Privacy Policy
Privacy Policy
Last updated: August 2026
CertiLayer's behavioral detection engine is built to operate without personally identifiable information. Where we necessarily do collect data — like when you create a CertiLayer account — this policy explains exactly what, why, and for how long.
1. What this policy covers
This Privacy Policy explains what data CertiLayer collects, why, and how it's handled — both when you use our dashboard as a customer, and when the CertiLayer SDK runs on your end users' devices as part of our behavioral verification service.
These are two different data flows with very different privacy profiles, and we describe each separately below rather than blending them into one vague statement.
2. Behavioral signal data (the core product)
CertiLayer's detection engine is built to never require personally identifiable information. The SDK captures behavioral timing and movement patterns — keystroke intervals, mouse velocity and curvature, touch dynamics, scroll behavior, and device motion — and reduces them, on-device, to a 34-dimensional numerical feature vector.
Raw inputs (actual keys pressed, exact cursor coordinates, raw touch paths) are never transmitted or stored. Only the aggregated feature vector and a randomly generated session identifier leave the device. This session identifier is not linked to any user account, email, or persistent identifier by CertiLayer — how you handle correlation on your own end is your responsibility as our customer.
This behavioral data is retained according to your plan's data retention window (7 to 365 days depending on tier — see /pricing) and is used solely to compute trust scores and improve detection accuracy.
3. Account and billing data (you, our customer)
When you create a CertiLayer account, we collect your name, work email, company name, and a securely hashed password (we never store passwords in plaintext — see /security for our cryptographic approach). We also store your organization's API keys (hashed) and usage metadata needed to enforce your plan's limits.
If you subscribe to a paid plan, billing is handled by Paddle.com as our Merchant of Record. Paddle processes your payment details directly — CertiLayer never sees or stores your card number. We receive and store only your subscription status, plan tier, and Paddle's internal customer/subscription identifiers, needed to keep your account's plan in sync.
We use your email address to send account-related communications: email verification codes, login OTPs, billing receipts, and service notices. We do not sell or rent this data to third parties.
4. Cookies and session storage
CertiLayer's dashboard uses httpOnly session cookies (access and refresh tokens) to keep you signed in, and a non-httpOnly cookie holding basic profile display data. These are strictly functional — we do not use third-party advertising or tracking cookies on the dashboard.
See /cookie-policy for the full breakdown of every cookie we set.
5. Sub-processors
We rely on a small number of infrastructure providers to operate the service: Paddle.com (billing, as Merchant of Record) and our hosting/email infrastructure providers for transactional email delivery. Each is bound by their own data processing terms; we do not share more data with any sub-processor than is required for them to perform their function.
6. Your rights (GDPR / CCPA)
You may request access to, correction of, or deletion of your account data at any time by contacting [email protected]. Because behavioral feature vectors are not linked to identifying information by CertiLayer, deletion requests for that data should be directed to the CertiLayer customer whose site or app you interacted with — see /gdpr for the full data-subject rights process.
7. Changes to this policy
We'll update the date below if this policy materially changes, and for significant changes we'll notify active account holders by email.