Privacy Policy

Last updated: December 2024

Overview

EverCert is designed with privacy as a core principle. Your documents are processed entirely in your browser and are never uploaded to our servers. This Privacy Policy explains what information we collect and how we use it.

Information We Collect

Document Information

We do NOT collect your documents. When you use EverCert:

  • Your document is hashed locally in your browser using SHA-256
  • Only the hash (a 64-character string) is sent to our servers
  • The filename you provide is stored for your reference
  • It is cryptographically impossible to reverse a hash back to your document

Account Information

If you create an account, we collect:

  • Email address (for authentication and notifications)
  • Password (stored securely using bcrypt hashing)
  • Account creation and activity timestamps

Payment Information

Payment processing is handled entirely by Stripe. We do not store credit card numbers or payment details. We only receive confirmation of successful payments and Stripe customer IDs for subscription management.

Technical Information

We may collect standard server logs including IP addresses, browser type, and access times for security and service improvement purposes.

How We Use Your Information

  • To provide timestamping services and generate proof certificates
  • To communicate service updates or respond to inquiries
  • To process payments and manage subscriptions
  • To respond to support requests
  • To improve our service and fix technical issues

Data Retention

We retain timestamp records according to your service tier:

  • Free Tier: 30 days
  • Proof of Existence: 1 year
  • Assured/Legal: As specified in your agreement

After the retention period, records may be deleted from our database. However, your OTS proof file remains valid and verifiable using the Bitcoin blockchain indefinitely.

Data Sharing

We do not sell your personal information. We may share data with:

  • Stripe: For payment processing
  • OpenTimestamps calendar servers: Document hashes are submitted to public calendar servers for Bitcoin anchoring
  • Bitcoin blockchain: Merkle roots containing aggregated hashes are permanently recorded on the public blockchain

Note: Information on the Bitcoin blockchain is public and permanent by design. Only cryptographic hashes are recorded, not document contents.

Security

We implement industry-standard security measures including HTTPS encryption, secure password hashing, and access controls. However, no system is completely secure, and we cannot guarantee absolute security of your information.

Your Rights

You have the right to:

  • Access your account information
  • Request deletion of your account and associated data
  • Opt out of marketing communications
  • Download your timestamp records and proof files

To exercise these rights, contact us.

Cookies

We use essential cookies for authentication (storing your login session). We do not use tracking cookies or third-party analytics that track you across websites.

Changes to This Policy

We may update this Privacy Policy periodically. We will notify registered users of significant changes via email. Your continued use of the service after changes constitutes acceptance of the updated policy.

Contact

For questions about this Privacy Policy or your data, contact us