Privacy Policy for Certcy
Last updated: 2026-06-04
Effective: 2026-06-04
This Privacy Policy explains how Certcy (“we,” “us,” or “the App”) collects,
uses, shares, and protects information about you. It applies to use of the
Certcy mobile applications (Android and iOS) and the website at certcy.app.
If you are an enterprise or education user invited to Certcy by your
organization, additional terms in your organization’s agreement with us may
apply, and your organization controls aspects of your account — see
“Enterprise & Education Members” below.
1. What Certcy Is
Certcy is an IT certification exam-prep platform. The current question library
covers 17 exams across CompTIA, ISC2, AWS, and Cisco. Use of the App is offered
under a freemium model with optional paid tiers and per-exam purchases.
2. Information We Collect
2.1 Information you provide directly
- Account information. Email address and display name when you create an
account or sign in with Google or Facebook. When you sign in with Google, we
receive your Google account email and basic profile (display name, profile
photo). When you sign in with Facebook, we receive your Facebook email and
basic profile under thepublic_profileandemailpermissions. The
Facebook SDK is used solely for authentication — see “Third-Party SDKs”
below for the steps we take to prevent it from collecting advertising data. - Profile customization. Optional username. If you sign in with Google
or Facebook, your profile photo is referenced via the URL returned by that
provider — Certcy does not currently upload, store, or serve copies of
profile photos on our servers. - Referral code you enter (if any) when signing up, used to attribute
bonus rewards. - Bug reports you submit through the in-app “Report a Bug” feature,
including any description you provide and device diagnostics.
2.2 Information generated by your use of the App
- Quiz and study activity. Questions answered, scores, time spent,
exam-readiness scores, and progress streaks. Stored in Firebase Firestore. - Health/economy state. “Hearts” (in-app virtual currency) balance and
consumption. - Leaderboard entries. Your display name and weekly score are visible to
other authenticated users on the public leaderboard. You can avoid being on
the leaderboard by not submitting scores; an in-app opt-out is a planned
improvement. - Referrals and challenges. Records of which users referred which and
challenge progression. - Achievements / level / badges. Local and synced progress markers.
- Theme skin preferences.
2.3 Information collected automatically
- Device and OS information (model, OS version, language, time zone) via
the Firebase SDKs. - App performance and crash data via Firebase Crashlytics, including stack
traces, breadcrumbs, and limited device state at crash time. - Usage analytics via Firebase Analytics: screens viewed, actions taken,
session counts. We send your Firebase user ID with analytics events as a
cross-session identifier; minimizing this signal is on our privacy roadmap. - Push notification token via Firebase Cloud Messaging (Android FCM /
Apple APNs), used solely to deliver in-app reminders and notifications. - A/B test assignments and events under per-test telemetry collections, to
measure feature variants.
2.4 Payment information
- Web payments (Stripe). Card or ACH details for web purchases are
collected directly by Stripe. Individual subscriptions and per-exam
purchases redirect to a Stripe-hosted Checkout page; enterprise web
subscriptions use a Stripe-served embedded Checkout iframe inside the
admin dashboard. In both cases, Certcy never sees, stores, or has access
to your card number, CVC, or bank credentials. We receive only a Stripe
customer identifier, a subscription identifier, the product purchased, and
the payment status from Stripe’s webhook. - In-app purchases (Apple App Store / Google Play). Payments on iOS go
through StoreKit and on Android through Google Play Billing. We receive the
transaction identifier and a purchase token, which we send to our Cloud
Functions for server-side validation. The store, not Certcy, sees your
payment instrument.
2.5 Enterprise & education accounts
If your account was provisioned by an enterprise or educational institution
via a license invitation, your employer or institution can see and export
your activity within Certcy (quiz scores, progress, last-active date, custom
quiz submissions, audit events tied to your account). Custom quizzes,
assignments, and team configurations are owned by the organization.
For accounts created under our education tier, organizations are provisioned
with an analyticsEnabled: false setting on the organization document and a
24-month retention policy on student data per FERPA expectations. Client-side
enforcement of the analytics-suppression flag (so the learner app reads
org.settings.analyticsEnabled and disables Firebase Analytics for that
tenant) ships with our education-tier launch; until that enforcement is live
we will honor analytics-suppression requests for education-tenant users on
demand via privacy@certcy.app. The 24-month retention setting is configured
at the organization level today; the scheduled enforcement job is the same
one referenced in §6.3.
3. How We Use Your Information
We use the information described above to:
- Provide, maintain, and operate the App (sync your progress, deliver
questions, manage your account). - Process purchases and subscriptions, validate receipts, and grant
entitlements. - Send service notifications and study reminders that you have opted into.
- Send transactional emails (account activation, password reset, enterprise
invitations, manager alerts you’ve opted into). - Detect, diagnose, and fix bugs and crashes.
- Measure feature performance and run A/B tests to improve the App.
