Privacy Policy
This policy explains how OpenCredia handles personal data for credential issuers, workspace members, recipients, earners, API users, and visitors.
Last updated: September 1, 2026
1. Scope
This Privacy Policy explains how OpenCredia handles personal data when organizations use OpenCredia to create, issue, host, verify, and manage verifiable credentials, including Open Badges 3.0 credentials.
OpenCredia is currently invite-only. When an organization uses OpenCredia for its credentialing program, that organization may also have its own privacy notices that explain how it decides to use credential data.
Depending on the data, OpenCredia may act as a Data Processor (for issuer-supplied recipient, badge issuance, credential artifact, and evidence data) or as a Data Controller (for account, sign-in, inquiry, and platform-security data we decide how to process).
2. Personal data we collect
Account data: name, email address, username, password authentication data, profile details, avatar URL, multi-factor authentication state, session metadata, and organization or workspace membership.
Organization and issuer data: organization name, legal name, website, support email, issuer profile details, logos, badge images, public issuer pages, API key metadata, OAuth client metadata, and workspace settings.
Credential and recipient data: recipient names, email addresses, external references, contact details, stable identifiers, credential templates, issued credential snapshots, public verification IDs, credential status, evidence links, endorsements, and claim state.
Usage and security data: audit events, sign-in events, rate-limit records, public verification access logs, user agent information, hashed IP-derived values where applicable, API usage metadata, and error or operation metadata needed to operate the service.
Inquiry data: information submitted through early-access, support, or contact forms, such as first name, last name, email address, organization name, organization website, primary goals, current credentialing method, website (honeypot), and request metadata used to prevent abuse.
Sensitive and regulated data: OpenCredia is not designed for issuers to upload special-category, student, health, biometric, criminal-record, minor, or similarly regulated data unless the issuer has the required lawful basis, notices, consents, written terms, and safeguards for that data.
3. Where data comes from
We receive data directly from users who create accounts, request access, configure organizations, manage workspaces, upload credential assets, import credentials, or submit forms.
We receive recipient and credential data from issuer organizations and their authorized administrators or API clients.
We generate service data automatically when people sign in, use the app, call the API, verify a credential, claim a credential, publish a profile, or share a credential.
4. How we use personal data
We use personal data to provide the OpenCredia service, authenticate users, enforce workspace permissions, issue and verify credentials, host public credential resources, support API access, and maintain credential status records.
We use service data to secure the platform, prevent abuse, troubleshoot errors, maintain audit logs, enforce rate limits, analyze aggregate product usage, respond to requests, and communicate about the service.
We may use contact and inquiry data to evaluate design-partner fit, answer questions, provide onboarding, and send operational messages related to OpenCredia.
5. Legal bases for processing
Where European Economic Area, United Kingdom, or similar privacy laws require a legal basis, we process personal data as needed to perform our agreement with users or issuer organizations, including account access, credential issuance, verification, support, and security.
We may rely on legitimate interests to secure OpenCredia, prevent abuse, maintain audit and integrity records, improve the service, analyze aggregate usage, and communicate with users about operational matters.
We may rely on consent for optional communications, non-essential cookies, or other activities where consent is required. We may also process data to comply with legal obligations, including tax, accounting, regulatory, dispute, and security obligations.
6. Public credential data
Some OpenCredia features are public by design. Public verification pages, credential JSON, credential JWTs, issuer profiles, public achievement pages, public earner profiles, and public collections may be accessible without signing in.
Public credential records can include issuer names, credential titles and descriptions, recipient or subject identifiers, issue dates, validity dates, verification URLs, status-list references, evidence marked public by an administrator, and other credential fields required by the credential format.
Do not place private recipient-only information in public badge images, issuer logos, public evidence URLs, or fields intended to appear in credential output.
9. How long we keep data
We keep account, organization, workspace, credential, audit, and API records for as long as needed to provide the service, preserve credential integrity, comply with legal obligations, resolve disputes, and maintain security.
Some credential data may need to remain available for verification after issuance, unless it is revoked, tombstoned, deleted under an applicable process, or otherwise removed by the issuer or OpenCredia.
When you delete your OpenCredia account, we schedule a 7-day grace period, sign you out immediately, and allow cancellation until the scheduled purge date. After grace, we remove account-layer data (profile, verified emails, wallet and collection state, OAuth authorizations, and notification preferences) and anonymize your user record. Credentials issued to you remain on issuer-owned records for verification; we do not delete those credential bytes as part of self-serve account deletion.
Public verification and analytics data is designed to minimize raw personal data. OpenCredia does not store raw client IP addresses for credential view analytics. Credential analytics deduplication uses time-limited daily salts on a 31-day retention policy and day-bucket deduplication records on a 90-day retention policy.
When data is no longer needed, we delete, aggregate, de-identify, or otherwise limit it according to operational, legal, and product requirements.
10. Security
OpenCredia uses access controls, organization and workspace scoping, hashed API secrets, CSRF protections, rate limits, audit logging, encrypted credential-signing secrets, and multi-factor authentication features to protect the service.
No system is perfectly secure. If you believe you found a security issue or exposed personal data in a public credential field, contact us promptly at [email protected].
11. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, export, or object to the processing of your personal data. You may also have the right to opt out of certain uses or withdraw consent where processing is based on consent.
If your data was provided to OpenCredia by an issuer organization, we may direct your request to that organization or work with that organization to respond, because the organization may control how the credential data is used.
California residents may have rights under the California Consumer Privacy Act, including rights to know, delete, correct, and opt out of certain sharing or sale of personal information. OpenCredia does not currently describe selling personal information.
Where the GDPR, UK GDPR, or similar laws apply, you may also lodge a complaint with your local data protection authority. This policy describes how we handle those requests; it is not a certification or an assertion that every obligation under those laws is met for every processing activity.
We aim to respond to privacy requests within one month where GDPR or UK GDPR timelines apply, and within 45 days where CCPA-style timelines apply, unless an extension is permitted or required by applicable law.
12. International processing
OpenCredia and its service providers may process data in countries other than the country where you live. Subprocessors are primarily US-based. Transfers rely on the transfer terms each subprocessor publishes in its own data processing terms, linked on the Subprocessors page. OpenCredia has not executed separate transfer agreements of its own.
13. Children
OpenCredia is not directed to children. Issuer organizations are responsible for ensuring they have the rights, notices, and consents needed before issuing credentials that involve minors or student data.
14. Changes to this policy
We may update this Privacy Policy as OpenCredia changes. When we make material changes, we will update the date on this page and provide additional notice when required.
15. Contact
To ask a privacy question or exercise privacy rights, contact OpenCredia at [email protected]. Include enough detail for us to understand your request and the organization, workspace, credential, or account involved.
Privacy requests: [email protected]