Account data
Required for login
Email address and encrypted password (or Google account token) when you create an account. Used to identify your session and link your scan results to your account.
Scan results
Required for service
Your Activation Scan answers, activation dimension scores, and saved result. Stored in your account so you can access your dashboard. Never shared individually with third parties.
When you choose to edit and save your Profile, we store the following fields in your account: display name, location (city or region, as you enter it), country, and LinkedIn profile URL. These are optional fields. Nothing is saved unless you actively press Save Profile basics. They are used only to display your profile within the Flux Forward app and are not shared with third parties for marketing purposes.
Career Navigation
Optional feature
Career Navigation is an optional part of the Flux Forward App that helps you work out which of the vacancies we already publish are worth your time. It is a beta feature available to signed-in Flux Forward users. You only have data here if you choose to set it up.
What we store. What you enter and confirm, in four parts. A short career profile: a headline, skills, education entries (qualification, institution, year) and languages with a proficiency level. Up to five experience entries: job title, employer, start and end date, and whether the role is current. Your preferences: target job titles, the kinds of opportunities you are looking for, seniority, preferred locations, working mode, maximum office days per week, maximum commute time, languages, and any employers you want excluded. Your situation: whether you need visa sponsorship, and a planning runway in days that you state yourself. We also store ordinary operational fields so the app knows what you have confirmed and when, such as revision counters and confirmation timestamps.
Some answers start pre-filled from your existing profile. To avoid asking you the same thing twice, we may pre-fill two Career Navigation answers from what your Flux Forward profile already holds: your location becomes a suggested preferred location, and your preferred language becomes a suggested language. A pre-filled language is given a default proficiency of "professional" that you did not choose, so please correct it if it is wrong. We only pre-fill when you have not already answered that step yourself. Your answer about needing sponsorship is never pre-filled — we show you what you told us before and ask you to confirm it. Everything pre-filled is visible and editable on screen, and none of it becomes stored Career Navigation data until you save that step. We never write anything back to your main profile.
Whether Career Navigation is switched on for you. If we ever need to switch this feature on or off for an individual account — for example during a limited preview — we store one small record on your account noting that the feature has been enabled or disabled for you, and when. It holds only the name of the feature, your account identifier, whether access is active or withdrawn, and those dates. Only we can set it — you cannot change it yourself, and it is not part of your career information. It is deleted with the rest of your data when you delete your account.
Career Navigation does not ask you for a free-text summary or for written evidence statements. Earlier versions of the setup did, and if you filled those in before they were removed, the values stay on your existing record until you delete your account. Nothing in the app asks for them any more.
What we do with it. We use your confirmed answers to narrow and order your own reading of opportunities we already publish, to explain why an opportunity appears where it does, and to give you planning context.
To be precise about which answers actually affect what you see: the ordering uses the kinds of opportunities you are looking for, your target job titles, your preferred locations, your working mode, your languages, any employers you excluded, whether you need sponsorship, and your planning runway. The rest — your headline, skills, education, experience entries, seniority, maximum office days and maximum commute — is stored as your own career record so you can keep it up to date and so the app knows your setup is complete. It does not currently change which opportunities are highlighted.
Career Navigation does not decide your eligibility for anything, does not determine your immigration status, does not decide whether an employer will hire you, does not apply for anything on your behalf, and does not send anything about you to an employer. No employer, university, partner or institution receives your Career Navigation profile, your results or the reasons behind them.
Sponsorship and planning runway. If you tell us you need visa sponsorship, we use that only as planning context, to compare against what a vacancy itself says about sponsorship. We do not use it to infer your nationality and we do not use it to judge whether you would qualify for anything. The planning runway is a number of days you state yourself so we can give you a sense of timing. It is not a permit expiry date, we do not check it against any official record, and it is not immigration advice.
Please leave sensitive details out. Career Navigation never asks for special-category or sensitive personal information, and you should not type any into the free-text fields. That means no health information, religion, political opinions, trade-union membership, sexual life or orientation, biometric or genetic information, and no passport number, BSN, permit number, immigration-case or legal-case details.
Opportunity assessments are not saved. Your profile, experiences, preferences and situation are stored in your account so you can come back and change them. What you see in Your Opportunity Space and on an opportunity page is worked out fresh from your answers each time you open it and is not stored: we keep no band, no ranking, no score and no record of any assessment. If you separately choose to save an opportunity, we keep the limited reference described below, not the assessment.
