Privacy Policy

This policy explains how OpenCredia handles personal data for credential issuers, workspace members, recipients, earners, API users, and visitors.

Last updated: September 1, 2026

1. Scope

This Privacy Policy explains how OpenCredia handles personal data when organizations use OpenCredia to create, issue, host, verify, and manage verifiable credentials, including Open Badges 3.0 credentials.

OpenCredia is currently invite-only. When an organization uses OpenCredia for its credentialing program, that organization may also have its own privacy notices that explain how it decides to use credential data.

Depending on the data, OpenCredia may act as a Data Processor (for issuer-supplied recipient, badge issuance, credential artifact, and evidence data) or as a Data Controller (for account, sign-in, inquiry, and platform-security data we decide how to process).

2. Personal data we collect

Account data: name, email address, username, password authentication data, profile details, avatar URL, multi-factor authentication state, session metadata, and organization or workspace membership.

Organization and issuer data: organization name, legal name, website, support email, issuer profile details, logos, badge images, public issuer pages, API key metadata, OAuth client metadata, and workspace settings.

Credential and recipient data: recipient names, email addresses, external references, contact details, stable identifiers, credential templates, issued credential snapshots, public verification IDs, credential status, evidence links, endorsements, and claim state.

Usage and security data: audit events, sign-in events, rate-limit records, public verification access logs, user agent information, hashed IP-derived values where applicable, API usage metadata, and error or operation metadata needed to operate the service.

Inquiry data: information submitted through early-access, support, or contact forms, such as first name, last name, email address, organization name, organization website, primary goals, current credentialing method, website (honeypot), and request metadata used to prevent abuse.

Sensitive and regulated data: OpenCredia is not designed for issuers to upload special-category, student, health, biometric, criminal-record, minor, or similarly regulated data unless the issuer has the required lawful basis, notices, consents, written terms, and safeguards for that data.

3. Where data comes from

We receive data directly from users who create accounts, request access, configure organizations, manage workspaces, upload credential assets, import credentials, or submit forms.

We receive recipient and credential data from issuer organizations and their authorized administrators or API clients.

We generate service data automatically when people sign in, use the app, call the API, verify a credential, claim a credential, publish a profile, or share a credential.

4. How we use personal data

We use personal data to provide the OpenCredia service, authenticate users, enforce workspace permissions, issue and verify credentials, host public credential resources, support API access, and maintain credential status records.

We use service data to secure the platform, prevent abuse, troubleshoot errors, maintain audit logs, enforce rate limits, analyze aggregate product usage, respond to requests, and communicate about the service.

We may use contact and inquiry data to evaluate design-partner fit, answer questions, provide onboarding, and send operational messages related to OpenCredia.

6. Public credential data

Some OpenCredia features are public by design. Public verification pages, credential JSON, credential JWTs, issuer profiles, public achievement pages, public earner profiles, and public collections may be accessible without signing in.

Public credential records can include issuer names, credential titles and descriptions, recipient or subject identifiers, issue dates, validity dates, verification URLs, status-list references, evidence marked public by an administrator, and other credential fields required by the credential format.

Do not place private recipient-only information in public badge images, issuer logos, public evidence URLs, or fields intended to appear in credential output.

7. Cookies and similar technologies

OpenCredia uses cookies and similar browser storage for authentication, session continuity, CSRF protection, security controls, and remembering the state needed to operate the app. The Cookies Policy explains this in more detail.

OpenCredia does not currently describe advertising cookies or cross-site ad tracking as part of the service. If we add analytics or marketing tools that use additional cookies, we will update this policy and provide any required consent controls.

You can control cookies through your browser settings. Blocking essential cookies may prevent sign-in, account security, or workspace features from working.

8. How we share personal data

We share data with authorized users inside the relevant organization or workspace according to their roles and permissions.

We publish public credential and issuer data when an authorized user configures or issues credentials through features intended to be public.

We use service providers and subprocessors to operate OpenCredia, such as hosting, database, email delivery, media storage, monitoring, and security vendors. These providers process data for us under contracts or terms intended to protect the data and limit use to service-related purposes.

The current list of subprocessors is published on our Subprocessors page.

We may disclose data when required by law, to protect OpenCredia, users, or the public, to investigate misuse, or as part of a merger, acquisition, financing, or similar business transaction.

9. How long we keep data

We keep account, organization, workspace, credential, audit, and API records for as long as needed to provide the service, preserve credential integrity, comply with legal obligations, resolve disputes, and maintain security.

Some credential data may need to remain available for verification after issuance, unless it is revoked, tombstoned, deleted under an applicable process, or otherwise removed by the issuer or OpenCredia.

When you delete your OpenCredia account, we schedule a 7-day grace period, sign you out immediately, and allow cancellation until the scheduled purge date. After grace, we remove account-layer data (profile, verified emails, wallet and collection state, OAuth authorizations, and notification preferences) and anonymize your user record. Credentials issued to you remain on issuer-owned records for verification; we do not delete those credential bytes as part of self-serve account deletion.

Public verification and analytics data is designed to minimize raw personal data. OpenCredia does not store raw client IP addresses for credential view analytics. Credential analytics deduplication uses time-limited daily salts on a 31-day retention policy and day-bucket deduplication records on a 90-day retention policy.

When data is no longer needed, we delete, aggregate, de-identify, or otherwise limit it according to operational, legal, and product requirements.

10. Security

OpenCredia uses access controls, organization and workspace scoping, hashed API secrets, CSRF protections, rate limits, audit logging, encrypted credential-signing secrets, and multi-factor authentication features to protect the service.

No system is perfectly secure. If you believe you found a security issue or exposed personal data in a public credential field, contact us promptly at [email protected].

11. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, export, or object to the processing of your personal data. You may also have the right to opt out of certain uses or withdraw consent where processing is based on consent.

If your data was provided to OpenCredia by an issuer organization, we may direct your request to that organization or work with that organization to respond, because the organization may control how the credential data is used.

California residents may have rights under the California Consumer Privacy Act, including rights to know, delete, correct, and opt out of certain sharing or sale of personal information. OpenCredia does not currently describe selling personal information.

Where the GDPR, UK GDPR, or similar laws apply, you may also lodge a complaint with your local data protection authority. This policy describes how we handle those requests; it is not a certification or an assertion that every obligation under those laws is met for every processing activity.

We aim to respond to privacy requests within one month where GDPR or UK GDPR timelines apply, and within 45 days where CCPA-style timelines apply, unless an extension is permitted or required by applicable law.

12. International processing

OpenCredia and its service providers may process data in countries other than the country where you live. Subprocessors are primarily US-based. Transfers rely on the transfer terms each subprocessor publishes in its own data processing terms, linked on the Subprocessors page. OpenCredia has not executed separate transfer agreements of its own.

13. Children

OpenCredia is not directed to children. Issuer organizations are responsible for ensuring they have the rights, notices, and consents needed before issuing credentials that involve minors or student data.

14. Changes to this policy

We may update this Privacy Policy as OpenCredia changes. When we make material changes, we will update the date on this page and provide additional notice when required.

15. Contact

To ask a privacy question or exercise privacy rights, contact OpenCredia at [email protected]. Include enough detail for us to understand your request and the organization, workspace, credential, or account involved.

Privacy requests: [email protected]