Privacy Policy
Effective Date: February 16, 2026
Last Updated: September 9, 2026
This Privacy Policy explains how Anesthesio ("Anesthesio," "we," "our," or "us") collects, uses, discloses, and protects information when you access or use anesthesio.com and related services (the "Services").
1. Scope
This Policy applies to individuals who browse job listings, create candidate profiles, post jobs, purchase plans, or otherwise interact with the Services. It does not apply to third-party websites or services that may be linked from our platform.
2. Information We Collect
We collect the following categories of information:
- Account and profile data: name, email address, login credentials, professional role (e.g., CRNA, Anesthesiologist, CAA), resume details, and profile preferences.
- Job and recruiting data: job postings, employer details, job application interactions, saved searches, and candidate preference information.
- Payment and billing data: billing contact details, transaction metadata, and subscription status. Payment card data is processed by Stripe and is not fully stored by Anesthesio.
- Usage and analytics data: page views, session events, browser/device information, IP-derived approximate location, and diagnostics.
- Support and communications: emails, support tickets, and other messages sent to or from Anesthesio.
3. Indexed Job Data
Anesthesio indexes and organizes publicly available job posting information from across the web, including employer and institutional career pages. Similar to how search engines index publicly available web content, we use automated systems and AI to discover and present job opportunities in a structured format to help users find relevant positions.
Indexed listings may become outdated, changed, or removed at the source. We attempt to refresh listings regularly, but we do not guarantee ongoing accuracy or availability of any indexed listing.
4. AI Features and Automated Processing
We use AI-powered features to improve relevance and usability, including job matching, recommendations, search ranking, and chat assistant functionality.
- AI outputs may be generated from your queries, profile data, and platform activity.
- AI outputs are informational and assistive only. They are not intended to make or substantially determine employment decisions. AI outputs should be independently reviewed before making employment, hiring, or business decisions.
- We may use de-identified and aggregated usage patterns to improve model performance and product quality.
- Automated decision-making and profiling. The Services may use automated processing to organize, rank, or recommend job listings based on your profile, preferences, and activity. This processing is used for relevance and convenience only — it does not produce legally or similarly significant effects on users. If you believe automated processing has affected you in a meaningful way, you may contact us to request information or human review of the relevant processing.
- AI-powered features may use third-party AI service providers. Personal data shared with such providers is governed by our data processing agreements and used solely for the purpose of providing the Services.
5. Connected AI Assistants and Agent Access
You may connect a compatible AI assistant or developer tool (for example ChatGPT, Claude, Gemini, or an MCP-capable coding tool) to Anesthesio through our hosted Model Context Protocol ("MCP") endpoint and related agent APIs (together, "Agent Access"). This section explains what a connected assistant can access, what we store, and how the assistant's own provider fits in.
What a connected assistant can do
Agent Access exposes a fixed, limited set of tools. Each tool is tied to a named scope, and every tool call is checked against the scopes granted to that connection:
- Job search and job details (
jobs:search) — read public job listings and return links to them. - Salary context (
salary:read) — read aggregated, public compensation context derived from current listings. - Job alerts (
alerts:write) — save a search and alert frequency to your account on your instruction. - Private job drafts (
job-drafts:write) — for recruiter accounts, organize details you provide into a private, unpublished draft and return a link for you to review and, if you choose, check out.
A connected assistant cannot apply to jobs on your behalf, contact employers or candidates through the Services, publish listings, change your profile or subscription, or make payments. Publishing and payment remain on Anesthesio and require your own confirmation. Some tools may require that you are signed in, or may be subject to usage limits or the terms of your plan.
Authorization and consent
- OAuth connection (preferred). Your assistant is directed to an Anesthesio consent screen where you sign in, see the name of the requesting assistant and the tool set it will receive, and approve or decline. Authorization uses OAuth 2.1 with PKCE through our authentication provider. The identity scope we request is limited to your email address, which we use to link the connection to your account.
- Email-code credential (fallback). Where an assistant cannot complete OAuth, it may request a scoped agent credential. We email you a one-time approval code; the credential is issued only if you share that code with the assistant. These credentials are limited to the scopes you approved, expire automatically (currently after 90 days), and can be revoked at any time.
- Revocation. You may end a connection at any time by removing or disconnecting Anesthesio in your assistant's connector settings (OAuth), by having the assistant call our revocation endpoint, or by contacting us. Revocation stops further tool calls but does not delete alerts or drafts already saved to your account; you can manage those from your dashboard or request deletion as described in Section 10.
Your AI provider is a separate controller
The company that operates your assistant (for example OpenAI, Anthropic, or Google) controls the conversation you have with it, including any prompts, outputs, and history it retains. Anesthesio receives only the tool calls the assistant sends to our endpoint and the information needed to authorize them; we do not receive or store your conversation. Tool responses we return to the assistant become part of that conversation and are governed by your provider's privacy terms, which we do not control. Please review those terms before connecting. We do not sell personal information to AI providers, and connecting an assistant does not authorize an AI provider to receive any data beyond the tool responses you request.
What we collect and retain from Agent Access
- Connection records: the assistant's name or client identifier, the scopes granted, the account it is linked to, and issue, expiry, and revocation timestamps. Retained while the connection is active and thereafter as account data.
- Tool-call analytics: for each tool call we record an analytics event in PostHog containing the tool name, whether the call succeeded, an error code if it failed, the connection identifier, and the assistant provider and name. We do not send bearer tokens or approval codes to analytics. These events are usage data and follow the retention period in Section 9.
- Alerts and drafts: job alerts and private job drafts an assistant creates on your instruction are stored in your account exactly as if you had created them yourself and are retained until you delete them or close your account.
