Privacy

How the product handles information.

This page explains the information used by the current Public, account, organization, support, purchase, and certification journeys. It is a practical overview, not a field-by-field data-flow audit.

The categories that apply depend on the journey a person chooses. A visitor does not provide every category described below, and this page reads no visitor or product record to present the explanation.

Information and purposes

What the product handles and why

Each category below is connected to the current product purposes described with it.

Contact, account, and authentication data

Contact details support communication and account continuity. Account and authentication data create and secure access to authenticated product journeys.

Profile, professional, and organization data

Where provided, profile and professional details support the product profile for that person. Organization and membership data control the relevant Workspace relationship, access, and organization-managed activity.

Support and identity data

Support messages are handled so staff can understand and address a request. For official certification, a self-declared legal name and identity-verification data establish the claimed identity and support admission to the controlled journey. On an eligible pass, the legal name is also used for the issued credential and its bounded public-verification presentation.

Assessment, result, and credential data

Assessment responses and submitted files provide the evidence required for scoring and evaluation. Results and credentials record the authorized outcome and, where eligible, the issued certification record.

Billing, payment, and tax data

Stripe processes billing, payment, and tax information for Checkout and the individual purchase path. The product also keeps its authorized backend commercial records for the purchase and settlement journey.

Email choices and purchase-interest signals

The product records whether a Quick Test participant opts in to email so it can deliver the requested optional message. It also records purchase-call-to-action funnel events to understand the current Public purchase-interest journey.

Official-certification integrity and connectivity events

The official journey records integrity, controlled-environment, and connectivity events to protect the assessment, validate its conditions, and support authorized review or operational handling.

Service providers

Services used for specific product purposes

Each service below supports a current product purpose. This does not mean that every provider receives every category of information.

Google Firebase and Google Cloud

We use Google Firebase and Google Cloud for Firebase Authentication, including sign-in with Google, Apple, and Microsoft, as well as hosting, Firestore, and Cloud Storage.

Stripe

Stripe processes Checkout, Tax, and Identity for the individual purchase, applicable tax calculation, and official identity-verification journeys.

Microsoft 365

Microsoft Graph sends product email, and SharePoint supports document viewing by authorized reviewers in the official-certification process.

Vercel AI Gateway

Vercel AI Gateway routes assessment evaluation to the permitted Anthropic, Google, and OpenAI models selected for that evaluation.

Retention boundary

Only the installed evaluation condition is stated

Every AI evaluation request is sent through Vercel AI Gateway with zero-data retention requested. This request-level setting is limited to the AI evaluation path; it is not evidence of provider retention duration, deletion timing, or permanent purge, and it does not describe application storage, reviewer handling, or any other provider. We state no general product retention period and make no claim about provider retention or deletion.

For unanswered privacy questions, contact [Contact email — owner replacement required before go-live].

Temporary operator identity

Marked for owner replacement before go-live

These shared repository values identify the operator for this page. They are visibly temporary and are not final production details.

Legal entity name
[Legal entity name — owner replacement required before go-live]
Registered address
[Registered address — owner replacement required before go-live]
Contact email
[Contact email — owner replacement required before go-live]