- Maintain a security audit log for sensitive account, billing, and
entitlement actions across both individual and enterprise accounts (SOC 2
Common Criteria 7.2 evidence), including a minimal record of account
deletions and of detected account-tampering attempts (see Section 6.1). - Comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information. We do not use your data to
serve targeted advertisements; Certcy displays no in-app advertising.
4. Third-Party SDKs and Services
| Vendor | Purpose | What they receive |
|---|---|---|
| Firebase / Google LLC | Authentication, Firestore database, Analytics, Crashlytics, Cloud Messaging, Cloud Functions, App Check | Account, activity, device, crash, and analytics data described above |
| Google Sign-In | Optional sign-in method | Standard OAuth flow data |
| Meta / Facebook SDK | Optional Facebook Login only | Login OAuth data only — see note below |
| Stripe, Inc. | Web payments + enterprise subscriptions | Payment details (collected directly by Stripe), customer + subscription identifiers exchanged via webhook |
| Apple App Store | iOS in-app purchases | Apple’s standard IAP signals |
| Google Play Billing | Android in-app purchases | Google Play’s standard IAP signals |
| Google Play Developer API | Server-side validation of Android purchase receipts | Purchase tokens we send for validation |
Meta / Facebook SDK note (important). Although the Facebook SDK is
embedded in the Android app for Facebook Login, we have disabled its default
auto-collection behaviors via the Android manifest
(AutoInitEnabled, AutoLogAppEventsEnabled, and
AdvertiserIDCollectionEnabled all set to false). The SDK initializes
on-demand only when you tap “Continue with Facebook,” with advertiser
tracking and automatic app-event logging explicitly disabled. As a result the
SDK does not send your Android Advertising ID, install events, or app-event
signals to Meta in the background. The iOS app does not currently use the
Facebook SDK at all.
These third parties have their own privacy policies; we recommend reviewing
them: Firebase/Google (https://policies.google.com/privacy), Stripe
(https://stripe.com/privacy), Meta (https://www.facebook.com/privacy/policy/).
5. Sharing and Disclosure
We share personal information only as needed for the purposes above, and only
with the parties named in Section 4. We may also disclose information:
- To comply with law or respond to lawful requests from public authorities.
- To enforce our terms or protect the rights, property, or safety of
Certcy, our users, or others. - In connection with a business transaction (e.g., a merger or
acquisition), in which case we will give notice and continue protection. - To your organization, if your account is enterprise- or
education-provisioned, as described in Section 2.5.
We do not sell personal information. We do not share personal
information for targeted advertising.
6. Account Deletion and Data Retention
6.1 Individual / direct-to-consumer accounts (in-app self-delete)
If you signed up directly with Certcy (free, per-exam, or paid plan), you can
permanently delete your account and associated data from within the app:
- Open the Account screen.
- Scroll to Danger Zone at the bottom.
- Tap Delete my account and follow the typed-confirmation flow.
A server-side function will then permanently delete the following:
- Your user profile and all profile subcollections (notification settings,
notification log, quiz history, in-app notifications). - Your purchase history records on our servers.
- Your leaderboard entries (current-week leaderboard rows).
- Your challenge progression.
- Your referral code and referral event records (both as referrer and
referee). - Your sweepstakes entries and bug-report submissions on our servers.
- Your Firebase Auth account.
In addition, the server-side function performs two automatic privacy
hygiene steps the moment you confirm deletion:
- Active Stripe subscriptions are cancelled automatically. If you paid
for a paid plan through our website (Stripe Customer Portal / Stripe
Checkout), all of your active, trialing, or past-due Stripe subscriptions
are cancelled immediately as part of the deletion — you do not need to
cancel them separately first. After cancellation, the Stripe customer
record’sfirebaseUIDlinkage is also removed so the orphaned customer
no longer references your account. - Leaderboard archive entries are redacted, not removed. Weekly
historical leaderboard archives that show your past placements are
edited so that your display name becomes[deleted user]and your
user identifier is removed. Your score, level, XP, and rank position
remain in the archive so that other users’ historical placements are
not retroactively changed.
The deletion is immediate and irreversible.
Apple App Store and Google Play subscriptions are different. Apple’s
StoreKit and Google’s Play Billing platforms do not allow us to
cancel auto-renewable subscriptions on your behalf — only you can do
that, from your device’s subscription management screen:
- iOS: Open Settings → [Your Name] → Subscriptions and cancel
the Certcy subscription there. - Android: Open the Google Play Store app → menu → Subscriptions
and cancel the Certcy subscription there.
If you delete your account while an Apple or Google subscription is still
active, the subscription will continue to renew and bill you on that
platform until you cancel it via the device-level settings above. We
have no way to cancel it for you. The in-app deletion flow surfaces
this reminder before you confirm if you signed up via iOS or Android.
What is not purged by in-app deletion:
- Aggregated A/B-test telemetry under per-test event collections. These
records do not contain personally identifying information beyond the
Firebase user identifier; we are working to remove that identifier at write
time (planned improvement). You may request manual purge — see Section 8. - Stripe transaction records. Stripe retains the transaction history
(Charge and Invoice objects) independently for tax and legal compliance.
