Privacy Policy
Effective date: September 23, 2026
Summary
MVQS Online is operated by McCroskey Vocational Quotient System (“MVQS”) and is a software platform for licensed vocational rehabilitation professionals to perform McCroskey Vocational Quotient System analyses. We store account credentials (email and hashed password), profile information, and the evaluee case data that evaluators enter on behalf of their clients. Only authenticated users with an active account can access the system; no data is shared with third parties for marketing purposes. Data is encrypted in transit (TLS); access is limited by role-based access control and per-evaluator access checks on every request, with optional two-factor authentication (TOTP). The database has row-level security enabled, so it refuses direct access with the public API key.
1. Who We Are
McCroskey Vocational Quotient System (“MVQS,” “we,” “us”) operates MVQS Online. For account and profile data we are the data controller. For evaluee case data, the evaluator (or their organization) is the controller and we act as a processor on their instructions under the Terms of Service.
- Contact email
- info@mccroskeymvqs.com
2. What Data We Collect
Account data
When you create an account, we collect your email address and name and record the time you accepted the Terms of Service and this Privacy Policy. Your password is processed by Supabase Auth and stored only as a bcrypt hash — we never store or transmit your plaintext password. If you turn on optional two-factor authentication, a TOTP factor is registered with Supabase Auth. When an account is created we also notify our administrator by email of the new account's name and email address (delivered through Resend, see Section 5).
Profile data
We store your assigned role (admin, evaluator, or viewer), your account status, and your last-viewed evaluee state so the application can resume where you left off.
Evaluee case data
Evaluators enter case data on behalf of the individuals they are evaluating. This data may include:
- Personal identifiers: full name, date of birth, last four digits of SSN, contact information, and address
- Work and case context: work location, employer, job title, referral reason, diagnosis, and case notes
- Assessment data: standardized test scores, worker trait ratings, work values, and vocational profiles
- Occupation data: DOT codes, earning-capacity (ECLR) estimates, and job-match results generated by the analysis pipelines
This data is owned by the evaluator (or their organization) and is processed by us solely to provide the analysis service. Evaluee records are isolated per evaluator by the application's access checks on every request: an evaluator can open only the evaluees they created, and MVQS Online administrators can open all. Row-level security on the database additionally blocks any direct database access with the public API key.
MVQS Online is a single shared workspace. The referral-source (client) directory shows each evaluator the shared General client plus the clients they created or that are linked to their own evaluees; administrators see the full directory.
Technical data
When an administrator performs a privileged action (such as changing a user's role or account status, resetting a password, or setting a temporary password), the system records an audit log entry containing: the action type, the acting administrator's user ID and email, the target user's email, a timestamp, and the requesting IP address and user-agent string. If a request fails with a server error, we also record the time, the request method and address, and the error details (message and stack trace) in our application logs and, when configured, send the same details to our operators by email through Resend (see Section 5).
Connector access log
If you connect Claude to your account (see Integrations you connect in Section 5), the system keeps a connector access log. It records one entry when you approve or decline a connection, one for each request Claude makes through the connector, and one for each request it refuses because the account is not allowed to use the connector. Each entry contains: your user ID, the identifier of the connecting application (the OAuth client ID), the kind of event, the name of the tool Claude called, the ID of the case it concerned, whether the request succeeded, the reason a request was refused, a one-line summary of a change drawn from a fixed vocabulary (for example “ratings: 24 set, 0 deleted”), the requesting IP address, and a timestamp. It never records what Claude asked, what was answered, or any evaluee’s name or case content. The log is append-only and is kept like the audit log (see Section 7). You can see your own entries under Account → Connected apps; administrators can see every user’s entries on the Audit log’s Connector tab.
Cookies and browser storage
We use only strictly necessary cookies. None are used for tracking, advertising or analytics:
sb-<project>-auth-token(may be split into numbered parts) — the Supabase Auth session that keeps you signed in. Set on sign-in; removed on sign-out.sb-<project>-auth-token-code-verifier— a short-lived code verifier set only while an email sign-in, password-reset or confirmation link is in flight.mvqs_mfa_pending— set for accounts with two-factor authentication after a password sign-in, until the authenticator code is verified; expires within one hour.mvqs_sudo— administrators only; set for five minutes after re-entering a password to perform a privileged action.mvqs_guided— set when you leave guided practice in the training walkthrough, so the guide stays paused for that practice run; cleared when you resume or start over, or at the end of the browser session.
Your theme preference (light/dark) and your dismissal of the cookie notice are kept in your browser's local storage, not in cookies, and are never sent to us.
3. How We Use Your Data
- To authenticate your identity and maintain your session
- To enforce role-based access control and account-status checks
- To provide the vocational quantification analysis service
- To generate reports based on evaluee data you have entered
- To maintain an audit log of privileged administrative actions
- To keep a log of what the Claude connector read or changed, when you have connected it
- To comply with applicable legal obligations
- To detect and respond to security incidents
We do not use your data for marketing, advertising, or profiling.
