Privacy Policy
Last updated: September 19, 2026 · Privacy Policy version 3.0 · Tack by Certifyde
1. Introduction
Certifyde, Inc. ("Certifyde," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Chrome browser extension, Tack by Certifyde ("Tack"), our web application at https://tack.certifyde.ai, and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
Tack watches the work you already do in your web applications, learns the jobs you repeat, and offers to do them again with your approval of every write. Doing that means reading the pages you work in. This policy says exactly what is read, what is never read, where it goes, and how long it is kept.
Your account is yours alone. This version of Certifyde has one seat per account. There is no organisation administrator who deploys it to you, configures it, sees your activity, or receives reporting about you, and there is no team dashboard or leaderboard. You install it, you consent to it, you see what it holds, and you can delete all of it yourself. If your employer later deploys Certifyde to you under an agreement of its own, we will tell you before that changes anything, and that arrangement will have its own notice.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name and email address, either from Google Sign-In or from the email address you verify with a six-digit code. Sign-in through Google requests three scopes and no more — openid, email and profile — which say who you are and give no access to your Google data. We also store your own answer to what you do every day, if you give one.
2.2 Page Capture
Nothing is captured until you have signed in and answered the consent screen. After that, the extension's content script reads the pages you work in, while you work in them:
- Page content and structure. The rendered page as you see it — its text, headings, tables, form field names and labels. This is the substance of the work, and reading it is how Certifyde learns what the job is.
- What you enter. The values you type, select and submit, subject to the credential floor in section 4.
- Network requests the page makes. The addresses, header names, and request and response bodies of the calls the page you are on makes — to its own application or to any other service it calls — subject to the credential floor. A request's address is recorded as the page made it, query string included.
- Which page, and which tab. The page's address and title, and which tab a capture came from and which tab opened it, so that a run's approval card appears on the page it started from.
The extension asks not to run on pages Certifyde hosts, and a capture identified as coming from one is discarded at our API before anything is stored.
2.3 Connected Applications
When you connect an application — Gmail, Google Drive, Google Sheets, Google Calendar, Slack, or any other application in our catalogue — you authorise it through that application's own OAuth screen, under your own account, and you see the scopes you are granting before you grant them. Certifyde then holds a grant for that application and uses it to read and write on your behalf when a shortcut runs.
Certifyde's Google Sign-In application and its data-connection application are two separate OAuth applications with two separate redirect lists. The Service refuses to start if they are configured as one.
Section 5 covers Google data specifically.
2.4 What a Shortcut Records When It Runs
When a shortcut runs, we record what it did: the steps, the values it settled on, what it read, what it proposed, what you approved or refused, and any error. Before a step sends, writes or changes anything in another application, it stops and asks you, and you see the exact values before it goes — section 4.3 of the Terms sets out how that works and where its limits are.
2.5 Usage Data
We collect standard usage data about how you interact with the Service — features used, requests to our API, and error reports from the extension and the panel. This helps us improve the product and find faults.
2.6 Billing Information
If you subscribe, our payment processor collects and processes your payment details. We never receive, hold or store your card number, CVC or bank details. We receive from the processor only your subscription status, the last four digits and brand of your card, and your billing country. No card is required to sign up or during the fourteen-day trial.
2.7 What We Do Not Collect, and What We Cannot Promise
We do not collect:
- Screenshots. We never capture screenshots or visual recordings of your screen.
- Keystrokes as such. We record the value a field ended up holding, not a stream of key events, and we record nothing from a page you are not working in.
- Your browser history. The extension does not ask for the browser's
historypermission and never reads it. The addresses and titles we hold are those of the pages captured under section 2.2, while you worked in them. - Precise device location. The Service asks your browser for no geolocation permission.
We also do not use anything we hold for advertising, we run no advertising of any kind, and we build no advertising profiles. Card details you give Certifyde to pay for a subscription go to our payment processor and never to us — see section 2.6.
And here is what we cannot promise. Certifyde reads the pages you choose to work in, as they are. If those pages show financial information, health information, an address, someone else's message, or any other sensitive thing, it is in the capture. The credential floor in section 4 removes secrets; it is not a filter for sensitive categories, and there is no site blocklist. This is the honest position:
- Sensitive information may be captured — financial, health, biometric, location, an advertising identifier, or a card number on a page that is not ours — if it is on a page you work in, in a value you enter, or in a request that page makes. The credential floor removes the credential values it recognises; section 4 says what it does not recognise.
- Other people's information may be captured — the sender of an email you are reading, a client named in a document, a colleague in a chat. Section 4.1 of the Terms puts the question of whether you are permitted to have that processed where it belongs.
