Privacy Policy

Last updated: July 30, 2026

1. Information We Collect

Account information: name, email address, and a hashed password (or Google account identifier, if you sign in with Google).

Credential and CE data: license/credential names, numbers, states, expiration dates, continuing-education course records, and hours you log.

Uploaded documents: certificates and other files you choose to upload as proof of completed CE or license status.

Optional profile photo: if you choose to add one, we use it only for your private, in-app Licensy credential card. We do not use profile photos for facial recognition, identity matching, biometric identification, advertising, or model training. Adding a photo is optional and does not affect credential tracking. Cropping and format conversion happen entirely in your browser using its built-in canvas capability — no third-party image-processing library is involved, and your original photo is never uploaded.

Billing information: we do not store your card details. Payments are processed by Stripe, which collects and handles payment information under its own privacy policy.

Usage and device information: basic technical data such as IP address, browser type, and pages visited, used for security, rate-limiting, and troubleshooting.

2. How We Use Information

We use your information to:

We do not sell your personal information, and we do not use your credential or CE data for advertising.

3. Third-Party Service Providers

We use a small set of vetted providers to operate Licensy, each of which processes a limited slice of your data solely to perform its function for us:

These providers are contractually restricted from using your data for any purpose other than providing services to us.

4. Data Sharing

We do not sell or rent your personal information. We share data only: with the service providers above, as necessary to operate the Service; if you are a member of an organization (“Practice”) plan, with your organization’s administrators to the extent needed for seat management and shared visibility you’ve been granted; when required by law, subpoena, or valid legal process; or with your consent.

5. Data Retention

We retain your account and credential data for as long as your account is active. If you delete your account, your data — including uploaded documents — is permanently removed from our active systems; some records may briefly persist in encrypted backups before they age out.

When you remove or replace a profile photo, or delete your account, we clear its active database reference immediately and target removal from active Cloudflare R2 storage within 24 hours. Retryable deletion records are retained until removal succeeds. Encrypted infrastructure backups may retain historical database references—but not a separate application backup of the photo file—for up to 30 days. Backups are isolated from ordinary application access and expire on schedule.

6. Your Data Rights

You can export a complete copy of your account data at any time from account settings, regardless of your subscription status — including if your account has lapsed. You can also permanently delete your account and all associated data from account settings. These rights apply to every user regardless of location.

Depending on where you live, state law may also give you the right to know what personal information we hold, correct inaccurate information, and opt out of the sale or sharing of personal information or its use for targeted advertising or profiling — we apply the rights above to every U.S. user the same way, and we do not sell personal information, share it for cross-context advertising, or use it for automated profiling in the first place.

Submitting a request: use the self-service tools in account settings when possible, or email [email protected]. We verify requests through your authenticated session or a one-time link sent to your account email before fulfilling them.

Authorized agents: someone you authorize (for example, a family member or attorney) may submit a request on your behalf by emailing [email protected]with your authorization; we will independently verify your identity and the agent's authority before acting on the request.

Appeals: if we decline a request, you may appeal by replying to our response within 30 days. We will review the appeal and respond within 15 days with the outcome and, if we still decline, the reason.

7. Security

We use industry-standard measures to protect your data, including encrypted connections (TLS), hashed passwords, database-level tenant isolation, and optional two-factor authentication (TOTP) for your account. No system is perfectly secure, and we cannot guarantee absolute security.

8. Cookies

We use a small number of essential cookies to keep you signed in and protect against cross-site request forgery. We do not use third-party advertising or tracking cookies.

9. Children’s Privacy

The Service is intended for licensed professionals and is not directed at, or knowingly used by, anyone under 18. Every account holder represents that they are at least 18 years old when they agree to our Terms of Service at signup; we do not otherwise verify age.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or through the Service before they take effect.

11. Contact

Questions about this Privacy Policy or your data can be sent to [email protected].