How long we keep it. Your Career Navigation data is kept while your account is active, so it is still there when you come back. Your stated situation goes stale after 30 days and we ask you to confirm it is still accurate before we use it again — going stale does not delete it, and nothing here is deleted automatically on a timer. You can change your answers at any time, and deleting your account deletes your Career Navigation data along with the rest. Legal basis: contract (Art. 6(1)(b) GDPR) — this is the feature you asked us to set up for you.
Situation Context and saved opportunities
Optional account features
Situation Context. If you describe your own situation in Connected Capture, the words you submit are sent through Flux Forward's protected server to OpenAI so an AI model can interpret them in the language you used. We send only that one Capture text and your current four-field Situation Context, where one exists. We do not send your profile, Journey history, saved opportunities, email address or account identifier to OpenAI for this interpretation. A supported Flux Forward job link is resolved separately and is not sent to OpenAI.
The words you typed into Capture are not stored, sent to analytics or kept as history by Flux Forward. OpenAI receives them as an external processor. The OpenAI project used for Capture has Global residency, so processing is not restricted to a particular region and may take place outside the EEA. Requests use store:false, which turns off OpenAI application-state logging for the response, and this project is not selected for sharing API inputs and outputs with OpenAI to improve or train models. These controls do not prevent OpenAI's standard abuse-monitoring retention: request content may normally be retained for up to 30 days, or longer where required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Do not submit confidential, sensitive, or special-category personal data in Capture.
The model can only propose values from the existing closed Situation Context: the kind of goal, a Study, Work, Build or Undecided route where present, up to three supported city keys, and one blocker category. You see the complete proposed summary and what would change before anything is saved. Nothing is written unless you press the confirmation button. If you confirm, we store one current structured summary in your account, plus limited operational fields such as confirmation times, revision numbers, a bounded outcome and a reference to an accepted next move. We also keep the current UTC day, a request count and an update time under your account to enforce a daily interpretation limit; that counter contains no Capture text or model output. Flux Forward may use the confirmed summary on Home, My context, Next moves, For you and Journey. You can correct or remove it in My context, including after access to a limited Beta ends.
Saved opportunities. If you press Save on an opportunity, we store only its canonical Flux Forward opportunity identifier and the time you saved it. We do not copy the vacancy title, employer, description or the link you used into your saved record. The app looks up the current public opportunity from that identifier when you return, so a listing can change or become unavailable. Free accounts can keep up to three saved opportunities at once; Plus and eligible organization access can have a larger allowance. Removing one deletes that saved reference. A plan downgrade does not silently delete references you already saved, and you can still remove them.
Saving or viewing an opportunity does not mean that Flux Forward applied for it, that you are eligible, that the employer is interested, that sponsorship is guaranteed, or that Flux Forward recommends it as a hiring or immigration decision. These account features do not send your Situation Context, saved references or Career Navigation answers to an employer, university, partner or institution.
How long we keep it. Flux Forward does not retain raw Capture prose. OpenAI normally retains request content for up to 30 days for abuse monitoring under its standard controls, even though application-state storage is disabled for the request; OpenAI states that it may retain it longer where required by law or reasonably necessary to prevent harm. Situation Context is current-state only: correcting it replaces the previous structured values rather than creating a history. The current Context, the limited usage counter and saved opportunity references remain while your account is active until you remove the relevant feature data or delete your account. Deleting your account deletes both feature records and the usage counter. Legal basis: contract (Art. 6(1)(b) GDPR) — the transient interpretation and confirmed records provide the account features you chose to use.
Firebase (Google)
Required for service
We use Firebase Auth and Firestore (Google Cloud) to handle login and store your data. Google processes your data as a data processor under a Data Processing Agreement. Data is stored in the EU (Netherlands, europe-west4).
Firebase privacy ?
Google Analytics
Consent required
Google Analytics 4 (GA4) is used for analytics across our web services: the main website (fluxforward.world), the blog (blog.fluxforward.world) and the Flux Forward app (app.fluxforward.world). The app has its own separate GA4 configuration rather than sharing the website's. Analytics is switched off by default and no Google Analytics code is loaded until you allow analytics — before that, the measurement library is not requested at all. Your analytics choice is shared across these Flux Forward services through our consent record, so allowing or rejecting analytics on one of them applies to the others too, including the app. You can reject analytics, and you can change or withdraw your choice at any time through Cookie settings. Legal basis: consent (Art. 6(1)(a) GDPR).
