CertPunch Privacy Policy
Effective date: August 3, 2026 Last updated: August 3, 2026
This Privacy Policy explains how CertPunch handles personal data when you use the CertPunch website, mobile applications for iOS and Android, APIs, account features, and related study services (together, the “Service”).
“CertPunch,” “we,” “us,” and “our” refer to CertPunch, the operator and controller of the Service. Questions and privacy requests can be submitted to support@certpunch.com.
1. Scope
This policy applies to personal data processed by CertPunch through the Service. It does not govern independent websites or services operated by Apple, Google, certification vendors, YouTube, or other third parties that you choose to visit or use.
The mobile app requires an authenticated account to enter the product. Public website pages and public catalog API responses may remain accessible without an account.
2. Data we collect
Data you provide
For a local CertPunch account, we process:
- first and last name;
- email address and email-verification status;
- a cryptographic password hash; and
- verification and replacement-email challenge records.
CertPunch does not store the plaintext password. Email-verification codes are delivered to you but stored by the API only as keyed cryptographic digests.
If you contact us, we process the information you include in the request and the contact details needed to respond.
Data received from an identity provider
If you use Apple or Google sign-in, we process the provider name, the stable provider account subject needed to recognize your account, verification claims, and any name or email the provider supplies under your choices and its policy. An Apple private-relay email is treated as an opaque routing address, not as the primary provider identity.
When Apple returns a provider refresh token, CertPunch stores it using authenticated encryption together with the exact Apple client identifier that issued it. This credential is used only to maintain the requested sign-in relationship and to revoke CertPunch’s Apple authorisation when the linked account is deleted.
CertPunch does not receive your Apple or Google password.
Study and account data
To provide learning and synchronization features, we process data such as:
- the internal CertPunch user ID;
- selected certifications and exams;
- study sessions, attempts, answers, completion timestamps, and results;
- derived progress such as XP, goals, streaks, and mastery;
- locally captured date and time-zone information needed for calendar-based progress;
- question flags and account preferences; and
- account creation, update, and last-seen timestamps.
Session, device, and security data
We process:
- hashed refresh-token records, issue and expiry times, revocation state, and authentication method;
- platform information attached to an authentication or refresh-token record;
- short-lived access-token claims;
- rate-limit and request-security information; and
- bounded operational events needed to diagnose authentication, sync, publication, deletion, and service health.
The current iOS and Android CertPunch apps do not generate, read, or send a stable installation or device identifier to the CertPunch API. The API retains an optional compatibility field for such an identifier, but it is not populated by the current mobile clients. Apple and Google sign-in providers may process technical data under their own privacy terms when you choose those services; their processing is also described in the privacy information supplied with the relevant app-store release.
The CertPunch application does not persist IP addresses in its application database or intentionally include them in application logs. The API may process an IP address transiently in memory for rate limiting. Hosting, reverse-proxy, network, app-store, or operating-system providers may independently process technical logs under their configurations and policies.
3. Data we do not use
The current Service does not use third-party advertising, behavioral tracking, or cross-app tracking. CertPunch does not sell personal data.
The app does not request or intentionally collect precise location, contacts, photos, microphone recordings, advertising identifiers, health information, or payment-card details for its current functionality.
Question text, search terms, passwords, access tokens, refresh tokens, provider identity tokens, and verification codes are not permitted in CertPunch application logs.
No crash-reporting or advertising SDK is currently enabled in the native apps. If that changes, this policy and the relevant app-store privacy declarations must be updated before collection is enabled.
4. Why we process data
We process data to:
- create, verify, authenticate, secure, and maintain accounts;
- deliver email-verification and replacement-email codes;
- provide study content and preserve study sessions;
- synchronize progress between authenticated devices;
- calculate and display factual study progress;
- respond to support and privacy requests;
- detect credential replay, abuse, fraud, and security incidents;
- operate, troubleshoot, and improve reliability; and
- comply with legal obligations and enforce the Terms of Use.
Where applicable law requires a legal basis, processing is based on performing the Service you request, our legitimate interests in operating and securing the Service, compliance with law, or consent when consent is specifically required. You may withdraw consent-based processing without affecting earlier lawful processing.
