Legal

Privacy Policy

Last updated: July 26, 2026

1. Data We Collect

We collect the information needed to provide Certifyrapp, including:

  • Name and email address
  • Certification information entered by you
  • Training information entered by you
  • Files you upload to the platform
  • Renewal Assistant questions, the bounded activity details you approve for the check, selected certification-cycle identifiers, and structured answers. Certifyrapp retains these records for up to 90 days so support can investigate reports of incorrect guidance.
  • Payment and subscription metadata needed for billing status. Full payment card details are processed by Stripe and are not stored by Certifyrapp.

2. How We Use Data

We use your information to:

  • Provide and operate the service
  • Send certification and renewal reminders
  • Manage your account and settings
  • Process subscription billing
  • Provide advisory, source-grounded guidance about whether a training activity may satisfy a certifying body's continuing-education rules

3. Third-Party Services

We use trusted third parties to run Certifyrapp:

  • Stripe for payment processing and subscription billing
  • Supabase for authentication, database, and storage
  • Railway for application hosting and runtime infrastructure
  • Anthropic for document autofill when that feature is enabled. Uploaded document content may be sent to Anthropic so the requested fields can be extracted.
  • Google Gemini for the Renewal Assistant and other text-oriented AI features. For an initial check, Certifyrapp sends your question, the activity fields shown in the "Details being shared" preview, and relevant certification policy data. If you explicitly choose "Research this activity," Certifyrapp may also send the activity title, provider, and public URL to Google so it can search or inspect public pages for facts such as syllabus, duration, and learning objectives. Public web results are not treated as certification-policy authority. Google's handling of API inputs and outputs depends on the service tier and applicable terms, so do not put confidential, personal, or sensitive information in assistant questions or activity descriptions.

Renewal Assistant records are stored in a backend-only table that is not readable by signed-in browser clients and are deleted after no more than 90 days. The assistant never sends or inspects proofs, attachments, the private training-notes field, account information, portal credentials, or issuer-portal sessions. A training description is included by default only after it is shown in the sharing preview and can be excluded before a check. It does not automatically change training facts or submit anything to a certifying body.

4. Cookies and Local Storage

Certifyrapp does not set first-party tracking or advertising cookies, and we do not use third-party analytics or advertising scripts.

  • We use your browser's local storage to keep you signed in (authentication session tokens) and to remember interface preferences such as your active dashboard tab and view settings. Session storage may hold short-lived data for the current browser session. This storage is strictly necessary for the service to function.
  • Our infrastructure providers may set strictly necessary cookies for security purposes — for example, Cloudflare may set a bot-mitigation cookie (such as __cf_bm) when you access the site.
  • When you check out or manage billing, Stripe may set cookies on Stripe's own pages in accordance with Stripe's privacy policy. Certifyrapp does not load Stripe scripts or set Stripe cookies on our domain.

Because we use only strictly necessary storage and cookies, no cookie consent is required. Clearing your browser storage for this site will sign you out and reset saved preferences.

5. No Sale of Personal Data

Certifyrapp does not sell your personal data.

6. Data Security

We use reasonable administrative, technical, and organizational safeguards to protect your data. No system is completely secure, and we are not liable for security incidents caused by events outside our reasonable control, including force majeure events.

7. Your Rights and Choices

You can update profile and account information in your dashboard. You may also request account and data deletion by contacting support.

8. Contact

Privacy questions or deletion requests can be sent to [email protected].