PostHog is used for product analytics in the Flux Forward app (app.fluxforward.world), to understand how the app is used and where people get stuck. It runs on PostHog's EU cloud, so your analytics data is stored in Germany. PostHog Inc. is a US company and some of its sub-processors are incorporated outside the EEA, so some processing may take place outside the EEA. PostHog processes your data as a data processor under a Data Processing Agreement, which includes Standard Contractual Clauses. Like Google Analytics it is switched off by default: no PostHog code is loaded until you allow analytics. We do not send PostHog your name, email address, or anything you type or answer in the app. We send only which pages you opened and which product steps you reached. When you are signed in we identify you to PostHog by a one-way code derived from your account, never by your email address. Session recording is not enabled. Legal basis: consent (Art. 6(1)(a) GDPR).
PostHog privacy
Analytics consent record
Required for service
To remember your analytics choice we store one small first-party cookie named ff_consent_v1. It is set on fluxforward.world and shared with our subdomains, which is how the same choice applies to the blog and the app without asking you again on each one. It records only that a choice was made, whether analytics was allowed, which analytics services you were told about, and when — it contains no account data and no advertising identifiers. It is kept for up to 400 days unless you change or clear it. You can change your choice at any time through Cookie settings, or clear the cookie through your browser settings. If you reject analytics, no Google Analytics or PostHog cookies are created, because neither measurement library is ever loaded. If you allow analytics, Google Analytics sets its own cookies in your browser — these usually have names beginning with _ga, and the exact set can vary with Google's own configuration and your browser settings. PostHog also sets one first-party cookie, whose name begins with ph_.
Flux Forward event registration
Event registration
When you register for a Flux Forward event through our own registration flow, we collect the information needed to manage your attendance, such as your name, email address, profile identifier, selected event, role/context, registration status, and source/UTM metadata. This is stored in FluxOS and may also be connected to your Flux Forward profile. Newsletter updates remain separate and are only sent if you clearly opt in. The event registration page stores a local cache of your registration records in your browser, keyed to your account, to display your registration status quickly and reduce repeat network calls. You can clear this at any time through your browser settings. When you register or cancel a registration, a transactional confirmation email may be sent to your registered email address. This is not a marketing email.
LinkedIn Events
Event registration
When you register for a Flux Forward event through a LinkedIn Events registration form, LinkedIn may share the information you submit with us, such as your name, email address, job title, company name, and country or region. We use this information to manage event attendance, send practical event-related updates, and follow up where relevant after the event. We only send promotional or marketing communications if you have given consent through the registration form or another clear opt-in. We do not sell attendee data. We do not use it for advertising profiling. We may store registration data securely for up to 12 months after the event, unless we need to keep it longer because of an ongoing relationship, legal requirement, or your explicit consent. You can ask us to access, correct, or delete your event registration data at any time by emailing
[email protected].
Stripe handles payment for Flux Forward Plus. When you buy Plus you enter your payment details on a Stripe checkout page, not on ours, so we never see or store your card or bank details. Stripe tells us that a payment succeeded, and we store the identifiers we need to keep your subscription working and to let you cancel it, together with the records we must keep for accounting. Stripe processes this data as a data processor under a Data Processing Agreement, and Stripe Inc. is a US company, so some processing may take place outside the EEA. Legal basis: performance of the contract you entered into (Art. 6(1)(b) GDPR), and our legal obligation to keep financial records (Art. 6(1)(c) GDPR).
Stripe privacy
Contact messages and Message Flux Forward
Legitimate interest
When you send us a message through a form on this website, including Message Flux Forward, we collect your email address and the message you write. If you choose to open the optional organization section, we also collect the name, organization, and topic you enter there. Alongside this we store the page path you wrote from, the time you sent it, your site language, and whether you ticked the optional newsletter box, together with the wording of the consent you were shown. We use this to receive your message, reply to you, and keep a limited record of the exchange so we can follow up and understand the conversation if you write again. Our legal basis is our legitimate interest in answering people who choose to contact us (see section 3). Your message is stored as a submission record in FluxOS, which uses Supabase in the EU (Ireland), and a contact entry is added to the FluxOS CRM so we know you have been in touch. Brevo delivers the notification email that tells us your message arrived; your own email address is set as the reply address on that notification so we can answer you directly. The form is called Message Flux Forward; messages sent through it reach the Flux Forward team mailbox, which the founder, Ben Brink, reads. To limit automated abuse we score submissions for spam and count recent submissions using a one-way hash of your email address; a message identified as spam is held and not delivered. Sending us a message never signs you up for anything: ticking the newsletter box is optional, separate, and never required to send a message. For Message Flux Forward the FluxOS CRM entry records that you contacted us and when, but not the text of your message. How long each of these is kept is described in section 4. You can object to this processing, or ask us to access, correct, or delete a message you sent us, at any time by emailing
[email protected].
