GrokCred
Resources ← Back

Privacy Policy

Effective April 25, 2026

This Privacy Policy explains how GrokCred ("we", "us") collects, uses, and shares personal information when you use our website and services (the "Service"). By using the Service you agree to the practices described here.

1. Information we collect

From account holders

  • Account information: name, email address, and authentication identifiers provided when you create or sign in to an account.
  • Issuer profile: organization name, contact email, and badge designs you upload.
  • Usage data: log data such as IP address, browser type, pages visited, and timestamps, used for security and to improve the Service.

From recipients of credentials

When account holders issue credentials, they submit recipient information including name and email address. We process this information on the account holder's behalf to:

  • generate the credential record;
  • email the recipient their badge and verification link;
  • display a public verification page for the credential;
  • publish a JSON-LD assertion that conforms to the Open Badges 2.0 specification.

Recipient email addresses are not exposed in our public Open Badges JSON-LD endpoints. Instead, we publish a salted SHA-256 hash of the email, as the specification recommends.

2. How we use information

  • To provide, operate, and improve the Service.
  • To authenticate users and protect against fraud and abuse.
  • To send transactional emails (for example, badge delivery, account notices).
  • To comply with legal obligations and enforce our Terms.

We do not sell personal information, and we do not use recipient data for advertising.

3. Legal bases (EEA / UK)

Where applicable, we process personal information on the following legal bases: performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service), consent (where required, for example for non-essential cookies), and compliance with legal obligations.

4. Sharing

We share personal information only in limited circumstances:

  • Service providers who help us operate the Service (for example, authentication, email delivery, hosting, and database providers). These providers process information on our behalf under contract.
  • Public verification pages: when an account holder issues a credential, the badge name, criteria, issuer, recipient name, and issuance/expiry dates are visible at the verification URL so anyone with the link can verify the credential. Recipient email addresses are not displayed.
  • Legal requests: if required by law, court order, or to protect rights, safety, or property.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections.

5. Data retention

We retain account information for as long as your account is active and as needed to provide the Service. Issued credentials and the data needed to verify them are retained as long as the credential is valid or while needed to satisfy our legal obligations. You may request deletion of your account at any time.

6. Security

We use industry-standard administrative, technical, and physical safeguards to protect personal information. No system is perfectly secure, however, and we cannot guarantee absolute security.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, or to object to or restrict certain processing. You may also have the right to withdraw consent and to lodge a complaint with a supervisory authority.

If you are a recipient of a credential and want your personal data corrected or removed, contact the organization that issued the credential first, since they are the controller of that data. We will assist them in responding to your request.

8. Cookies

We use a small number of cookies and similar technologies that are strictly necessary to operate the Service (for example, to keep you signed in). We do not use third-party advertising cookies.

9. International transfers

We and our service providers may process personal information in countries other than the one you live in. Where required, we use appropriate safeguards (such as standard contractual clauses) to protect that data.

10. Children

The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us personal information, please contact us so we can delete it.

11. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Effective" date above and, where appropriate, notify you in the Service.

12. Contact

For privacy questions or to exercise your rights, contact us through the details listed on our site.

GrokCred GrokCred

An UnDesto AI product

About Pricing Contact Terms Privacy Data

FAQ

Resources Open Badges 2.0 Bulk CSV issuing Issue from Excel Course certificates Add to LinkedIn Badges vs PDF