted on expiry; privacy-safe security events retained up to 1 year. |
| Security and abuse incident evidence | The active case. | 3 years after closure by default, longer only under a documented litigation or legal hold; access heavily restricted. |
| Support cases | The active case. | 2 years after closure by default; attachments deleted sooner and unnecessary personal information redacted. |
| Privacy and rights requests | The active request and proof of completion. | 3 years after closure, or a counsel-approved requirement; only what proves proper handling is retained. |
| Provider and webhook operational events | Idempotency and reconciliation need. | Safe metadata 1–2 years; billing events follow the financial schedule; routine mail content is never stored. |
| Administrative audit events | Security, fairness, and compliance need. | 7 years by default, using minimized values in tamper-evident storage. |
| Public verification profile | While the member has opted in and membership is active. | Disabled immediately when consent is withdrawn or service is not active; optional fields deleted within 30 days. |
| Address assignment tombstone | While Admitted controls the domain and must prevent reassignment. | Retained indefinitely as an irreversible, versioned, keyed representation of the address, for the sole purpose of ensuring a retired address is never reassigned. This is the only data class retained with no scheduled end. |
| Database and object backups | The rolling recovery window. | Target 35 days or a shorter plan-supported window; deletions propagate as backups expire, and restored backups rerun deletion and tombstone jobs. |
| Mailbox content | Governed by the mailbox provider contract and the membership lifecycle. | A 30-day export window after membership ends, then provider-confirmed purge by day 60; no copy is kept in Admitted’s database or document storage. |
One row deserves emphasis: the address assignment tombstone is retained indefinitely, in a keyed, irreversible form, for one narrow purpose - making sure a retired address is never given to anyone else while Admitted controls the domain. It is not a copy of mail, a profile, or readable personal history.
6. Applicant and member rights
Applicants and members have authenticated mechanisms for access, correction, deletion, and withdrawal of their application, subject to the legal retention exceptions in the schedule above (for example, payment and consent records that must be kept). Withdrawal before human review begins also triggers a full refund of the application fee, as the Refund Policy describes.
7. Cross-border transfers
Personal data is processed by the named processors above under their service agreements. Admitted claims no cross-border transfer arrangements beyond those processors; any additional transfer mechanism is documented in this notice before it is relied on.
8. Email content
Ordinary email is not end-to-end encrypted. Once a mailbox provider is contracted and named, this notice will describe exactly how message content is processed. The address itself does not create privilege, and members remain responsible for judging what client information is appropriate to send by email.
Document history
- 2026-08-23 - Initial version, published ahead of opening.