Privacy Notice
Effective 26 September 2026 · version 2026-09-26
1. Who we are and how to contact us
CertAscent ("we") is the controller of the personal data described here. Operator: [legal entity name, registered address]. Privacy contact: privacy@certascent.com (placeholder). Data Protection Officer: [name / contact, or "not required" once assessed]. EU representative (GDPR Art. 27) and UK representative: [appoint if the operator has no EU/UK establishment]. This notice covers the CertAscent web app and API. It is a template: have it reviewed by qualified counsel before relying on it.
2. Local mode: nothing leaves your browser
If you use CertAscent without an account, your plan (profile, tracked certifications, study log, notes, spending, notebooks) is stored only in your browser's localStorage. Nothing is sent to our servers. Clearing your browser data deletes it; export a backup (Data & backup page) if you want a copy.
3. What we collect and why
Account: email, display name, password hash (never the password), passkey public keys, authenticator-app secret (encrypted), recovery-code hashes, linked Google/Microsoft/Apple identity (provider id and email), terms acceptance. Purpose: provide and secure your account. Legal basis: contract.
Sessions and security logs: IP address, browser user agent, sign-in times, security events (sign-in, MFA and password changes, org role changes, deletions). Purpose: keep accounts secure, detect abuse. Legal basis: legitimate interests (security) and contract.
Workspace: your plan, study log, CPE log, spending, notes, notebooks, flashcards, credential links. Private to you and synced across your devices. Legal basis: contract.
Notebook sources: text you paste and PDFs you upload, kept until you delete them. Legal basis: contract.
AI assistant and notebook: your questions and the replies, see "AI processing". Legal basis: contract.
Support requests and feedback: what you write, the module you were in and the diagnostics you chose to attach (app version, route, coarse browser/OS, screen size, locale, last error). Legal basis: contract / legitimate interests (improving the service).
Billing: plan, status, seats, renewal dates and the payment provider's customer and subscription ids. We never see or store card details. Legal basis: contract and legal obligations (accounting).
Referrals (when the program is live): a hashed referral code, referral status and reward records; referrers never see who they referred. Legal basis: contract (program terms).
Marketing e-mail: only if you turn on "Product news" (Account → Privacy). Legal basis: consent, withdrawable at any time.
Mobile number (optional): used to help you recover your account and to stop one person opening many free accounts. It is required only while we can verify it by text message; today it is optional. Stored encrypted, with a keyed fingerprint for matching. Legal basis: contract / legitimate interests (security, fraud prevention).
Country, city and profile answers: your country decides which privacy rules apply to you (see "Rules for your country") and your regional price; city and your focus answers personalise the app. Legal basis: contract.
Sign-in history: time, method, IP address, browser and approximate location (country/city from the network, rounded; no GPS) of each sign-in, kept 180 days, to spot sign-ins that weren't you. Legal basis: legitimate interests (security).
Consent records and requests: when you give or withdraw a consent (with the wording version and the privacy regime at the time) and a log of the privacy requests you make (type, dates, outcome; no content), so we can prove we honoured them. Legal basis: legal obligation.
We do not use your data for advertising or for profiling with legal or similarly significant effects. See "Account protection" for the one automatic limit we apply.
4. Account protection (duplicate accounts and trial abuse)
To keep trials fair (one free trial per person), we compare keyed fingerprints (never the raw values) of the device, network and mobile number used at sign-up with other accounts, for 12 months, and of the e-mail address, mobile number, device and payment method of accounts that already had a trial or a subscription, for 24 months. When they match, the account automatically does not get a second free trial (it can still subscribe), and for duplicate sign-ups a staff member reviews it. This does not close or suspend your account, and it is reversible. You can ask for a human review at any time through Help & feedback → Account; a person checks the case and lifts the limit if it was wrong. Legal basis: legitimate interests (fraud prevention). [Counsel: confirm this is not a decision under GDPR Art. 22.]
5. Single sign-on and directory data from your organization
If your organization signs you in through its identity provider (SAML single sign-on) or provisions accounts through SCIM, we receive from that organization, not from you: your e-mail, name, an identifier from their system, group membership and whether your account is active. When an organization invites you, its administrator gives us your e-mail address for the invitation. Your organization is the controller of that data and we process it on its behalf; ask your organization's administrator about it. Accounts created by an organization can be removed when the organization deprovisions them (with a grace period). Organizations with audit export keep a tamper-evident record of actions in the organization (who, when, IP address) for 1 to 7 years, as agreed with them. [Counsel: org audit retention and basis.]
6. Organizations
If you join an organization, its owners and admins see your name, email and role. They can never read your workspace. If you turn on progress sharing for that organization (off by default, only you can change it) they see a summary: certifications certified / in progress / planned, hours logged, your next exam and skill areas by level. Never notes, costs, credential links or notebooks. Support requests you raise in an organization's context (except security reports) are visible to its admins. For organization plans, the organization may have its own agreement with us (a data processing agreement) covering its members' use.