- A shared browser profile shares its work. Captures are filed under the account signed in to the extension, whoever is at the keyboard. Do not use Certifyde on a browser profile you share.
If that is not acceptable for a particular page, sign out before you work in it.
3. How We Use Your Information
- Learn the work you do — page captures are read to find jobs in your work that could be done for you, and offer them back to you as shortcuts. A job can be offered after it has been seen once.
- Suggest applications to connect — when you sign up, the applications that fit your own sentence about your job, followed by the applications from our catalogue that the most other companies have connected. That count is made across all accounts; an application is suggested this way only once at least three other companies have connected it, and no company, person or number is shown.
- Run shortcuts you turn on — reading the pages and applications a shortcut needs, proposing each write, and carrying it out after you approve it.
- Show you what happened — the run view, the panel, and the counts of what the Service holds.
- Improve the Service — including improving the models Certifyde runs. See section 6.
- Communicate with you — transactional email (sign-in codes, a run waiting on you, billing notices) and, where you have not opted out, product updates.
- Keep the Service secure and working — authentication, abuse prevention, fault diagnosis, and meeting our legal obligations.
We do not sell your personal information, we do not share it with advertising platforms or data brokers, we do not use it for advertising of any kind, and we do not use it to determine creditworthiness or for lending.
4. The Credential Floor
Certifyde has a mandatory, non-configurable floor over what may be recorded. You cannot waive it and neither can we. It runs in your browser before anything is sent, and again at our door before anything is stored — because a copy of the extension built before a rule was fixed would otherwise keep sending what the fixed rule blanks. An extension floored by outdated rules is refused outright rather than stored.
The floor is designed to blank:
- The value of any field declaring itself a credential (
type="password"). - The value of any field whose
name,idorautocompleteattribute matches a credential word on our list — password, passcode, PIN, secret, token, API key, authorization, CSRF or XSRF, session id, OTP, MFA, TOTP, CVV or CVC, SSN, card number, account number, one-time code, WebAuthn. - Both bodies of a request whose path is a recognised authentication exchange —
oauth,token,auth,authorize,login,signin,session,sso,saml,credsorcredentials. Such a request carries its secret in a shape nothing can safely pick apart, so neither body is recorded at all. - Every header value in a captured request. That a request carried an
authorizationheader is a fact about the page worth keeping. What it carried is not ours. Header names stay; every value goes. - Any value in a request or response body under a credential-named key, at any depth.
- Any token-shaped string of 80 characters or more under any key, and any long opaque element of an array — a secret that arrives with no name is blanked by its shape.
The field itself stays in the record with its value replaced. A reader can still see that a password field was on the page, which is a fact about the page, without the secret being one of our rows.
What the floor is not, stated plainly. It matches field attributes, field names, endpoint paths and value shapes. It is a pattern-based floor, not a proof, and it is not general personal-data redaction. In particular:
- It does not scan the free text of a page for names, email addresses, phone numbers, government identifiers or other personal data and remove them. The pages you work in are read as they are, because their content is the work.
- It does not remove a secret carried in a request's address — a token in a query string is recorded with the address.
- It does not recognise every spelling of a credential field name, or every authentication endpoint, or a short secret under a name it does not know.
- It removes credential values. It is not a filter for financial, health or location information; see section 2.7.
Treat a page you would not want read as a page not to work in while Certifyde is capturing. You can stop capture at any time by signing out.
5. Google User Data
5.1 Limited Use
Certifyde's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
Our collection and use of information received through the Tack by Certifyde browser extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
5.2 What Google data we access, and why
Two different things, kept apart:
- Signing in.
openid,emailandprofile, and nothing more. These say who you are. They give no access to your mail, files, calendar or any other Google data. - Connecting a Google application. When you connect Gmail, Google Drive, Google Sheets, Google Calendar, Google Docs or another Google application, you grant the scopes configured for that integration on Google's own consent screen, and you see them there before you grant them. We use that access only to read what a shortcut needs to read and to make the writes you approve. What that permits, per application, is what that application's authorisation screen lists — for example, reading and sending mail for Gmail, or reading and writing cells for Google Sheets. We do not use a connection for anything the shortcuts you turned on do not need, and you can disconnect any application at any time.
5.3 How Google data is stored and handled
- Your refresh token is sealed with AWS Key Management Service under an encryption context naming your company, you, and that specific connection. KMS refuses to decrypt under any other context, so a row copied into the wrong account — by a bug, a bad join, or anything else — yields nothing usable. The key rotates.
