Privacy Policy
How Incredify collects, uses, and protects personal data on behalf of institutions and their learners.
Effective date: June 2026
This policy is provided for transparency and is subject to legal review and finalization before formal publication.
Overview
Incredify is a digital credentialing platform built on the Open Badges 3.0 standard. It is operated by Tamahagane, LLC, a company based in the United States.
This Privacy Policy explains what personal data we collect when you use Incredify (including the website at incredify.net, the issuer dashboard, badge claim pages, and the verification API), how we use that data, with whom we share it, and what choices you have.
Incredify serves two primary groups: issuers — institutional staff who log in to create and issue badges — and recipients— individuals who receive a badge issued by an institution. Recipients do not create Incredify accounts. Institutions that use Incredify to issue badges to their learners are the controllers of recipient and education records; Incredify processes that data on the institution's behalf.
Information We Collect
Issuer account data
When an institution sets up an Incredify account, we collect the email address and name of each staff member who is added as an issuer. Email addresses are used for passwordless authentication (one-time codes) and for service communications.
Institution profile
During onboarding, we collect the institution's name, logo, and chosen subdomain. This information is used to generate the institution's public badge issuer identity (a did:web document) and to brand badge claim pages.
Recipient data
When an institution issues a badge, it provides the recipient's email address and name. We store the recipient's email address (encrypted at rest — see Data Security below) to deliver the badge notification email and to identify the issuance in the institution's account. We also store a salted cryptographic hash of the email address, which is embedded in the signed credential for public verification without exposing the plaintext address. Recipients do not create Incredify accounts and are never marketed to.
Badge and credential records
We store the badge class definitions (name, description, criteria, image) and badge assertions (which recipient earned which badge, when, and with what evidence) created by issuers. This data is the core record of the credentialing service.
Evidence files
Issuers may optionally attach evidence files to a badge. These files are stored in Incredify's file storage (Supabase / AWS) and referenced in the signed credential.
Billing contact
Subscription and billing is handled by Stripe. Stripe collects the billing contact details you provide at checkout. Incredify receives only subscription plan identifiers and billing status from Stripe — we never receive or store raw payment card data.
Usage analytics
We use Google Analytics 4 (GA4) on public-facing pages of incredify.net to collect anonymized session data, including page views, referral source, and conversion events. See the Analytics & Cookies section for details.
What we do not collect
We do not collect Social Security numbers, government-issued ID numbers, financial account numbers, health information, or sensitive demographic data.
How We Use Information
We use personal data only for the following purposes:
Operating the badging service
Issuing, delivering, and enabling third-party verification of Open Badges 3.0 credentials on behalf of institutional clients.
Account management
Authenticating issuer staff; managing subscription access and permissions.
Billing
Maintaining subscription records; processing payments via Stripe; meeting financial record-keeping obligations.
Security
Detecting unauthorized access; investigating security incidents; maintaining audit logs.
Legal compliance
Responding to lawful requests from regulatory bodies or courts; meeting obligations under applicable privacy law.
What we do not do with your data
- We do not sell personal data to third parties.
- We do not use personal data for advertising, targeting, or profiling unrelated to the badging service.
- We do not use customer data — including recipient personal data, institution profiles, badge content, or evidence files — to train artificial intelligence or machine learning models, and we contractually require the same of our subprocessors.
How Information Is Shared
We share personal data only with the subprocessors listed below, and only to the extent each subprocessor needs that data to perform its function. We do not sell data. We do not share data with third parties for their own commercial purposes. We share data beyond these subprocessors only when required by law or with the explicit consent of the institution or individual.
Institutions that use Incredify to issue badges are the data controllers for their recipient and education records. Incredify acts as a data processor on their behalf. Our Data Processing Agreement (DPA) governs that relationship.
| Subprocessor | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase (AWS) | Database, authentication, file storage | All application data: institution records, issuer and recipient data, badge records, encrypted signing keys, badge images | United States (AWS us-east-1) |
| Vercel | Application hosting, edge delivery, serverless functions | HTTP request metadata and application logs (environment variables are used for application configuration only and do not contain personal data) | United States (primary); global CDN edge nodes |
| Postmark | Transactional email delivery | Recipient email addresses and names; badge name and claim URL; issuer email addresses (OTP delivery) | United States |
| Stripe | Payment processing, subscription billing | Institution billing contact; subscription plan data; payment events. Raw card data stays on Stripe's infrastructure. | United States |
| Upstash | Rate limiting and caching | IP addresses and email-address hashes used as rate-limit keys (minimal; expires automatically) | United States |
| Google LLC (GA4) | Web analytics and conversion measurement | Anonymized session data, page views, purchase events, ad attribution parameters on public pages only | United States and global Google infrastructure |
Each subprocessor is bound by contractual agreements that include a prohibition on using Incredify data for unauthorized secondary purposes, including AI model training. This list is current as of June 2026 and will be updated when we add or change subprocessors.
Data Security
For a detailed description of our security controls, see our Security page. The following controls are directly relevant to data protection:
Encryption in transit
All traffic to incredify.net and its subdomains is served over TLS 1.2 or higher with HTTP Strict Transport Security (HSTS). Connections over plain HTTP are redirected to HTTPS.
