Security & data practices

Security Starts With Collecting Less

No security program can eliminate every risk. TalentAid reduces exposure by limiting sensitive-data collection, separating different data purposes, and keeping optional advertising outside the core career decision flow.

Last updated

August 17, 2026

Plain-language commitment

We explain what TalentAid does, what it does not do, and where you should verify an important decision with an official source.

TalentAid is not designed to store medical records or clinical information.

Anonymous usage analytics are separated from information users intentionally save to an account.

Security claims are kept evidence-based: we do not advertise certifications TalentAid has not actually obtained.

Data minimization

The first safeguard is not collecting information the product does not need. Core career exploration does not require an account, and TalentAid does not need a diagnosis, medical history, health-card number, Social Insurance Number, bank information or identity document to explain a career pathway.

Separation of data purposes

TalentAid's current first-party analytics are designed around anonymous session-level events rather than names or contact details. Information intentionally saved to an account serves a different purpose and should not be silently merged into advertising profiles.

Location preferences are used to localize Canadian career information. Users can choose their location rather than being required to provide precise device location.

Access and administrative controls

Administrative data-management areas are intended for authorized administration rather than public access. Application permissions, backend functions and data schemas should continue to follow least-privilege principles as the team and feature set grow.

Authentication credentials and infrastructure secrets should be kept out of public client code. Public configuration values such as an AdSense publisher identifier are different from private secrets and should be handled accordingly.

Service providers and infrastructure

TalentAid depends on technology providers to operate the application. Before adding a provider that will handle personal information, the business should assess what data the provider receives, why it is needed, where it may be processed, retention, access controls, contractual protections and incident obligations.

We do not claim that TalentAid has a particular security certification, audit report or compliance attestation unless that assessment has actually been completed.

Advertising isolation

Optional advertising technology is not required for core career navigation and is gated by the user's advertising choice. Advertising partners do not receive authority to alter verified career facts or access medical records because TalentAid does not ask users to provide those records in the first place.

Security incidents

If TalentAid becomes aware of a suspected confidentiality or security incident, the appropriate response depends on what information was involved, the likelihood and severity of harm, applicable law and affected providers. The business should maintain an internal process to document, investigate, contain, remediate and make legally required notifications when thresholds are met.

Incident-response and breach-register procedures should be operational business controls, not merely statements on a website.

Responsible product use

  • Do not enter passwords, banking credentials, Social Insurance Numbers, health-card numbers or identity documents into Career Advisor.
  • Do not upload or paste medical records, diagnoses, treatment notes or insurance records for a career-planning question.
  • Use official regulator and institution sites for applications that legitimately require sensitive documentation.
  • Report unexpected account or security behaviour through the designated business contact once that contact is configured.