FIRST CHAIR · PRIVATE CAREER WORKSPACE
Privacy information
Updated September 21, 2026
First Chair is a private organizer for dental hygiene job research, temp shifts, and application preparation. Its account owner operates it for a candidate and one trusted collaborator: two authorized users in total. The workspace and its documents require sign-in. These information pages contain no candidate records.
Information in the workspace
The app stores the profile, résumé text and confirmed facts, commute starting point, availability, job sources, application and shift history, drafts, office reviews, and spending approvals that users enter. Both authorized users can see the shared records. PDF and DOCX résumé files are read in the browser; the résumé reader sends the extracted text, rather than the original file, to private storage. Extracted qualifications need confirmation before use in drafts.
Private access and storage
The workspace runs on the owner's DigitalOcean server with network access through Tailscale. Each user signs in with an individual passkey. The app stores public passkey credentials, not a device's biometric information or private key. A sign-in token is held in the browser tab's session storage, expires after seven days, and is revoked when the user signs out.
Project credentials are retained in a dedicated 1Password vault. Credentials needed by the running app are held in restricted server configuration or private files outside the web content and document API. The app does not publish credentials in its interface.
Optional Gmail daily digest
Gmail is the selected delivery service. It sends only after the owner connects a Gmail account and a user enables the daily digest. The app requests only https://www.googleapis.com/auth/gmail.send, allowing it to send email on the connected account's behalf. It does not request permission to read, search, delete, or import messages from that account, and it does not use inbox-reading APIs.
A digest contains selected job titles, office names, source links, match explanations, the number of application follow-ups due, and an eligibility reminder. Google receives that message, its sender, and both fixed recipient addresses to deliver it to the two authorized users. Both recipients are visible in the message. The digest does not attach résumés or send applications or employer messages.
The app retains a send-only refresh token and its scope in a restricted server file, with a recovery copy in the project vault. It uses temporary access tokens in memory to send messages. Credentials are excluded from ordinary workspace backups. Local delivery records retain recipients, selected record references, time, and outcome to avoid repeated messages; they do not prove inbox receipt.
Turn off the daily digest in the profile to stop future digest attempts. The connected account owner can also revoke First Chair through Google Account connections and ask the workspace owner to remove stored credentials. Revocation does not delete messages already delivered; their retention is controlled by the sender, recipients, and Google.
First Chair uses Google authorization data only to provide this chosen email feature. It does not sell that data, use it for advertising, or send OAuth tokens or data obtained through Gmail to AI providers. First Chair's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google's handling of information is described in the Google Privacy Policy.
Search, transit, and AI
Brave Search receives job-search terms, not the candidate's résumé. Search responses are used transiently to discover employer sources; the app imports listings separately from those sources. Approved Google Maps transit requests send the entered starting point, office address, and relevant arrival or departure time to Google. Route results stay in the open workspace's memory for up to 15 minutes and are not retained in the workspace database or browser storage. Maps links also send the included route information to Google when opened.
Cloudflare Workers AI is optional and requires provider setup and the spending owner's approval for each request. Approved extraction can send résumé text or listing text to Cloudflare. For drafts, it receives the job description and confirmed qualification facts to select relevant facts; the app builds the draft from those confirmed facts. AI output is checked and still requires human review. Manual imports and draft templates remain available without AI.
Following an employer or staffing-platform link opens a separately operated service. Google Maps features are subject to the Google Maps terms and Google's privacy policy. Automatic alert imports, if separately configured, use a dedicated receiving mailbox; the Gmail send-only connection does not provide this access.
Backups, retention, and deletion
Workspace records remain available until the owner removes them or retires the workspace. Nightly backups cover the database and referenced résumé text. Local archives are private, unencrypted files retained for 30 days. Off-server copies are encrypted before upload to Backblaze and have a 1 GB encrypted-storage ceiling. Existing bucket settings protect objects from deletion for 90 days, hide them after 365 days, and delete them one day later. Removed records can therefore remain in protected backup copies until those copies expire.
The workspace owner manages exports, record deletion, access removal, and credential removal. Authorized users can contact the owner through their existing private communication channel to request these changes. Deletion from this workspace does not remove information already sent to an employer, staffing platform, email recipient, or other provider.
Spending and other controls
Each paid operation needs the spending owner's approval. Application controls use a $50 monthly ceiling and pause additional discretionary paid processing at $45; provider invoices remain the source of actual charges. The configured Gmail digest does not create a paid-action approval for each message. Notifications can be disabled in the profile.
The private app requests display fonts from Google Fonts. These information pages use local system fonts and load no analytics or advertising trackers. The app does not automatically submit applications, book or cancel shifts, or contact employers.