Missing User Warnings
Medium
- Confidence
- 80% confidence
- Finding
- The API accepts session-linked assessment data and optional user identifiers, yet the specification provides no privacy, retention, consent, or handling guidance. In a career-roadmap context, this can lead to unnecessary collection or downstream exposure of behavioral/profile data, especially when clients or integrators assume such fields are safe to transmit without constraints.
