Privacy Policy
What we hold, and who can see it.
Menehune Health holds the documents that prove you are qualified to work. That is sensitive material, so this page is written to be read rather than skimmed past. It says plainly what we collect, why, who it goes to, and what we have not built yet.
Last updated September 29, 2026
Scope
This policy covers the Menehune Health platform — the website, the installable web app, and the APIs behind them. It applies to two kinds of people: providers (clinicians who keep a credential wallet and look for work) and facility users (hospital, locum, and agency staff who review candidates and hire).
Menehune Health is not a patient-facing service. There is no patient portal, no charting, and no place for clinical records. We do not collect patient health information. The health-adjacent data we do hold is about you as a professional — your immunization records, TB test, and drug screen, because facilities require them before you can work.
We do not sell your personal information, and we do not share it with advertisers.
What we collect
Grouped by what it actually is:
Account data
Your name, email address, and phone number. Your role (provider or facility user), and for facility users the organization you belong to. Accounts are invite-only, so we also keep the invitation record that created yours. Passwords are handled by our authentication provider and are never visible to us in readable form.
Professional data
Provider type and specialties, license and certification details (number, issuing body, state, issue and expiration dates), NPI number, education, work history, professional memberships and references, EMR systems, years of experience, and your bio. If you enter them, we also store the billing identifiers no public registry exposes — your Medicare PTAN and state Medicaid number — so credentialing forms can fill themselves in.
Verification identifiers
If you hold a nursing license, we ask for your birth year and the last four digits of your Social Security number. These exist for exactly one purpose: NCSBN requires them to match you to the right record in the NURSYS national license database. We never ask for a full SSN. The last four digits are encrypted at rest, used only server-side to build the NURSYS request, never returned to your browser, and never shown to a facility. NURSYS enrollment also requires a physical address, so we store the street address you provide for that purpose.
Documents you upload
State licenses, board certifications, life-support cards, malpractice insurance certificates, immunization and titer records, TB tests, drug screen reports, background check results, case logs, your CV or résumé, a government-issued photo ID, and a profile photo. Once you are hired through the platform, your private file cabinet also holds contracts, timesheets, and pay and tax documents you put there.
Placement records
If you are placed at a facility through Menehune Health, we keep a record of the placement: the facility, your role, the start and end dates, the agreed rate, and whether the placement is active, completed, or cancelled.
Availability and job preferences
Your weekly availability grid (day, swing, night, on-call), blackout dates, the date you are available from, desired pay range, job types and shift preferences, willingness to travel and travel radius, and your city, state, and ZIP.
Timekeeping data
If you are placed at a facility that uses geofenced timekeeping, each punch records the timestamp and your approximate location — latitude, longitude, the accuracy your device reported, and the computed distance from the work site. We capture this only at the moment you tap to clock in or out. The app does not track your location in the background or between punches. A punch outside the fence is flagged for the approving manager; it is never blocked.
Usage and technical data
Standard server and application logs from using the site, including IP address, browser and device information, and timestamps. We keep an audit log of sensitive actions (for example administrative changes and document access) so we can investigate problems. If you turn on push notifications, we store the subscription endpoint your browser issues.
Why we collect it
- Account data
- To create and secure your account, to sign you in, and to contact you about your account or a facility you are talking to.
- Professional data
- To build the profile facilities evaluate you on, to match you to real openings, and to auto-fill credentialing applications instead of making you re-type your history for every facility.
- Verification identifiers
- Only to run your NURSYS license verification with NCSBN. Nothing else uses the SSN last four or the birth year.
- Documents
- To build your credential wallet, track expiration dates, generate your credentialing packet, and show a facility the credentials you have chosen to share with them.
- Placement records
- To run the placement, pay and bill for the work, and give credentialing offices a verified record of where you have worked through NAMSS PASS (section 5), unless you opt out.
- Availability and preferences
- To match you to shifts and to tell you when something fits — that is the point of keeping the grid current.
- Timekeeping data
- To record the hours you worked, let the facility manager approve them, and produce an accurate invoice. The location on a punch is evidence that the punch happened at the work site.
- Usage and technical data
- To keep the service running, debug problems, and detect abuse or unauthorized access.
Email and notifications
We send credential expiration reminders as a license or certification approaches its renewal date, plus a periodic recap of your account. These are on by default because a lapsed license costs you shifts. You can turn them off in your notification settings, and every one of these emails carries a link back to that page. Messages tied to something you are actually doing — a password reset, a security notice, a new message from a facility, an update on an application or placement — are part of the service rather than marketing.