7. AI processing
The AI features are optional and only run when you use them. Cert Coach: your message (after we strip e-mail addresses, phone numbers, card-, ID- and key-like strings), up to 20 earlier messages of that conversation, and a minimal view of your plan (certification ids, statuses, dates, hours, experience level, weekly hours, budget, interests) are sent to Anthropic's API. Never your name, email, notes, credential links or other people's data. Study notebook: when you ask about or generate study material from sources, the selected sources (pasted text, notes and uploaded PDFs, as they are) and your question are sent to Anthropic. For link sources, Anthropic's service fetches the page for you: the website sees a request from Anthropic, and our server never fetches it. Conversations are stored for 30 days and then deleted automatically; you can delete one or clear all of them earlier (Account → Privacy). Anthropic processes this data as our processor under its commercial terms, does not use it to train models, and may retain it briefly for abuse monitoring under those terms. AI answers can be wrong; the assistant never changes your plan without your click.
8. Anonymous error reports (beta)
While the platform is in beta, the app sends a short technical report when something breaks: the error text, the page name, the app file and line, and your browser type (for example "chrome"). Before it is stored, the server removes anything that looks like an email address, identifier, token or web address details; reports are not linked to your account or IP address, are combined with identical reports, and are deleted after 30 days. Lawful basis: our legitimate interest in keeping the service working. You can turn this off at any time on the Status page (it then stays off in that browser), and it is also off when your browser sends a Global Privacy Control signal unless you turn it on.
9. Credly badge import and badge images
You can import badges by pasting the badge data you download from your Credly profile; nothing is fetched. Automatic lookup by Credly username is off unless we have Credly's permission; when it is available, our server looks up the username you enter at credly.com and returns your public badges, and we keep only the badges you choose to import. Badge images and Credly embeds are loaded from those websites only when you click "Show" (or if you turn on automatic loading in Account → Privacy); those sites then see your IP address and apply their own privacy policies.
10. Payments: Paddle is our merchant of record
Paid plans are sold by Paddle.com, which acts as merchant of record and reseller: Paddle collects your payment details, billing address and tax information, issues invoices and handles refunds, as an independent controller under Paddle's privacy notice. Paddle tells us your subscription status and plan, never your card details. Deleting your CertAscent account cancels any subscription you pay for.
11. Cookies and local storage
Only strictly necessary cookies (keeping you signed in, protecting requests, binding sign-in flows, and, when the referral program is live, remembering a referral link you followed). No analytics, advertising or tracking cookies, so no consent banner. Fonts are served from our own domain; the app makes no third-party requests unless you use a feature that needs one (sign-in with Google/Microsoft/Apple, checkout, showing a badge). Details: Cookie Notice.
12. Who processes data for us (subprocessors)
Hosting and database: [hosting provider, region] runs the servers, database and backups. E-mail delivery: [SMTP provider] sends verification, security, invitation, receipt and support e-mails. Anthropic, PBC (USA): AI features, only when you use them. Paddle: merchant of record for payments (independent controller, see above). Credly (Pearson): contacted only when you import badges. Sign-in providers (Google, Microsoft, Apple): only if you choose to sign in with them. Have I Been Pwned: we check new passwords against known breaches using k-anonymity (only the first 5 characters of a hash are sent, never your password or email). Error tracking or uptime monitoring services are used only if the operator enables them and will be listed here: [none enabled]. The current list is kept at [URL of subprocessor list]; we give organization customers notice before adding a subprocessor.
13. We do not sell or share your personal information
We do not sell personal information, and we do not "share" it for cross-context behavioural advertising (as defined in the California Consumer Privacy Act). We have not done so in the past 12 months. We honour the Global Privacy Control browser signal as an opt-out of all optional processing: marketing e-mail stays off while it is present, and we keep a record that we received and honoured it (not the signal on every request).
14. Your rights and how to use them
Access and portability: Account → Privacy → Export my data downloads everything we hold about you as JSON (account, mobile number, location and profile, sign-in methods and history, sessions, workspace, notebooks, AI conversations, support requests, billing records, referral records, consent records, privacy requests, single sign-on / directory links, security events). Rectification: edit your name and workspace directly; for anything else contact us. Erasure: Account → Delete account deletes your account and all associated data at once (see "Retention" for the few exceptions). Restriction: Account → Privacy → Restrict processing pauses AI features, product news, study digests and anything optional while your data stays viewable, exportable and deletable; turn it off when you are ready. Objection: contact us; you can also turn off progress sharing, product-news e-mail and AI features yourself at any time. Human review: ask for a person to review any automatic account-protection limit (see "Account protection"). Withdraw consent: turn off "Product news" at any time. We answer requests within one month (GDPR/UK GDPR), 45 days (California) or the period your law sets, and may need to verify your identity (normally by asking you to sign in). You will not be treated differently for using your rights. You can complain to your data protection authority. Contact: privacy@certascent.com.
15. European Economic Area and United Kingdom
Legal bases are listed under "What we collect and why". Where we rely on legitimate interests (security, service improvement) you may object. Transfers outside the EEA/UK (for example to Anthropic in the USA) use the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or the EU-US Data Privacy Framework where the recipient is certified. You may ask us for a copy of the safeguards. Supervisory authority: [lead authority of the operator's establishment]; UK: the Information Commissioner's Office.
