Last updated: July 2026
This Privacy Policy explains how CertifyAI collects, uses, stores, and protects personal data. It is aligned with the principles of India’s Digital Personal Data Protection Act, 2023 (DPDP) and, where applicable, the GDPR.
For account holders (organizations), CertifyAI is the data processor and the organization is the data controller for the recipient data they upload. Organizations are responsible for having a lawful basis and any required consent to upload student or recipient personal data.
We use data solely to provide the Service: to authenticate you, generate and verify documents, and show analytics. We do not sell personal data. We do not use recipient data for advertising.
Data is stored in our database provider, Supabase (hosted on cloud infrastructure), and the application is hosted on Netlify. Generated PDFs are not stored — they are re-created on demand from your template and data. Access is protected by row-level security so one organization can never read another’s data.
We retain data for as long as your organization is active. When you delete your organization (Settings → Danger zone), all of its templates, certificates, batches, and recipient data are permanently deleted from our database.
Under DPDP and similar laws you may:
We use HTTPS, row-level security, hashed passwords, security headers, and access controls. No system is perfectly secure, but we take reasonable measures to protect your data. We recommend you keep your own export/backup of important documents.
Where recipient data concerns minors (e.g. students), the uploading organization is responsible for obtaining any consent required by law before uploading.
Data protection queries: privacy@certifyai.app (replace with your actual contact address before launch).
This document is a starting template, not legal advice. Have it reviewed by a qualified lawyer, appoint a contact/grievance officer as required by the DPDP Act, and update the details before launching publicly.