- The plaintext token is never logged, never cached, never returned to a caller that did not ask for it, and never placed in a model's context. It is exchanged for a short-lived access token and discarded.
- Data a shortcut reads from a Google application is used for that run, shown to you in the run view, and kept under the retention in section 7.
5.4 What we never do with Google data
- We do not sell it, and we do not transfer it to advertising platforms, data brokers or information resellers.
- We do not use it for advertising of any kind, including retargeting or interest-based advertising.
- We do not use it to determine creditworthiness or for lending.
- We do not use it — raw or derived — to create, train, fine-tune, evaluate or improve any machine-learning or artificial-intelligence model, whether ours or anyone else's. That exclusion follows the information, not the database column it arrived in: it applies whether it appears as an API response, a document, a summary or any later record. Certifyde's own model training draws only on page captures made in your browser. See section 6.2.
- No human at Certifyde reads it except where you have given your affirmative agreement for us to look at specific messages, files or data; where it is necessary for security purposes, such as investigating abuse; or where the law requires it. Where we need to understand how the Service is performing without one of those grounds, we use aggregated and anonymised information. The same rule applies to the data the extension collects from your browser, not only to data from Google APIs.
6. Models, and Model Training
6.1 The models that read your work
Certifyde's agents run on Amazon Bedrock, in Amazon Web Services accounts we control, in the United States. The primary route is a United States cross-region inference profile, which means a single call may be processed in any one of several US regions rather than only in us-east-1; a named fallback in us-east-2 is used when the primary is unavailable. Your prompts and completions are handled under Bedrock's terms:
- Amazon Bedrock operates a zero-operator-access and, by default, a zero-data-retention model: by default it does not store model inputs or outputs, and its operators cannot read them.
- For the model we use, traffic that Bedrock's abuse classifier flags may be retained by AWS for up to 30 days for automated abuse detection.
- Retained inputs and outputs are stored and processed by AWS and are not shared with the third-party model providers whose models we call.
- AWS does not use content processed by Amazon Bedrock to develop or improve its own or its affiliates' models.
We also use Amazon Comprehend as a fast first pass over a captured page, to suggest candidate names, organisations, dates and key phrases that our own model then judges. It sees up to 25,000 characters of a captured document's text per pass.
Amazon Comprehend is handled differently from Bedrock, and we will not pretend otherwise. Under the AWS Service Terms, Amazon Comprehend is one of the AI Services whose content AWS may use and store to develop and improve that service, and — where the content is not personal data — other AWS machine-learning technologies, and may store in an AWS region outside the one where the service was called. A customer may instruct AWS not to, by configuring an AI services opt-out policy.
We send content to Amazon Comprehend only while that opt-out is in force, so that AWS may not use or store it to develop or improve its own services. Before sending any, the Service asks AWS for the opt-out setting that applies to our account, and asks again every fifteen minutes. If AWS does not confirm the opt-out, no content goes to Amazon Comprehend, and our own model reads the page without it — we do not carry on and simply tell you afterwards. AWS requires the customer of the service — us — to give you this notice, which is why it is here rather than left to Amazon's terms.
6.2 Certifyde's own model training
We build training examples, which may be used to train, fine-tune and evaluate our own models, to make the Service better at reading a page and recognising a job. The training set is built from page captures made in your browser and what our agents made of them. It is never built from data obtained through a connected application's API or derived from it, and never from your browser history.
What a training example contains, stated exactly. It is not anonymised and it is not a summary. It holds the document our agents produced from a capture — its label, description and text — together with the captured page's address, title and host, and the request and response bodies that page exchanged, after the credential floor in section 4 has been applied. It is stored in our object store under a key identifying your account, encrypted at rest, in the same AWS account as everything else.
Unlike the raw captures they were derived from, training examples are not automatically deleted after 30 days. They are removed when you delete your account, under section 8. Deleting them does not reverse training that has already been done; where the law requires us to address personal information retained in a trained model, we will.
We do not use your data to train any third party's model, and no third party receives your data to train or improve its own models or services.
7. Data Retention
| What | How long |
|---|---|
| Raw page captures — the page tree and the network bodies | 30 days from capture, then deleted automatically |
| A capture record that produced nothing — its address, title, host and the values you entered | About 30 days from capture, then deleted |
| A capture record that produced a document — the same fields | Kept with that document, until you delete your account |
| The document made from a capture — including the page's text as our agent rendered it | Until you delete your account |
| Model turn records — the prompt as the model saw it, with the page in it | 30 days, then deleted automatically |
| What a run read while it ran | 30 days, then deleted automatically |
| Capture chains exported for fault diagnosis | 30 days, then deleted automatically |
| Derived training examples (section 6.2) | Until you delete your account |
| Your account, connections, shortcuts and run records | Until you or we delete them (section 8) |
| Application logs | 3 days |
| Database backups | 7 days |
Two things worth saying plainly about that table. First, the 30 days runs from when the page was captured, not from when you stop using Certifyde — it is an automatic expiry, not an offboarding promise. Second, a capture that taught us something outlives 30 days. The raw page and the network bodies always expire; but where a capture produced a document, the document and the capture record that points at it are kept until you delete your account, because they are what your shortcuts were built from. A small number of captures stored before 17 September 2026 sit under an older storage layout that the automatic rule does not reach; they go when you delete your account.
Data is held in Amazon Web Services in the us-east-1 region of the United States, except as described in section 6.1 for model inference, which may be processed in another United States region.
8. Deletion of Your Account and Your Data
You may delete your account from the Service at any time. Before you confirm, the Service shows you the count of what deletion destroys — every page seen, every document, every connection.
Deleting your account deletes your account records and everything that hangs off them: your captures, documents, shortcuts, runs, run records, derived training examples, and your sealed grants for every application you connected. Deleting the grant does not by itself revoke it at the application; you can also revoke Certifyde's access from your Google Account's permissions page or the equivalent page at any other application you connected.
Some residual copies persist after a deletion, and then go on their own:
- Database backups, for up to 7 days.
- Application logs, for up to 3 days.
- Anything the model provider retained under the abuse-detection exception in section 6.1, for up to 30 days. That is AWS's copy, held inside AWS, and we cannot reach into it to delete it early.
None of these is used to restore a deleted account, and all expire automatically. Deleting your training examples does not undo training already done; section 6.2 covers that.
Signing out stops the extension capturing anything further, without deleting your account. It does not by itself disconnect the applications you connected or revoke Certifyde's access at them — do that from the application's own permissions page — and it does not delete what we already hold.
To ask us to delete your account on your behalf, write to privacy@certifyde.com.
9. Data Sharing
We do not sell your personal information. We share data only in the following circumstances:
9.1 Service Providers and Artificial Intelligence Subprocessors
We use third parties to run the Service, each processing data on our behalf as our service providers and subprocessors:
| Provider | What it does | What it sees | |---|---|---| | Amazon Web Services | Hosting, storage, database, encryption keys | Everything the Service holds, encrypted in transit and at rest | | Amazon Bedrock (AWS) | The models our agents call | The prompts our agents send, which include the page a capture read | | Amazon Comprehend (AWS) | Candidate names and phrases in a captured page | Up to 25,000 characters of a document's text per pass | | Mailgun | Transactional email | Your email address and the contents of the message | | Google | Sign-in, and the applications you choose to connect | Your identity for sign-in; for a connection, only what that application's own scopes cover | | Stripe | Subscription billing | Your payment details, which go to Stripe and not to us |
Each application you connect also sees the requests a shortcut makes to it, under the grant you gave.
The artificial-intelligence subprocessors on this list are Amazon Bedrock and Amazon Comprehend, both Amazon Web Services. Section 6 states what each is contractually permitted to do with what it sees. A current list of subprocessors is available on request.
9.2 Other disclosures
- For legal compliance. We may disclose information if required by law, regulation, legal process, or governmental request.
- With your consent. We may share information for other purposes with your explicit consent.
- In a corporate transaction. If Certifyde is involved in a merger, acquisition or sale of assets, your information may transfer as part of it; where data obtained from Google APIs is involved, we will obtain your explicit prior consent, as Google's policy requires.
10. Data Security
We implement security measures appropriate to what the Service holds, including:
- Encryption in transit for everything: HTTPS to our API, and a verified TLS connection between our services and the database.
- Encryption at rest for the database and the object store.
- Grants sealed individually with AWS KMS under an encryption context naming the account, the person and the connection, so a misfiled row will not decrypt.
- Requests you make through the Service scoped to your own account, so your own use of the Service cannot reach another account's rows; object storage keyed by account.
- The credential floor of section 4, applied in your browser and again at our door.
- Sign-in through Google or a verified email code, with tokens scoped to the surface that minted them.
No system is perfectly secure. We do not claim the Service is.
Human access. No one at Certifyde reads your data, from your browser or from a connected application, except on the grounds section 5.4 sets out: with your agreement to look at something specific (for example, when you ask us for help with a run), where it is necessary for security, such as investigating abuse, or where the law requires it. Our internal console, which only our own staff can reach, shows the state of the Service (whether a run finished, how long a step took, which application it used) and not the content of your pages, runs or connected applications.
11. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your personal data. Account deletion is available in the Service itself — see section 8.
- Portability: Request your data in a structured, machine-readable format. There is no self-service export in the Service today; write to us and we will prepare it.
- Objection: Object to processing of your personal data for certain purposes.
- Withdrawal of consent: Stop capture at any time by signing out; disconnect a connected application at any time.
To exercise any of these rights, contact us at privacy@certifyde.com. We may need to verify your identity before we act on a request. We will respond within the time the applicable law allows. Where a United States state privacy law applies to our processing, any additional rights, methods and exceptions it gives you apply too, and a supplemental notice will describe them.
12. International Transfer
The Service is operated in the United States by Certifyde, whose principal office in the United States is located at 465 Brickell Avenue CU-1 Miami, FL 33131. Whatever country you use the Service from, your information is transferred to, stored in and processed in the United States — in Amazon Web Services, as section 7 describes. The privacy and data protection laws of the United States may differ from those of your own country.
If you are located in the European Union, the United Kingdom or Switzerland, you may have rights under the General Data Protection Regulation (GDPR) or equivalent local law in addition to those in section 11, including the right to lodge a complaint with your national supervisory authority. Where Certifyde processes your information as a "data processor" under the GDPR — for example where a shortcut acts on data you obtained from a connected application on someone else's behalf — we do so on your instruction. For any GDPR request, write to privacy@certifyde.com.
13. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
14. Chrome Extension Specific Disclosures
14.1 Permissions
| Permission | Why it's needed |
|---|---|
| Host permissions (all sites) | The extension's purpose is to learn the work you repeat in whichever web applications you use, and which ones those are is your choice, not ours. The content script runs on the pages you work in, after you sign in and consent. It asks not to run on pages Certifyde hosts, and a capture of one is refused at our door before anything is stored. |
scripting | To re-inject the content script into already-open tabs after the extension installs or updates, so capture does not silently stop on every open tab. |
identity | Google Sign-In from the panel. |
alarms | The capture loop's timers and the checks for a run waiting on you and for your subscription. A worker timer dies with the service worker; an alarm does not. |
storage | Your session token, your consent answers, and the local set of pages worth asking about. |
sidePanel | The panel where approvals, shortcuts and connections live. An approval never renders inside a third-party page. |
notifications | To tell you a run is waiting on you when the page it started from is not in front of you. |
14.2 Data the extension handles
Consistent with our Chrome Web Store listing, the extension handles:
- Website content — the pages you work in, their text and structure, and the request and response bodies those pages exchange.
- Web history — the addresses, titles and times of the pages you work in, captured with them (section 2.2). We do not read your browser's history (section 2.7).
- Personally identifiable information — your name and email address from sign-in.
- Authentication information — the OAuth grants you give to the applications you connect, held sealed. We never ask for a password to another service, and the floor in section 4 blanks the value of a password field; a credential that the floor does not recognise can still reach a capture.
- User activity — the values you entered on the pages you work in, after the credential floor, and which pages and tabs they came from.
- Personal communications — because the pages you work in include your mail and your chats, their contents are captured as website content when you are working in them.
- Financial and payment information, health information, and location — not because we ask for any of them, but because a page you work in may display them, as section 2.7 explains. We declare these rather than rely on a category we cannot technically guarantee.
We certify that we do not sell your data to third parties, do not use or transfer it for purposes unrelated to the extension's single purpose, and do not use or transfer it to determine creditworthiness or for lending.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy at https://tack.certifyde.ai/privacy and updating the "Last updated" date, and, where we begin using data in a way this policy did not describe, by asking you to consent before we do so. Your continued use of the Service after changes constitutes acceptance of the updated policy.
16. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Certifyde, Inc. 465 Brickell Avenue CU-1 Miami, FL 33131
Email: privacy@certifyde.com Support: support@certifyde.com
What changed in this version
This is a substantially new Privacy Policy, because the product it describes is substantially new. In summary: it now says that Certifyde reads the content of the pages you work in, the values you enter and the requests those pages make — not a summary of a page's structure; it describes the browser-history states that the extension does not read your browser history; it describes the applications you connect and the Google data that reaches us; it states which model providers process your work and on what terms; it discloses that page captures are used to build training examples for Certifyde's own models and that those examples are kept until you delete your account; it gives a retention table with real numbers; and it is explicit about what the credential floor does not do. Earlier versions of this document are available on request.