Your Stripe subscriptions are cancelled and the customer record’s
Certcy-side linkage is removed, but Charge and Invoice records that
Stripe retains for legal-compliance purposes remain on Stripe’s side.
Stripe’s retention is governed by Stripe’s privacy policy. - Apple / Google in-app-purchase records. Receipts and entitlement
records held by Apple App Store and Google Play remain under those
platforms’ retention controls. - A minimal security/audit record of the deletion event itself. We retain
a small record — your user identifier, the categories and counts of data
removed, and the outcome of any subscription cancellation — for up to 24
months (and up to 36 months for records evidencing fraud or account
tampering) to satisfy our legal obligations and to establish or defend legal
claims (GDPR Article 17(3)(b)/(e); CCPA § 1798.105(d)). This record contains
no email, name, or payment-card data. Where a record concerns a detected
tampering or fraud attempt, it may reference the identifiers of other
affected accounts solely for incident response. These records are
server-side only and are not accessible to any user or organization.
6.2 Enterprise / education accounts (request via your org admin)
If your account is part of an enterprise or education tenant, the in-app
deletion control instead directs you to contact your organization’s
admin, who can revoke your license and remove your access through their
admin dashboard. This is because your data and license are owned by the
organization, and self-deletion would orphan the organization’s seat count
and audit chain. Your organization is your data controller for these
purposes; reach out to them directly.
Full deletion of an enterprise / education account is a two-step process:
- Your organization’s admin revokes your license through their admin
dashboard. This removes your enterprise access and clears your
enterprise tenant claims on next sign-in. - Once your license has been revoked, you can then return to the app
and use the in-app Delete my account flow described in Section
6.1 above to remove the remainder of your individual-account data.
If you do not return to complete step 2, your individual-account data
(profile, quiz history, leaderboard entries, etc.) remains until you
either complete step 2 yourself or request a manual purge by emailing
privacy@certcy.app.
6.3 Retention
We retain personal information for as long as your account is active. When
you delete your account (or when an enterprise admin revokes your license and
data), the data described above is removed within hours, subject to backup
purge cycles that complete within 30 days — except for the limited records
listed in Section 6.1 (“What is not purged by in-app deletion”) above,
which are retained for their stated purposes and durations. Crashlytics and
Analytics records
have their own auto-retention windows set in Firebase. Education-tier
organizations are provisioned with a 24-month retention setting on student
data after license revocation; the scheduled enforcement job that performs
the purge ships with our education-tier launch. Until that job is live, we
will honor 24-month purge requests on demand via privacy@certcy.app.
7. Security
We protect your data with industry-standard measures:
- All traffic between your device and our servers is encrypted in transit
(HTTPS / TLS). Cleartext network traffic is disabled in the Android
manifest. - Data is encrypted at rest by Firebase by default.
- Firebase App Check is enforced on our Firestore data layer to reduce
unauthorized API access from outside our apps. We are progressively
extending App Check enforcement to additional Firebase services. - Server-side write rules require authenticated requests; entitlement fields
(plan, subscription, purchase records) can only be written by Cloud
Functions via the Admin SDK. - We do not store payment instruments on our servers; payments are tokenized
by Stripe and the app stores.
No system is perfectly secure. If we become aware of a personal-data breach
that materially affects you, we will notify you in accordance with applicable
law.
8. Your Privacy Rights
Subject to applicable law (including the GDPR for residents of the European
Economic Area and the UK, the CCPA/CPRA for California residents, and similar
laws elsewhere), you may have the right to:
- Access the personal information we hold about you.
- Rectify inaccurate personal information.
- Erase your personal information (see Section 6 for in-app deletion).
- Restrict or object to certain processing.
- Portability — receive a copy of your data in a portable format.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a supervisory authority.
To exercise these rights, use the in-app deletion control if it applies to
your account type (Section 6.1), or contact us at privacy@certcy.app. We
will verify your identity and respond within the time required by applicable
law (typically 30 days). We do not discriminate against users who exercise
their rights.
Lawful bases (GDPR/UK GDPR). We rely on (a) contract performance to
operate your account and process your purchases, (b) legitimate interests to
diagnose bugs and improve the App, (c) consent for push notifications and
email marketing, and (d) legal obligation where required.
International transfers. Our Cloud Functions and Firebase data
processing happen in Google Cloud regions including the United States. Where
data is transferred from the EEA/UK to the U.S., we rely on the standard
contractual clauses Firebase makes available.
9. Children’s Privacy
The App is intended for users aged 13 and older. We do not knowingly collect
personal information from children under 13. If you believe we have collected
information from a child under 13, please contact us at
privacy@certcy.app and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will
be announced in the App and on certcy.app/privacy-policy. The “Last updated”
date at the top of this document indicates the most recent revision.
11. Contact
For privacy questions or to exercise your rights:
- Email: privacy@certcy.app
- Postal address: available on request to privacy@certcy.app.
If your account was provisioned by an enterprise or education organization,
contact your organization’s admin or data protection officer for matters
relating to your account.