Privacy
Checking a certificate
The free checker runs entirely in your browser. The text you paste is analysed by code already loaded on the page and is never sent to a server, never written to storage, and never seen by us. The same is true of the message it composes for your supplier: it is built on this page and copied to your clipboard, and we never see it either.
You can confirm this by opening your browser’s network panel while you use it. To be precise about what you will see there: no request carries your certificate, but the analytics described below do send one event when you start a check and one when it finishes. Those events carry how many requirements were found, incomplete or missing, and nothing else — four numbers, no text.
Publishing a certificate
Publishing is different, because it has to be. The certificate you build is sent to our server once, so that it can be signed, and the signed result is returned to you as a URL. We keep no copy: there is no database, and the certificate exists only inside the link you receive. If you lose the link, we cannot recover it for you.
Anyone holding the link can read the certificate. Treat it the way you would treat the document itself. Certificate pages are served with a noindex directive and are disallowed in robots.txt so search engines do not list them, but that is a convention, not a security control.
Starting a new certificate from an existing one works the same way: the link that opens the prefilled form carries the whole certificate, so it deserves the same care as the certificate link itself. It is kept out of search engines and out of analytics on the same terms.
Analytics
We use PostHog, hosted in the European Union, to count page views, clicks and a small number of named events: starting and finishing a check, opening the builder, clicking through to payment, publishing, and downloading. Those events carry counts and yes/no flags only. Form contents are never captured, and neither are product names, laboratory names or licence keys.
We also use Vercel Analytics, our hosting provider’s own page-view counter, which records addresses and referrers and sets no cookie.
Because a published certificate lives inside its own URL, every analytics event sent to either service has that URL rewritten to /c/[redacted] before it leaves your browser. The same applies to the link that starts a new certificate from an existing one, which carries the same document as a from parameter and is redacted the same way. Certificate contents cannot reach either analytics service.
Payment
Payments are handled by our merchant of record, who collects the billing details required to process the transaction. We receive an order reference and issue a licence key against it. We do not see or store card details.
Contact
For anything relating to your data, write to the address on the terms page.
Withdrawing a single published certificate is a known limitation of the design. Because the content lives in the link rather than in a database, there is no row to delete; the only lever today is rotating the signing key, which would invalidate every link at once. If you need a certificate withdrawn, contact us and we will agree an approach with you rather than break other customers’ documents.