Encryption at rest — signing keys
Each institution's Ed25519 private signing key is encrypted with AES-256-GCM at the application layer before being written to the database. A database-level breach alone cannot expose usable signing material.
Encryption at rest — recipient email addresses
Recipient email addresses are encrypted at rest using AES-256-GCM at the application layer. This is in addition to the infrastructure-level encryption provided by our database provider (Supabase / AWS).
Tenant isolation
Every table in the Incredify database enforces PostgreSQL Row-Level Security (RLS). Institution data is isolated at the database layer — a session authenticated as one institution cannot read or write another institution's data.
Access controls
Issuer staff log in via short-lived one-time codes (no passwords). Members are assigned Admin or Issuer roles per institution. Signing keys are accessible only via service-role operations — no client-side policy exposes them. Incredify operations access is restricted to a named allowlist.
Honest status as of June 2026
The controls described above are implemented and operational, but Incredify has not completed an independent security audit or penetration test and holds no current third-party certifications (SOC 2, ISO 27001, or similar). We describe what is built, not what has been independently verified.
Analytics & Cookies
Incredify loads Google Analytics 4 (GA4) and the Google Ads tag across incredify.net — including signed-in areas of the application — to understand how the product is used and to measure subscription conversions. These tags collect:
- Page views, session duration, and referral source
- Device type, browser, and geographic region (city- or region-level)
- Purchase/conversion events (subscription sign-ups) with anonymized amounts
- Ad attribution parameters when you arrive via a paid link
When an account subscribes, Google Ads enhanced conversions transmits a one-way hashed (not plaintext) form of the purchasing account holder's email address to Google to attribute the conversion. This applies only to the paying account holder at checkout — it is never applied to badge recipients.
GA4 and the Google Ads tag do not receive badge recipient email addresses, badge or credential content, or evidence files. Google applies IP anonymization to GA4 data.
Institutional opt-out
Some institutions — particularly those with data governance policies that restrict third-party analytics — may request that GA4 not be loaded for their users. Incredify will accommodate such requirements contractually. Contact hello@incredify.net if this applies to your institution.
GA4 uses cookies (primarily the _ga cookie) to distinguish sessions. Institutions that require it can have these tags disabled for their users (see above).
Data Retention & Deletion
Personal data is retained for as long as it is needed to provide the service, meet legal obligations, or resolve disputes.
Active account data
Issuer account data, institution profiles, badge records, and assertion records are retained for the duration of the institution's active subscription. Upon account termination, institutions may request a data export before deletion is performed.
Important limitation: VC-JWT credentials already issued
When a badge is issued, the recipient receives a signed Verifiable Credential (VC-JWT). That signed credential is cryptographically self-contained: its validity can be verified using the institution's public key, without Incredify's database being consulted. Deleting the assertion record from our database does not invalidate, recall, or destroy a VC-JWT that has already been delivered to the recipient. This is an intentional property of the Open Badges 3.0 standard and is disclosed in Incredify's public documentation.
Backup retention
Data deleted from our active database persists in automated backup snapshots until those snapshots expire naturally per the provider's backup retention schedule. Incredify cannot selectively remove individual records from a backup snapshot.
Your Rights / Recipient & Issuer Requests
Issuer data export
Institutions may request a full export of their data at any time — for example, before account termination. Contact hello@incredify.net.
Deletion requests
Recipients and issuers may request deletion of their personal data from our active database. We process verified requests within 30 days. The VC-JWT caveat (above) applies to badge assertion records.
To submit a rights request, email security@incredify.net. We will verify your identity before processing any deletion or export. All rights requests and their outcomes are logged.
International / Cross-Border Transfers
Incredify is operated from the United States. All current subprocessors are primarily US-based and process data on US infrastructure (see the subprocessor table above). Google's GA4 infrastructure is global per Google's data residency terms.
For institutions based outside the United States, or for institutions that process personal data of individuals in jurisdictions with cross-border transfer restrictions (such as the European Economic Area), the applicable transfer mechanism — such as Standard Contractual Clauses (SCCs) or reliance on an adequacy decision — is addressed in the Data Processing Agreement between Incredify and that institution. Contact hello@incredify.net to discuss a DPA.
Children & Education Records (FERPA)
Incredify is designed for use by higher education institutions and professional training organizations. We do not knowingly collect personal data from children under 13.
FERPA note
Where Incredify processes education records on behalf of an institution, it does so as a service provider acting under the institution's direction. The institution remains the responsible party under the Family Educational Rights and Privacy Act (FERPA) and is responsible for determining whether and how FERPA applies to its use of Incredify. Incredify has not undergone FERPA-specific legal review and makes no FERPA certification claim.
Changes & Contact
We will notify institutional clients of material changes to this policy — such as new categories of data collected, new subprocessors, or significant changes to how data is used — before those changes take effect, with sufficient notice for institutions to evaluate the change.
Non-material updates (clarifications, formatting, contact information) may be made without advance notice. The effective date at the top of this page reflects when the current version took effect.
Privacy questions or requests
For privacy inquiries, data requests, or DPA discussions, email hello@incredify.net.
For security concerns or vulnerability reports: security@incredify.net
Tamahagane, LLC · Incredify · incredify.net