Who sees your data
This is the section that matters most if you are a provider. You choose how much of your profile each category of employer can see — hospitals, locum companies, and staffing agencies are set separately, because they are not the same kind of viewer.
Full
Everything: your full legal name, email, phone, street address, NPI, license numbers, and downloadable credential documents.
Summary
Your complete professional detail — credentials, work history, education, dates and statuses — but no contact information, no identifiers, and no documents. Your name appears as your first name and last initial.
Anonymous
A de-identified card only: specialty, general region, experience, and credential score. Nothing claimable.
Hidden
Not discoverable by that category at all.
By default hospitals get Full, anesthesia groups get Summary, and locum companies and agencies get Anonymous. You can change any of them, and a single master switch hides your profile from everyone at once. The redaction happens on our servers before the data is sent — a viewer below Full is never shipped your contact details or license numbers in the first place.
A relationship changes this. If you apply to a facility’s posting, or you are placed with them, that facility gets the Full view regardless of your category setting. You engaged them on purpose; they need to be able to reach you. Turning your visibility off later removes you from search but does not retract what a facility you already engaged can see.
What a facility never sees: your private file cabinet — contracts, timesheets, pay and tax documents, and your contacts — and the last four of your SSN. Those live in private storage scoped to your account, and the hospital side of the platform has no path that reads them.
What you never see: the boundary runs both ways. When a facility marks your profile or a credential as “reviewed,” that mark is private to that facility. It is not shown to you, it is not shown to any other facility, and it never changes the status of your credential. The same is true of hiring paperwork a facility attaches to you on their side.
Menehune Health staff can access account data when it is necessary to operate the platform — investigating a bug, answering a support request, or reviewing a credential. Administrative actions are recorded in the audit log.
Service providers and verification sources
There are three different things in this section, and it is worth keeping them apart: vendors that process data for us, registries we check you against, and one registry we contribute to.
Vendors that process your data for us
These companies hold or handle your data as part of running the service:
- Supabase — Authentication, the application database, and private file storage. Your account record, your profile, and every document you upload live here.
- Vercel — Application hosting and server logs. Requests to the site pass through their infrastructure.
- Resend — Sends our email — verification, password resets, expiration reminders, and notifications. They receive your email address and the message content.
- OpenAI — Reads documents you upload so the wallet can fill in fields for you — license numbers, dates, vaccine doses, résumé content. The document image or text is sent to their API for that parse.
- Anthropic — Used for the credentialing form-filler, which maps the fields of a blank facility form. Blank forms, not your personal data, are what this step reads.
- Browser push services — If you enable push notifications, delivery goes through the push service your browser or operating system uses (for example Apple, Google, or Mozilla).
Registries we check you against
These are official sources we query. We do not give them your documents or hand them your account; we send the identifying details needed to look you up and we record what comes back.
- NPPES (NPI Registry) — Public CMS registry. We look up your NPI number to confirm it is active and matches your name.
- OIG LEIE — The HHS exclusion list. We check whether you appear on it.
- SAM.gov — The federal exclusions system. Same purpose as OIG.
- OFAC sanctions lists — Through the U.S. government’s Consolidated Screening List (Trade.gov), we check your name against the Treasury OFAC sanctions lists. A possible match is flagged for a person to review; it never blocks your account and never counts against your score.
- State licensing boards — Some states publish their license rosters as public data. For those states we send your name or license number to the state’s public data service to find your license. For a few others we search a copy of the published roster that we keep ourselves, which sends nothing.
- NCSBN / NURSYS — Primary-source nurse license verification. This one receives more: to enroll you, we send your name, license details, birth year, address, and the last four of your SSN. NCSBN returns your license status, compact status, expiration, and any discipline records, and keeps monitoring the license for changes.
- NAMSS PASS — A practitioner affiliation registry (described below). We may send your NPI to confirm the work history you list, and request a verification letter for a specific affiliation.
A registry we contribute to: NAMSS PASS
NAMSS PASS is a practitioner affiliation registry from the National Association Medical Staff Services. Hospitals, health plans, and credentialing offices use it to confirm where a clinician has worked, instead of writing to each organization for a letter. Menehune Health contributes the placements it arranges, because those are facts we know first-hand.
What we may share. When you are placed through Menehune Health: your name, NPI, provider type, and specialty; the facility’s name, NPI, city, and state; your role; the placement’s start and end dates and whether it is active or completed; whether the placement was in good standing, as NAMSS PASS defines it; and an internal reference number so we can correct a record later.
What we never share. Your date of birth, any part of your Social Security number, your license numbers, your contact details, your documents, or work you found on your own. A work history entry you typed, or one that came from your CV, is your statement: we may check it against NAMSS PASS, but we never send it as our own record.
Who sees it. Credentialing offices that use NAMSS PASS can see these records and request a verification letter when they credential you. That is the purpose: it saves you from chasing affiliation letters.
Your visibility settings do not apply here. The levels in section 4, including the switch that hides your profile, control what facilities see inside Menehune Health. A placement shared with NAMSS PASS is a record of work you did, and the control over it is the opt-out in section 7.
We may also disclose data if the law requires it, or to protect the rights and safety of our users or the platform.
Security
What is actually in place:
- All traffic to and from the platform runs over encrypted HTTPS connections.
- The last four digits of your SSN are encrypted at the field level before they are stored. The decrypted value is only ever assembled server-side to build a NURSYS request.
- Uploaded documents are kept in private storage buckets — not public URLs. They are opened through short-lived signed links, which expire (one hour by default) and are generated only for a request our server has already authorized.
- Every request is authenticated and authorized on the server against the account making it. Access to the platform is invite-only.
- The separation between a provider’s private files and what a facility can read is enforced in code and covered by automated tests.
What we do not claim: Menehune Health does not hold a security or privacy certification, and this page is not a claim of HIPAA compliance. We are not a covered entity, and we are not acting as a business associate. We hold professional credentials, not patient records. No system is perfectly secure, and we will not pretend otherwise — if we learn of a breach affecting your information, we will notify you.
Your choices and rights
- Control who sees you. Set the visibility level for hospitals, locum companies, and agencies independently, or use the master switch to hide your profile from search entirely. You can also mark yourself as open to offers or only passively available.
- Control your email. Turn credential reminders and the recap email off in your notification settings at any time.
- Correct your profile. Every profile field is editable. You can replace or delete any document you uploaded — deleting removes both the record and the stored file.
- Take a copy with you. You can download any document you uploaded, and generate your credentialing packet as a single PDF to keep or send anywhere, including to facilities that are not on the platform.
- Opt out of NAMSS PASS sharing. Write to claudia@menehune.io and we will stop contributing your placement records to NAMSS PASS (section 5).
Export and deletion — honest status. We have not built self-service account export or self-service account deletion yet. We are building that tooling. Until it ships, email us and we will handle your request manually: a full copy of your data, or deletion of your account and the files attached to it. Some records may be retained after deletion where we are required to keep them — see retention below.
Data retention
We keep your account, profile, and credential data for as long as your account is active, because that is the product — a wallet that stays current and follows you between facilities. Credential documents remain until you delete them or delete your account.
Some records outlive the account. A completed placement, an approved timesheet, and an invoice are business and financial records, and a verification result is evidence of what a primary source said on a given date. We expect to retain those, and our audit log, after an account closes. We will not keep your uploaded documents longer than we need to.
Placement records already shared with NAMSS PASS are held by NAMSS PASS under its own terms. If you opt out or close your account, we stop sending new records, and we will ask NAMSS PASS to remove the ones we sent where its process allows.
Children
Menehune Health is for licensed and credentialed healthcare professionals and the facility staff who hire them. It is not directed to anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe a minor has created an account, contact us and we will remove it.
State privacy rights
Depending on where you live, state law may give you specific rights over your personal information — for example the right to know what is collected, to request a copy, to request correction or deletion, and not to be discriminated against for exercising those rights. California residents have rights of this kind under the CCPA as amended by the CPRA, and several other states have comparable laws.
Two things we can state now without qualification: we do not sell personal information, and we do not share it for cross-context behavioral advertising. To exercise any right, contact us using the details below.
Changes to this policy
We version this document. Every substantive edit gets a new version date, shown at the top of this page, and the platform records which version you accepted and when — so “what did I agree to, and when” stays answerable after an edit.
When we make a material change, we will update the date here and notify account holders by email or in the app before or when the change takes effect. Minor clarifications and wording fixes will be reflected on this page without a separate notice.
Contact
Questions about this policy, a request for a copy of your data, or a request to delete your account — all go to the same place.
Privacy contact
claudia@menehune.io
Menehune Health · Provider credentialing and direct hospital hiring
Related reading: the Provider FAQ explains the same privacy behavior in practical terms — what a hospital sees, where your SSN goes, and how to hide your profile.