16. California (CCPA/CPRA)
Categories collected in the past 12 months: identifiers (email, name, IP address, account ids), customer records (billing status via Paddle), internet activity limited to security logs and sessions, professional or education information (your certification plan and study data), and the content of AI conversations, notebooks and support requests. Sources: you, your devices, sign-in providers you choose, Paddle, Credly (on request). Purposes: as above. We disclose personal information only to the service providers listed under "subprocessors". We do not sell or share it, and we do not use sensitive personal information to infer characteristics. You have the right to know, delete, correct, opt out of sale/sharing (not applicable) and limit use of sensitive personal information (not applicable), and not to be discriminated against. An authorised agent may make a request with your signed permission. Retention periods are in the table below.
17. India (Digital Personal Data Protection Act, 2023)
We process your personal data for the purposes stated when you sign up and use each feature, based on your consent or legitimate uses under the Act. You may access a summary of your data, correct or erase it, withdraw consent, and nominate another person to exercise your rights in case of death or incapacity. Grievance officer: [name, contact] (placeholder); if unresolved you may approach the Data Protection Board of India.
18. Canada and Australia
We handle personal information in line with PIPEDA and the Australian Privacy Principles: collection limited to the purposes above, access and correction on request, and complaints to us first and then to the Office of the Privacy Commissioner of Canada or the Office of the Australian Information Commissioner. Data may be stored outside your country (see "International transfers").
19. Children
CertAscent is for professionals and adult learners. It is not directed to children, and you must be at least 16 to create an account, or 18 where local law requires it (for example India, the UAE, Saudi Arabia and Brazil). Sign-up shows the minimum age for your country and asks you to confirm it. If we learn that an account belongs to someone under that age, we delete it. Parents or guardians can contact us at privacy@certascent.com.
20. International transfers
Our servers are in [hosting region]. Anthropic and some other processors are in the United States. Transfers are protected by Standard Contractual Clauses (and the UK Addendum) or equivalent safeguards, with supplementary measures (encryption in transit, data minimisation, PII redaction before AI calls).
21. Security and breaches
Encryption in transit (TLS), hashed passwords and tokens, encrypted MFA secrets, database row-level security so each person sees only their own data, strict access controls and logging. If a breach affects your personal data we notify the competent authority within 72 hours where required and tell you without undue delay when there is a high risk to you.
22. Card numbers, ID numbers and secrets you type
We never need your card number, a government ID number (such as a Social Security, National Insurance, Aadhaar, PAN or Emirates ID number), a password or an API key. If you type one into a support request or feedback we ask you to remove it before sending; if it is in a notebook note we remove it before saving and tell you; it is also removed from error reports and our logs. We record only that this happened and the type of value, never the value. Payments are made on Paddle's pages: card details never reach our servers.
23. Changes to this notice
We will update the effective date and, for material changes, tell you in the app or by e-mail before they take effect.
24. Data retention at a glance
| Data | Kept for |
|---|---|
| Account (email, name, sign-in methods) | Until you delete your account |
| Workspace (plan, study log, notes, notebooks) | Until you delete it or your account |
| Notebook sources (pasted text, uploaded PDFs) | Until you delete them or your account |
| Sessions (signed-in devices, IP address, browser) | Idle 7 days of inactivity, or 30 days absolute, whichever comes first |
| Email verification / password-reset links | Single use; expire in minutes to 24 hours; removed within 1 day of expiry or use |
| Recovery codes (MFA) | Removed 30 days after use; unused codes remain until regenerated or account deletion |
| Sign-in history (IP address, approximate location, browser) | 180 days |
| Account-protection fingerprints (keyed hashes of device, network, mobile number) | 12 months |
| Mobile number, city, country, profile answers | Until you change them or delete your account |
| Consent records | Until you delete your account |
| Privacy request log (type, dates, outcome; no content) | 24 months after the request is closed (kept without your identity after account deletion) |
| Organization audit trail (organizations with audit export) | 1 to 7 years, as agreed with the organization |
| Anonymous error reports | 30 days |
| Security audit log (includes IP address) | 90 days, then deleted automatically (kept for that period even after account deletion, for security and legal claims) |
| AI assistant conversations | 30 days, or sooner if you delete them |
| AI usage counters (requests and token counts only) | About 13 months (plan limits and billing), deleted with your account |
| Support requests and replies | 24 months after the request is closed, or until you delete your account |
| Feedback ratings | Comments removed after 24 months or on account deletion; the rating is kept only without your identity |
| Billing records (plan, status, provider ids) | Until you delete your account (the subscription is cancelled first). Invoices and payment records are kept by Paddle under its own legal obligations |
| Billing webhook log (event ids, no personal data) | 24 months |
| Referral records (when the program is live) | 24 months after the reward, then anonymised; your link to a referrer is removed when either account is deleted |
| Organization invites | Expire after 7 days; removed 30 days after expiry |
| Organization progress summaries | Recomputed from your workspace; visible only while you keep sharing turned on |
| Backups | Encrypted; rotated out within 30 days, so deleted data disappears from backups within that time |
25. Rules for your country
See also the Cookie Notice and the Disclaimer & terms of use.