Product and pilot feedback
Optional and anonymous
We sometimes ask people who have tried Flux Forward to fill in a short feedback form, including during university pilots. Taking part is voluntary. The form does not ask for your name or your email address, it is not linked to your Flux Forward account, and we cannot tell who did or did not answer. We collect only your answers, the pilot the form belongs to, and a coarse device type such as mobile or desktop, so we can tell whether something read badly on a phone. Answers are stored as a submission record in FluxOS, which uses Supabase in the EU (Ireland), and a copy of the answers is emailed to our internal address through Brevo so the team can read them. That copy carries no name, no address, and no identifier. We use this to understand what worked and what needs to change. Our legal basis is our legitimate interest in improving the product (see section 3). Because the answers are anonymous, we cannot find or remove an individual response afterwards, so please do not include sensitive personal information in them.
Optional follow-up email
Optional
After you send anonymous feedback, you can choose to leave your email address if you are open to a short follow-up conversation. This is entirely optional, and the feedback form works exactly the same if you skip it. If you do leave it, your address is sent as a separate submission and stored as its own record, with the pilot it belongs to and the time you sent it. We use it only to contact you about a follow-up conversation. It is deliberately kept apart from your feedback: your answers carry no identifier that could be matched to your address, we store nothing that links the two records, and leaving your address does not attach your identity to the answers you already sent. It does not subscribe you to anything. Our legal basis is your consent, which you give by choosing to enter your address. You can ask us to delete it at any time by emailing
[email protected].
Newsletter, CRM, and Brevo
Consent required
If you subscribe to Flux Forward Updates, we collect your name, email address, selected persona or context, consent status, source page, and basic signup metadata. This is stored in FluxOS CRM and synced to Brevo for email delivery. We use this only to send Flux Forward updates and manage your preferences. You can unsubscribe or update preferences anytime through the link in every email or by contacting
[email protected].
Substack (legacy blog images)
Limited legacy role
The Flux Forward blog at blog.fluxforward.world is served by Cloudflare, which hosts our website and blog, not by Substack. Some older blog articles still load images that remain stored on Substack's media servers, so opening those articles can make your browser request an image from Substack. Substack is an independent platform with its own privacy policy. Subscribing to Flux Forward Updates does not go through Substack.
Substack privacy ?
Local storage (app.fluxforward.world)
Required for service
The Flux Forward app uses two local storage entries in your browser. One stores a record that you acknowledged this privacy notice. It contains only a version number, a status value, and the timestamp of your acknowledgment. It does not contain account data. The other stores your in-progress Activation Scan answers and your current question position on this browser for up to 14 days. This lets you continue where you left off if you close and reopen the browser before saving. It does not store your final saved scan result. Your final scan result is saved to your account only when you are signed in and press Save scan. Both entries can be cleared at any time through your browser settings. Neither entry contains personal account data or financial information.
Session storage
Required for service
The Flux Forward app (app.fluxforward.world) does not use session storage. The event registration page (app.fluxforward.world/events/register/) may store a temporary copy of your most recent registration record in session storage for the duration of that browser session. This is cleared when you close the browser tab and is used only to reduce repeat network calls on that page.
Fluxy AI clarity companion
Required for service
Flux Forward includes an AI-powered clarity companion called Fluxy. If you type a message to Fluxy, your message may be sent to the Fluxy backend to generate a response, and that backend may use an AI provider. Fluxy currently uses OpenAI. Our OpenAI project is not restricted to a particular region, so your message may be processed outside the EEA. Fluxy may include public page context, route context, and recent in-memory conversation context so it can answer. On the public website and blog, Fluxy uses public page context only. In the Flux Forward App, private scan, snapshot, journey, profile, and event context stay out of Fluxy until explicit consent and audit are implemented. Fluxy chat is not saved as conversation history by the website or app. To help us look into problems, we keep a short technical record of each Fluxy answer for 30 days: a random reference for that answer, when it happened, which surface and route it came from, which model answered, and whether it worked. That record contains no part of your message and no part of the answer, and it is not linked to your account. If you use the report option to tell us an answer was wrong or harmful, we keep that report for 90 days: the same random reference, the reason you picked, and the time. The text of the answer is included only if you tick the box asking us to include it, and your own message is never sent with a report. Fluxy does not execute actions, register you for events, update profiles, send emails, delete accounts, or make decisions for you. Fluxy is not legal, immigration, financial, medical, therapeutic, hiring, or eligibility advice.