Tenure Hire

Privacy policy

Last updated October 6, 2026

Tenure Hire, by TenureMetrics, helps healthcare employers find and contact clinicians. That work runs on personal information: about the clinicians in our database, about the people at the employers who use the service, and about the people we write to about it. This policy says what we hold on each, where it comes from, how we use and protect it, and what you can ask us to do. It applies alongside our terms of service.

1.Who this covers

Three groups of people appear in Tenure Hire, and this policy has a part for each.

Clinicians are the physicians, nurse practitioners, physician assistants, nurses, nursing assistants and other licensed healthcare professionals in our database, whether or not they have ever heard of us. Customers are the employers that use the service, and the recruiters and administrators on their teams. Prospects are people at healthcare employers we write to about Tenure Hire.

TenureMetrics decides how and why this information is processed, which makes us the controller of it. When a customer takes information out of the service, for instance by receiving a clinician's reply, the customer is responsible for what they do with it from then on.

2.Clinicians: what we hold and where it comes from

For a clinician, we may hold a name, profession, specialty, work history, education, certifications, the state licences they hold and their status and dates, an NPI number, a general location (city and state), contact details such as an email address or phone number, a CV, and the record of any contact between them and an employer through Tenure Hire: the message sent, whether they replied, and what they said. We do not hold Social Security numbers, payment details, health information about the clinician themselves, or a licence record's personal details beyond those listed here.

This information comes from a few places.

  • Public professional records: state licensing boards' public licence files, the National Plan and Provider Enumeration System (the NPI registry), and facility datasets published by the Centers for Medicare and Medicaid Services.
  • Information clinicians make available to employers on job boards and professional networks, including the CVs they post there, reached through accounts our customers hold with those boards.
  • Information clinicians give us directly: an application, a profile, a message, a reply to an employer, or a conversation with our screening assistant.
  • Information customers give us about clinicians they already know, such as a contact list or notes from a call.

Where a record came from is kept internally so we can answer questions about it; it is not shown to customers. We make every effort to keep records accurate: licences are checked against the issuing board's public record where we can, names and specialties against the NPI registry, and records are refreshed as their sources change. The information is still only as accurate as its sources, and we make no claim that any record is complete or current. If something about you is wrong, section 10 says how to have it corrected.

3.Clinicians: how it is used

We use clinician information for one purpose: to let healthcare employers find clinicians who fit a role and to put them in touch. That means matching a clinician to a role by profession, specialty, licensure and location; showing an employer the professional facts about them, with the sources checked where possible; sending an employer's message to them; routing their reply back; and keeping the record of that contact so the same employer does not write to them twice.

Our legal basis, where one is required, is our and our customers' legitimate interest in recruiting for healthcare roles, balanced against the clinician's interests: we hold professional information, we use it only for recruiting, and we stop when asked. Contact details are shown to a customer only with a plan that includes direct contact, and a clinician's reply is shared only with the employer they replied to.

We do not sell clinician information, we do not use it for advertising, and we do not share it with anyone other than the employer whose role it concerns and the service providers listed below.

4.Customers and their teams

When an employer opens an account we collect the company's name, the names and work email addresses of its users, passwords (stored hashed), billing details handled by Stripe, and the roles, messages, notes, contact lists and reports the team creates. We record what each user does in the service, such as searches run and messages sent, so the account's administrators can see their team's activity in reports and so we can keep the service secure.

We use this to provide and bill the service, to support the account, to keep it secure, and to tell administrators about the account: a run that finished, a reply that came in, a payment that failed, a change to these documents. We may also tell customers about changes to the product. We do not sell customer information or use it for advertising.

5.People we write to about Tenure Hire

We keep a list of people in leadership, hiring and human resources roles at healthcare employers, with their name, title, employer, work address, work email and phone, taken from business directories and public professional sources. We use it to tell them about Tenure Hire and to answer when they write to us. Every email we send carries an unsubscribe link, and we never write again to someone who has used it.

If you write to us through the contact form on our site, we keep your message and use your details to reply.