4. Legal Bases for Processing (GDPR / UK GDPR)
If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
- Contract: Processing your account data and delivering the analysis service is necessary to perform the agreement between you and McCroskey Vocational Quotient System.
- Legitimate interests: We maintain an audit log of administrative actions to protect the security and integrity of the platform. Our legitimate interest is overridden only where your fundamental rights require otherwise.
- Legal obligation: We may process and retain data where required by applicable law.
5. Who We Share Data With
We share data only with the sub-processors listed below, solely to the extent necessary to operate the service. We do not sell personal data. We do not share personal data for marketing or advertising purposes.
- Supabase Inc. — Provides authentication (Supabase Auth) and the managed Postgres database. Infrastructure is hosted on Amazon Web Services. Supabase processes credentials, profile data, evaluee case data, and audit log entries on our behalf.
- Railway Corp. — Hosts the Next.js application runtime. Railway processes request/response data in the course of serving the application.
- Resend, Inc. — Delivers our transactional email: account confirmation, password reset and sign-in links, the internal notification to our administrator when an account is created, and (when configured) internal server-error notifications to our operators. Resend processes the recipient email address and the message content: for the administrator notification, the new account's name and email address; for an error notification, the error details and the address of the request that failed. Resend does not receive evaluee case records.
Integrations you connect
MVQS Online can be connected to Claude, the AI assistant made by Anthropic, PBC, through the MVQS connector. We send nothing to Anthropic on our own, and Anthropic is not one of the sub-processors listed above: data reaches Claude only if you connect it yourself — you add the connector in Claude, sign in to MVQS Online with two-factor sign-in, and approve the connection on a page that lists what Claude will be able to read and, when the administrator has enabled writes, change.
Once connected, each time you ask Claude about one of your cases the connector sends Claude the case data it asks for — which can include the case’s identification, work history, worker-trait profiles, matched job sets and job lists, and the occupational requirements of a job, as listed on that page — and Anthropic processes it under the terms of your own Claude account and under your own consent, given when you approved the connection. You can revoke that consent at any time by removing the connector in Claude (Customize → Connectors): the connector then answers nothing further, and the connector access log described in Section 2 is kept.
6. International Data Transfers
Our sub-processors may transfer or store personal data outside the European Economic Area. Where such transfers occur, they are made on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission, or another lawful transfer mechanism recognized under applicable data protection law. For further information about the safeguards in place, contact us at info@mccroskeymvqs.com.
7. Data Retention
- Account data: Retained until you request deletion of your account. After deletion, your Supabase Auth record and application profile are removed.
- Evaluee case data: Retained until the controlling evaluator deletes it. You are responsible for managing the retention of case data in accordance with your professional obligations.
- Audit log entries: The audit log is append-only and is retained for as long as the account it relates to exists. Individual log entries cannot be deleted by users.
- Technical data (IP / user-agent in audit log): Retained as part of the audit log record for the same period.
- Connector access log entries: Kept like the audit log: append-only and retained, IP address included, for as long as the account they relate to exists. Individual entries cannot be deleted by users.
8. Your Rights
Depending on your location and applicable law, you may have the following rights with respect to your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that inaccurate data be corrected.
- Deletion: Request deletion of your account and associated personal data, including audit log and connector access log entries that relate to it, unless we are required by law to keep them.
- Export / portability: Request your data in a structured, machine-readable format.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Objection: Object to processing carried out on the basis of legitimate interests.
- Supervisory authority: Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at info@mccroskeymvqs.com. We will respond within the timeframe required by applicable law (generally 30 days).
9. Security
We implement the following technical and organizational measures to protect your data:
- TLS encryption for all data in transit
- bcrypt hashing for all passwords (via Supabase Auth)
- Optional two-factor authentication (TOTP)
- Role-based access control (admin / evaluator / viewer)
- Account-status enforcement: an administrator can deactivate an account at any time, and deactivated accounts lose access immediately
- Per-evaluator data isolation enforced by the application on every request: evaluee records are accessible only to their creating evaluator and administrators
- Postgres row-level security enabled on every application table, blocking direct database access with the public API key
- Append-only audit log for all privileged administrative actions
No method of transmission or storage is 100% secure. If you become aware of a security issue, please contact us immediately at info@mccroskeymvqs.com.
10. Children
MVQS Online is a professional software platform not directed to children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently received information from a child, please contact us at info@mccroskeymvqs.com so we can delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page. We encourage you to review this page periodically. Continued use of the service after the effective date of a revised policy constitutes your acceptance of the changes.
12. Contact
Questions or requests regarding this Privacy Policy may be directed to: