Home · Legal
Privacy notice
Last updated: August 2026. Early-access product.
Who we are
This platform issues and verifies open-standard digital credentials. The operator of this deployment is the data controller for account and lead data described below. Each customer organization is responsible for the personal data of the people they invite and to whom they issue credentials.
What we process
- Early-access lead emails you submit on the contact form.
- Issuer accounts: email address and authentication data (including passkeys when registered).
- Recipient contact data provided by the issuer (name and email), encrypted at rest per organization.
- Signed credential documents and public verification metadata (titles, issuer name, status).
- Delivery and audit events needed to operate the service (without putting recipient addresses in free-form logs).
What we deliberately do not do
- The public verifier does not store the credential you paste: it checks and discards it.
- Credential documents do not embed the recipient's email or name as clear text; identity binding uses a salted hash.
- We do not sell personal data.
Erasure
An issuer can erase a recipient from the panel: that destroys the key protecting that person's contact data and unpublishes their credentials. Someone who already knows an address may still be able to confirm a hash inside a retained credential document. We do not claim absolute unrecoverability of that confirmation property.
Contact
Use the early-access contact form on the home page for privacy requests about this deployment.
Early-access draft. These pages describe the product as shipped today. They are not a substitute for a signed contract or a reviewed DPA where one is required.