6.Automated tools and AI

Tenure Hire reads CVs with software running on our own servers to pull out the facts shown on a record. Some features draft text with the help of AI models from Anthropic: for example a message an employer is about to send, a summary of a screening conversation, or an answer from the assistant inside the product. Where a model processes clinician information, we send the fields the task needs and nothing more, and the provider does not use what we send to train its models. Our screening assistant, where an employer uses it, holds a voice or text conversation with a clinician who has chosen to take part, and the clinician is told at the start that they are speaking with an automated assistant.

No automated decision in the service produces a legal or similarly significant effect on a clinician by itself. The service finds and introduces people; employers make the decisions.

7.Who we share information with

We share personal information with the service providers that run parts of Tenure Hire for us, under contracts that limit them to that purpose:

  • Hetzner, which hosts the service and stores its data and files;
  • Stripe, which handles payments and holds customers' card details, which never reach our servers;
  • Postmark, which delivers our email;
  • Twilio, which delivers text messages;
  • ElevenLabs, which provides the voice for the screening assistant and transcribes those conversations;
  • Anthropic, whose models draft text and summaries as described above;
  • Voyage AI, which turns text into the numerical form that powers search;
  • Laravel Nightwatch, which monitors the service for errors and slowness; it does not receive the contents of requests.

We share a clinician's information with the employer whose role it concerns, as described in section 3. When an employer connects a job board account, messages to clinicians on that board are sent through the board under the board's own terms and privacy policy. We may also disclose information when the law requires it, to protect the rights or safety of anyone, or as part of a sale or merger of our business, in which case this policy continues to apply to it.

8.Where information is kept and for how long

The service runs on servers in the European Union, and our service providers process information in the United States and the European Union. Wherever it is, it is protected as this policy describes.

We keep a clinician's professional record while it is useful for recruiting, and we refresh it from its sources as they change. The record of a contact is kept for as long as the employer's account exists, so the employer can see who they have reached. A clinician who asks us to stop keeps a minimal entry, their name and contact details, for the sole purpose of making sure nobody contacts them again. A customer's content is deleted within 30 days of the account closing, except what we must keep for legal, accounting or security reasons. Backups are kept for a limited period and then overwritten.

9.Security

Information travels encrypted between your browser and our servers and between our servers and our providers. Access inside the service is limited by role, and a customer's team sees only its own account. Passwords are stored hashed. CVs and other files are stored in private storage that only the service can read. We log access and changes, we take daily backups, and we monitor the service for faults. No system is perfectly secure, and if we learn of a breach that affects you we will tell you and the authorities as the law requires.

10.Your choices and rights

Anyone can ask us what we hold about them, ask us to correct it, ask us to delete it, or ask us to stop using it. Clinicians can ask us to stop contact from Tenure Hire altogether, and we will honour that from every account. Depending on where you live, you may have further rights under laws such as the California Consumer Privacy Act or the General Data Protection Regulation, including the right to object to processing, to receive your information in a portable form, and to complain to your data protection authority. We respond to every request within the time the law allows and usually sooner, and we do not treat anyone differently for making one.

To make a request, write to hello@tenurehire.com from the address we hold for you, or tell us how to confirm it is you. We will not sell your information, so there is nothing to opt out of there; we do not share it for cross-context behavioural advertising either.

11.Cookies

The service uses two cookies, both needed to work: one that keeps you signed in and one that protects forms against forgery. We set no advertising or analytics cookies and we do not track you across other sites. Because of this, there is no cookie banner. Your browser may remember small preferences, such as a chosen tab, on your own device only.

12.Children

Tenure Hire is for working professionals and employers. We do not knowingly collect information about anyone under 18, and we delete it if we find we have.

13.Changes to this policy

When this policy changes, we post the new version here with a new date. For changes that affect how we use information about customers, we email account administrators before they take effect. For changes that matter to clinicians, we also note the change here for at least 30 days.

14.How to reach us

TenureMetrics is responsible for this policy and for the information it describes. Write to hello@tenurehire.com with any question or request, and we will answer.