Privacy Policy
How we collect, use, and protect data on the Nurse Residency Directory — operated by Global Cyber Institute, a New York State non-profit.
1. Plain-language summary
The directory is free for nurses. You can browse all 1,213 programs without an account and without any cookie on your device. We do not run advertising pixels, session replay, or behavioral tracking. We do use Google Analytics 4 in a cookieless configuration to count aggregate visits — no cookies are stored, your IP is anonymized before logging, and ad personalization signals and Google Signals are disabled. There are no accounts, no forms, no listing-claim process, and no submission channel on the Site. We never sell, rent, share for advertising, or "monetize" personal data. Period.
2. Who we are
The Nurse Residency Directory ("we", "us", "the directory") is operated by Global Cyber Institute, Inc., a 501(c)(3) non-profit organization registered in New York State. Global Cyber Institute is the data controller for personal information collected through this site.
3. What data we collect
Nothing personally identifying. Browsing does not require an account. We do not load advertising pixels or session-replay code. We do load Google Analytics 4 in a strict cookieless configuration (client_storage: 'none', anonymize_ip: true, allow_ad_personalization_signals: false, allow_google_signals: false) to measure aggregate page views, country, and device class. Google receives a per-request beacon with an anonymized IP, page URL, and standard request metadata; no cookies are stored on your device, no cross-site identifiers are sent, and the visit cannot be tied to advertising profiles. Your IP address may also briefly appear in our hosting provider's edge logs (Vercel) for delivery and abuse-prevention purposes; we do not store, query, or join those logs to anything else.
4. How we use it
We use collected data only to:
- Operate the directory (display listings and count aggregate visits)
- Respond to privacy inquiries and data-subject requests (only to the address you wrote from)
We do not use any data for behavioral advertising, profiling, or training third-party AI models.
5. When we share it
We do not sell, rent, trade, or share personal data for advertising. We share data only with:
- Sub-processors required to run the site:
- Vercel, Inc. — hosting and content delivery (United States). Privacy.
- Resend — retired. Resend previously sent outreach messages to program coordinators about their listings. That campaign was discontinued on 10 September 2026 and no message of any kind is now sent from this site. We retain no active integration with Resend, and nothing on the Site's pages ever contacted it. Privacy.
- Google LLC — (1) Google Fonts CDN serves typefaces; Google may briefly receive your IP for font delivery. (2) Google Analytics 4 in a cookieless configuration (see §3.1) — Google receives an anonymized per-request beacon used to count aggregate visits. We do not use Google Ads, conversion tags, Google Signals, or any Google service for behavioral profiling. Privacy.
- Law enforcement when legally required, with notice to the affected user where lawful.
- Successor entity if Global Cyber Institute's assets are transferred to another non-profit; in such a case, this policy continues to apply.
6. Cookies, pixels & trackers — explicit list
We list every tracking technology used on this site, in plain language, so you can audit us against your network log:
- Cookieless Google Analytics 4 beacon (every page). Configured with
client_storage: 'none',anonymize_ip: true, and ad signals disabled. Does not write any cookie to your device. Google receives an anonymized IP, page URL, and device class per page view. Cannot be joined to advertising profiles. Measurement ID:G-PH5VNTSZB6.
That is the complete list. This site sets no cookies of any kind — there is no sign-in, and no checkout.
We do not use:
- Meta (Facebook) Pixel
- Google Ads conversion tags, Google Signals, or any standard (cookie-based) Google Analytics configuration
- TikTok Pixel, LinkedIn Insight Tag, Pinterest Tag, Twitter/X Pixel
- Hotjar, FullStory, Mouseflow, Microsoft Clarity, or any session-replay tool
- Any cross-site behavioral advertising network
- Any "data broker" sharing arrangement
- Any healthcare-related third-party tracker (the directory is a public information resource, not a covered entity, but we hold ourselves to the same anti-tracking posture that healthcare-pixel litigation has identified as the safe baseline)
Because the only browse-time technology we load is the cookieless GA4 beacon (which sets no cookies and sends no personally identifying data to Google), a cookie-consent banner is not required and would be misleading. We do not display one.
7. Your rights
Regardless of where you live, you can:
- Access the data we hold about you
- Correct inaccurate data
- Delete your account and all associated data
- Export your data in a portable format (JSON)
- Opt out of all marketing emails (we send minimal transactional emails only)
If you are in the European Economic Area, the United Kingdom, California, or another jurisdiction with specific privacy rights (GDPR, UK GDPR, CCPA/CPRA), those rights apply in full. Email privacy [at] globalcyberinstitute.org to exercise any of them.
8. Data retention
We retain personal data only for as long as it is needed to operate the service. When you delete your account, your personal data is removed from production systems within 30 days and from backups within 90 days. Aggregated, non-identifying analytics may be retained indefinitely.
9. Security
Data is encrypted in transit (TLS 1.3) and at rest. Authentication uses magic-link sign-in (no passwords stored on the site). Ownership verification follows the same standards as Google Search Console.
10. Children's privacy
The directory is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16. Nurse residency programs require licensure (which presumes adulthood), so this should never be an issue in practice.
11. Changes to this policy
We will update this policy if our practices change. There are no accounts and no mailing list, so we have no way to notify you directly — material changes are published on this page with a revised effective date at least 14 days before they take effect. Non-material changes (clarifications, formatting, fixes) may be made without notice.
12. Contact us
Global Cyber Institute, Inc. is the data controller. You can reach us at:
New York, NY · USA
New York State
This policy is provided for transparency and is not a substitute for legal advice. Global Cyber Institute reviews and updates this policy annually as part of its non-profit governance practices. A summary of all sub-processors and our anti-tracking posture is also published as a static page at /trust.