Privacy

What this site loads, what it stores, and what it will never ask you for.

This is a public student resource. It has no accounts, no forms, and no login, and it is not a safe place to send anything confidential. Below is a specific inventory of what happens in your browser when you open a page here — read from the site's own code and configuration on 29 August 2026 — rather than a generic policy.

Never send this to this site

Do not submit grades, disability or medical information, financial-aid records, Social Security or student identification numbers, immigration records, private application materials, private correspondence, or non-public contact lists — not through the email links here, and not in a correction request. If a correction requires sensitive detail to make sense, say only that it does, and it will be handled through an appropriate channel.

What loads when you open a page

Three things, and nothing else.

  • The page, stylesheet, and scripts, from this site's own domain. Hosting is Vercel, so Vercel's servers necessarily see ordinary request information: your IP-derived location, browser and device details, the time, the page requested, performance timings, and the referring page.
  • Vercel Web Analytics and Speed Insights, loaded from first-party paths on this domain. They produce aggregate page and performance counts. There is no third-party advertising or marketing tag anywhere on this site.
  • Two typefaces from Google Fonts. The stylesheet requests fonts from fonts.googleapis.com and fonts.gstatic.com, which means Google receives a request from your browser when a page loads. This is the only external host contacted during normal reading.

A content security policy is served with every page that blocks anything beyond that. Framing this site inside another page is refused outright, plugin and object embedding is disabled, and the only place a form may submit is this origin or a mail client. Camera, microphone, and geolocation are disabled by policy header, so no page here can ask for them even if something tried.

What is not stored in your browser

This site sets no cookies of its own, writes nothing to local or session storage, and keeps no campaign or referral parameters between visits. That is a property of the code, not a promise: the site's scripts contain no storage or cookie calls at all.

The search boxes on the opportunity tracker, the student guide, and the glossary run entirely inside your browser. They filter rows already on the page. Nothing you type into them is sent anywhere, logged, or seen by the maintainer — there is no request to send it in.

Where a link takes you, and what it tells them

Most of the value here is in links to other people's sites: employers, courts, agencies, national organizations, and Northeastern's own pages. Once you follow one, that site's rules apply, not this one's.

This site sends a referrer policy of strict-origin-when-cross-origin, which means an external destination learns that you arrived from flexjd-site.vercel.app but not which page you were reading. That matters on the campaign pages, where the topic of the page you came from can itself be sensitive.

Two links go somewhere that does collect information, and both are clearly labelled where they appear: the feedback links open your own mail client and address a message to the student maintainer, and the office-hours link opens Microsoft's booking service, which is operated by Microsoft under Northeastern's arrangements rather than by this site. Read the destination before you send anything, and leave confidential details out.

Information about other people

The site reproduces and links to information that organizations have intentionally made public: posted opportunities, published deadlines, official staff directories, court and agency pages. Public availability is not permission to do anything with it. The working rules here are to use the minimum necessary, preserve the context the source gave it, and never retain a person's details simply because they once appeared in a public posting.

Direct personal phone numbers and individual organiser contact details have been removed from live campaign pages in favour of the office or organization that owns the enquiry. Private student records and secrets are never committed to the public repository; the reporting route for anything found there is in the repository's SECURITY.md.

Asking for review, correction, or removal

Anyone whose personal information appears on this site may ask for it to be reviewed, corrected, or removed, and does not need to give a reason. Naming the page and the information at issue is enough to act on, and requests of this kind are handled before other corrections.

Because the site's history is public, removal from a live page and removal from the repository's commit history are different operations. A removal request is treated as covering both, and a scheduled scan runs weekly over the commit history for anything that should not be there.

Send a privacy request Status & reliance notice

Inventory read from this site's source, scripts, and response headers on 29 August 2026. Previously reviewed 15 August 2026.

Book student office hours Send a correction or suggestion
Built by Aloha AI. Explore related work at RN Builds.