- Referral attribution: links we return to an assistant may identify the assistant as the referral source so that we can understand which tools are useful. This is product analytics, not advertising, and is not shared with the AI provider.
- Rate-limit and security data: request counts and related metadata used to enforce usage limits, detect abuse, and keep the Services secure.
Public registry data
Some features, including our provider directory and People Search tools, draw on public government datasets: the National Plan and Provider Enumeration System (NPPES) NPI Registry published by the U.S. Department of Health and Human Services, and the Centers for Medicare & Medicaid Services (CMS) Doctors and Clinicians facility-affiliation data. Please note:
- Registry data, including specialty and practice location, is self-reported by clinicians to the federal government and may be outdated, incomplete, or inaccurate. We display it as published and do not independently verify it.
- A CMS facility affiliation is a billing-relationship indicator, not proof of current employment, hospital privileges, or credentialing status.
- We do not infer or display whether a clinician is available for work, and we do not add photographs, biometric identifiers, or data purchased from data brokers to these records.
- Before relying on any registry record, verify it directly with the federal NPI Registry or the relevant licensing board. If you are a clinician and believe a record about you is inaccurate, the authoritative correction path is through NPPES; you may also contact us and we will review the record we display.
Whether you obtain registry data on our site or through a connected assistant, you are responsible for using it lawfully. See our Terms of Service for the acceptable-use rules that apply to connected assistants and to outreach using data obtained from the Services.
6. How We Use Information
We use information to:
- Provide and maintain the Services;
- Match candidates with jobs and assist employers with hiring workflows;
- Process purchases, subscriptions, and billing-related operations;
- Analyze performance, improve platform quality, and prevent abuse;
- Communicate service updates, alerts, and support responses; and
- Comply with legal obligations and enforce our agreements.
7. Cookies and Tracking Technologies
We use essential cookies and similar technologies required for core site operation, authentication, and security.
Outside the EU/UK/CH and other regions that require affirmative consent, non-essential analytics, measurement, and marketing tools may load by default unless you decline them through our cookie banner. In the EU/UK/CH and other regulated or required-consent regions, those tools load only after you affirmatively accept; if you decline, they do not load.
When enabled under these cookie and consent rules, those tools may include:
- PostHog for product analytics and usage insights;
- Google services for business operations such as authentication, productivity, and/or measurement where enabled.
- Pinterest for ad measurement, retargeting, and conversion attribution where enabled under our cookie and consent rules.
- Apollo for website visitor identification where enabled.
You can accept or decline non-essential cookies in the banner. Browser controls may also limit cookies, but disabling essential cookies may affect platform functionality.
8. How We Share Information
We share information with trusted providers only as needed to operate the Services, including:
- Supabase (including AWS infrastructure) for database, storage, and authentication;
- Stripe for payment processing;
- PostHog for analytics;
- Pinterest for marketing measurement and conversion attribution where enabled under our cookie and consent rules;
- Sentry for monitoring and error reporting;
- Resend for transactional email delivery; and
- Google for selected product and communications infrastructure.
- AI assistants you connect (for example ChatGPT, Claude, or Gemini) receive the tool responses you request through Agent Access, as described in Section 5. Those assistants and their providers are independent controllers of your conversation and are not our service providers. They never receive your password, bearer tokens, or payment credentials from us.
We may also disclose information when required by law, to protect safety or rights, or in connection with a merger, acquisition, financing, or asset transfer.
9. Data Retention
We retain information for as long as necessary to provide Services, meet contractual commitments, resolve disputes, enforce terms, and satisfy legal obligations. General retention periods include:
- Account data: retained while your account is active and for a reasonable period after deletion to fulfill legal obligations.
- Transaction and billing data: retained as required by tax and financial reporting laws (typically 7 years).
- Usage and analytics data: retained in identifiable form for up to 24 months, then de-identified or deleted.
- Support communications: retained for up to 3 years after resolution.
- Indexed job data: refreshed, updated, or removed on a rolling basis as source availability changes.
You may request deletion of your personal data at any time by contacting us. Some data may be retained as required by law or for legitimate business purposes.
10. Your Rights and Choices
Depending on your location, you may have rights to:
- Request access to personal information we hold about you;
- Request correction of inaccurate or incomplete information;
- Request deletion of your personal information;
- Request export/portability of your data; and
- Object to or restrict certain processing in some circumstances.
To submit a request, email support@anesthesio.com. We may require identity verification before processing requests.
11. CCPA and GDPR Disclosures
If you are a California resident, you may have rights under the CCPA/CPRA, including rights to know, delete, and correct personal information, and to limit certain uses of sensitive data where applicable. You may designate an authorized agent to submit requests on your behalf. We will not discriminate against you for exercising your privacy rights.
If you are in the EEA, UK, or similar jurisdictions, we process personal data under recognized legal bases including:
- Contract performance — to provide the Services you requested (account management, job search, communications).
- Legitimate interests — to improve and secure the Services, prevent fraud, and conduct analytics, balanced against your rights and freedoms.
- Consent — where required for specific processing activities, which you may withdraw at any time.
- Legal obligation — to comply with applicable laws and regulations.
EEA/UK users have the right to lodge a complaint with their local supervisory authority if they believe their data has been processed unlawfully. For cross-border data transfers, we rely on Standard Contractual Clauses or equivalent mechanisms approved under applicable law.
Anesthesio does not sell personal information for monetary consideration as defined by CCPA and does not share personal information for cross-context behavioral advertising as defined by CPRA.
12. Security
We implement commercially reasonable technical and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children's Privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16.
14. Changes to This Policy
We may update this Policy from time to time. Material updates will be posted on this page with a revised "Last Updated" date.
15. Contact Us
Questions about this Privacy Policy or our data practices can be sent to support@anesthesio.com.