5. How data is shared
We disclose data only as needed for the purposes above:
- Hosting and infrastructure providers process data to run the website, API, databases, networking, backups, and deployment environment.
- Email-delivery providers, currently including Hostinger for local-account messages, process destination email addresses and message delivery data.
- Apple and Google process information when you choose their sign-in or platform services.
- External content providers such as YouTube receive data under their own policies only when you choose to open or use their service.
- Authorities or professional advisers may receive data when disclosure is legally required or reasonably necessary to protect rights, users, and the Service.
- A successor operator may receive relevant data in a merger, acquisition, financing, or transfer of the Service, subject to applicable law and notice requirements.
Service providers are expected to use personal data only to provide their contracted service. CertPunch does not share personal data for third-party advertising.
6. International processing
The Service and its providers may process data in countries other than the one where you live. Where required, CertPunch will use an approved transfer mechanism and safeguards appropriate to the applicable privacy law. You may contact us for available information about safeguards relevant to your data.
7. Retention
Retention depends on the data and purpose:
- account profile, provider identity, and synchronized study data are kept while the account exists;
- refresh-token records expire after the configured lifetime, currently up to 60 days, and may be removed lazily after expiry or revocation;
- verification challenges have a short validity period, currently 15 minutes, but digest-only challenge records may remain with the account until routine maintenance or account deletion;
- operational logs follow bounded schedules configured by the relevant infrastructure service;
- deletion-request, verification, and related support communications are kept for up to 12 months for auditing and legal-compliance purposes;
- deleted data may remain in encrypted backups for up to 90 days before it is removed automatically through the backup lifecycle; and
- after account deletion, CertPunch keeps only an unlinkable, event-specific deletion-evidence digest and deletion facts for up to 730 days. The record does not contain the deleted email address or provider subject.
Restored backup data remains subject to the deletion record and normal deletion process and is not used to recreate a deleted account or its study progress.
8. Account deletion
The authenticated app settings provide a permanent account-deletion flow. Sensitive deletion requires recent authentication. A successful deletion removes account-owned server rows, including local credentials, verification challenges, provider identities, refresh tokens, study sessions, attempts, flags, targets, and the account row. Existing CertPunch access tokens then stop authorizing requests.
Deleting the mobile app does not by itself delete server data. Data stored only on a device is controlled through the device and app-storage controls.
You may also request account deletion without downloading or reinstalling the app by following https://certpunch.com/delete-account/. Send the request from the email address registered to the account where possible. CertPunch may ask for additional information when needed to confirm the requester’s identity and completes verified requests within 30 calendar days after identity confirmation.
Deleting a CertPunch account does not automatically delete data held independently by Apple, Google, YouTube, an app store, or another third party. CertPunch attempts to revoke its Apple authorisation when an Apple-linked account is deleted. Third-party authorisations may also be managed in the provider’s account settings.
9. Your choices and rights
Account settings allow an authenticated user to:
- view and change first and last name;
- request and confirm a replacement email address;
- change a local-account password;
- sign out; and
- permanently delete the CertPunch account.
Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to complain to a privacy authority. Submit a request to support@certpunch.com.
We may need to verify your identity before fulfilling a request. We will not discriminate against you for exercising a privacy right. Some rights are subject to legal exceptions. The product does not currently expose an automated account-data ZIP export, so requests for a copy must use the contact route until that feature is implemented.
10. Security
CertPunch uses measures designed to protect data, including TLS in transit, memory-hard local-password hashing, digest-only verification codes and refresh tokens, short-lived access tokens, single-use refresh-token rotation, replay detection, rate limiting, database access controls, and session invalidation after sensitive account changes.
No system can guarantee absolute security. Keep your device and credentials secure and contact us if you suspect unauthorized account access.
11. Children
The Service is not directed to children under 13, or a higher minimum age where local law requires it. We do not knowingly collect a child’s personal data without legally required authorization. Contact us if you believe a child provided personal data improperly so we can investigate and delete it.
12. Changes to this policy
We may update this policy when the Service, providers, or legal requirements change. The page will show its effective date. We will provide additional notice when a material change requires it.
13. Contact
Privacy questions and requests can be submitted through: