Legal
Privacy Policy
Last updated: 8 August 2026
Service stage: Stellar test network
Acredia currently operates on the Stellar test network. Credentials issued today are for evaluation and demonstration purposes and should not be relied upon as authoritative academic records. Test networks may be reset by their operators, which can make on-chain records unavailable. This notice will be updated when the service moves to the Stellar public network.
1. Who we are
Acredia ("Acredia", "we", "us", or "our") is the data controller for personal data processed through this platform. You can reach our privacy team at acredia.stellar@gmail.com.
2. Personal data we collect
| Category | Data | Lawful basis | Where stored |
|---|---|---|---|
| Account | Email address, display name, role (student / institution) | Contract (Art. 6(1)(b)) | Supabase DB (Asia-Pacific region) |
| Wallet | Stellar public key (wallet address) | Contract | Supabase DB + Stellar blockchain |
| Credential metadata | Student name, degree, grade, institution name (in JSONB metadata field) | Contract | Supabase DB + encrypted IPFS (Pinata) |
| Verification logs | Verifier-supplied email / organisation (optional), verification outcome | Legitimate interest (fraud prevention, Art. 6(1)(f)) | Supabase DB — deleted 90 days after the verification attempt |
| Contact form | Name, email address, message content, hashed IP address, browser user-agent | Legitimate interest (responding to your enquiry, Art. 6(1)(f)) | Supabase DB — deleted 24 months after the last correspondence |
| On-chain record | SHA-256 hash of credential metadata + IPFS CID pointer | Public interest / legal obligation (Art. 6(1)(e), 17(3)(b)) | Stellar blockchain — immutable (see §7) |
3. How we use your data
- Create and manage your account and session.
- Issue and display academic credentials to students.
- Allow institutions to issue credentials to their students.
- Enable third-party verifiers to confirm credential authenticity.
- Detect and prevent fraud, abuse, and unauthorised access.
- Comply with legal obligations.
4. Data sharing & sub-processors
- Supabase — database and authentication, hosted in the Asia-Pacific region. Supabase's Data Processing Addendum, which incorporates the EU Standard Contractual Clauses, governs this processing (see §5).
- Pinata / IPFS — decentralised file storage for encrypted credential documents. Content is only accessible via the CID (content address); without the encryption key it is unreadable.
- Stellar Network — public, permissionless blockchain. Only non-PII hashes and wallet addresses (which you control) are written on-chain.
We do not sell personal data to third parties.
5. International data transfers
Our primary database and authentication provider (Supabase) hosts data in the Asia-Pacific region. If you are located in the European Economic Area or the United Kingdom, this means your personal data is transferred and stored outside the EEA/UK.
Such transfers are made under the safeguards permitted by Chapter V GDPR — principally the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), incorporated through our agreements with each sub-processor. You may request a copy of the relevant safeguards at any time.
Note that the Stellar network and IPFS are public, distributed systems: data written to them is replicated across nodes worldwide and its geographic location cannot be controlled. Only irreversible hashes, wallet addresses and encrypted content are published to these networks — never plain-text personal data. You can request details of our current transfer safeguards at acredia.stellar@gmail.com.
6. Data retention
| Data | Retention |
|---|---|
| Account profile & credentials | Lifetime of account; deleted on erasure request |
| Verification logs | 90 days, then deleted by an automated purge that runs nightly at 03:00 UTC |
| IPFS credential documents | Unpinned on erasure request (content becomes inaccessible) |
| On-chain hash record | Permanent (see §6) |
| Contact form messages | 24 months from the last correspondence, then deleted by the same nightly purge |
| Erasure request records | 7 years (legal compliance) |
7. On-chain data & immutability
Important notice about blockchain data
When a credential is issued, a SHA-256 hash of the credential metadata is written to the Stellar blockchain. This hash is cryptographically irreversible — it does not reveal the credential content — and is considered non-personal data under GDPR Recital 26 (data that, without disproportionate effort, cannot be attributed to an identified natural person without additional information).
Because blockchain records are technically immutable, this data cannot be erased. We rely on the exemption in Art. 17(3)(b) GDPR (necessity for compliance with a legal obligation and the exercise of official authority) and the design principle of pseudonymisation to justify retention. The hash alone reveals nothing about the credential holder without the original document, which is either deleted from IPFS or remains encrypted.
For the full technical data-model documentation, or a copy of our records-of-processing, contact us at acredia.stellar@gmail.com.
8. Your rights
Under GDPR you have the following rights:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate personal data.
- Erasure — delete your account via Dashboard → Settings → Delete Account. This removes your profile, credentials metadata, and IPFS documents. On-chain hashes are not PII and are retained (see §6).
- Portability — export your credential data in JSON/PDF via the dashboard.
- Restriction — restrict processing in certain circumstances.
- Objection — object to processing based on legitimate interest.
To exercise any right, email acredia.stellar@gmail.com. We will respond within 30 days.
9. Cookies & analytics
Acredia uses only strictly-necessary session cookies required for authentication (Supabase auth tokens stored in browser localStorage). No third-party analytics or advertising cookies are currently deployed. If analytics are added in future, this policy will be updated and a consent banner will be displayed.
10. Security
All data in transit is encrypted with TLS. Credential documents stored on IPFS are encrypted with AES-256-GCM before upload. Database access is protected by Row Level Security (RLS) policies. We follow responsible disclosure — if you believe you have found a vulnerability, please report it privately to acredia.stellar@gmail.com rather than disclosing it publicly.
11. Children's data
Acredia is not directed at children. Accounts are intended for users aged 16 or over (or the minimum age of digital consent in your jurisdiction, where higher). We do not knowingly collect personal data from children below that age. Where an institution issues a credential relating to a minor, the institution acts as controller for that record and is responsible for obtaining any necessary parental consent. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
12. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects concerning you, or that similarly significantly affects you, within the meaning of Art. 22 GDPR. Credential verification is a deterministic cryptographic comparison — it checks whether a hash matches an on-chain record and does not evaluate, score, or profile individuals.
13. Changes to this policy
We may update this Privacy Policy to reflect changes to the service, our sub-processors, or applicable law. The “Last updated” date at the top of this page always reflects the current version. Where a change materially affects how we process your personal data, we will provide notice — for example by email or an in-app notice — before it takes effect.
14. Contact & complaints
For any privacy-related query, contact us at acredia.stellar@gmail.com. If you believe we have not addressed your concern, you have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK or the relevant EU data protection authority).