Skip to content
accredit.
Product
Universities & institutesProfessional associationsSpecialist trainingMedical education
Our approach
Sign inBook a walkthrough
Product

Who it’s for

Universities & institutesProfessional associationsSpecialist trainingMedical education
Our approachBook a walkthroughSign in

Privacy

What we collect, and why.

Effective 16 September 2026. Last updated 16 September 2026.

Accredit is the platform that professional education providers — universities, associations, colleges, regulators and training teams — use to run their courses and events. Throughout this page, “we” is Accredit, and “your provider” is the organisation that enrolled you and publishes the course you are taking. Most of what we hold, we hold on their behalf.

This page is written to be read. If something here is unclear, ask us.

What we collect

  • Your account. The email address you sign in with, and your name where you or your provider gave it. If you set a password we store only a hash of it, never the password itself. If you turn on two-factor authentication we store the secret that generates your codes, and hashes of your backup codes.
  • Your learning. The courses and events you are enrolled in, your progress through them, the assignments and quiz answers you submit, the files you upload, your grades and the feedback on them, attendance in live sessions, and the certificates and CPD records issued to you.
  • Payments. Where a course or event is paid for, the payment is taken by a payment provider — Stripe, Eventbrite, or Moneris where your provider uses it. They handle the card details. Accredit never receives or stores your card number. We keep the record of what was bought, the amount, and whether it succeeded or was refunded.
  • Email we send you. The transactional messages your course requires — sign-in links, enrolment and joining details, grade and certificate notices. We keep a copy of each message, including its subject and its contents, and whether it was delivered. How long we keep that copy is below.
  • Logs. The ordinary records a web service keeps: IP address, browser user agent, the request and the time. Sign-in attempts are recorded the same way, and significant actions taken on an account are written to an audit record with the same details.
  • Your browser. This website sets no cookies and sends nothing to an analytics service; it remembers your light or dark preference in your own browser. When you sign in to Accredit itself, your browser holds the session that keeps you signed in. That is what signing in requires; none of it is used for advertising.

We do not sell personal data. We do not run advertising or advertising trackers. We do not use your submissions to train machine-learning models.

Why we collect it

  • To run the course you enrolled in and show your provider the records it needs.
  • To confirm, when someone checks a certificate, that your provider really issued it.
  • To send you the messages the course depends on.
  • To keep accounts secure — recognising a stolen sign-in link, limiting repeated attempts, and investigating abuse.
  • To meet the record-keeping your provider is required to do.

Signing in with Google

Where Accredit offers you a Google sign-in, we ask Google for openid email profile and nothing else.

From what Google sends back we keep the Google account identifier — the stable id that tells us next time that it is the same account — and a snapshot of what Google asserted about you at that moment: your email address and whether Google had verified it, your name, the address of your profile picture, and, for a Google Workspace account, your workspace domain. Your name and your email address are the only parts of that we ever display. Each sign-in attempt also writes a short-lived record holding the time, your IP address and the site you started from, which is cleared once the attempt has expired.

We do not read your Gmail, your contacts, your calendar, your Drive or anything else in your Google account, and we never post to it. We store no Google passwords and no long-lived Google access tokens. Google sign-in is optional — you can use an email address and a password instead — and you can ask us to unlink a Google account from yours.

Who else sees it

  • Your provider. The staff running your programme can see your enrolment, your submissions, your grades, your attendance and the credentials issued to you. That is the point of the platform. What they then do with those records is governed by their own privacy policy.
  • Anyone holding the code on one of your credentials. A certificate or CPD record issued through Accredit is checkable in public — that is what makes it worth anything. Anyone with its verification code or QR code can see, without signing in and without telling us who they are: your name; the credential and its title; who issued it; when it was issued and when it expires; whether it has been revoked or replaced; and any supporting documents attached to it. The code is random and is listed nowhere — it reaches a verifier only from the certificate itself, or from a link you or your provider shares.
  • The services we run on. Google Cloud hosts the platform and its databases in the United States. Stripe, Eventbrite and Moneris process payments and registrations. Brevo delivers our email, unless your provider routes its learner email through its own mail server, in which case that server’s operator does. Live sessions run on LiveKit, which powers our own conferencing service, or — where your provider has connected its own Zoom account — on Zoom. Each of them acts on our instructions, for the purposes above.
  • Nobody else — unless you ask us to, or the law requires it of us.

How long we keep it

  • Your account, your course records and your credentials are kept while your account is open and while your provider needs them. A certificate is only worth something if the record behind it is still there years later.
  • Payment records are kept for as long as accounting and tax rules require.
  • Sign-in sessions expire on their own and are swept automatically.
  • Each email we send you is kept in full for 90 days, so we can answer “I never got it”. After that we erase its contents and keep only the record that it was sent: the address, the subject, the template, and whether it was delivered.
  • Audit records and server logs are kept for one year, then deleted.

Your copy, your corrections, your deletion

Write to us from the address on your account and tell us what you want: a copy of what we hold, a correction, or deletion. We will answer within 30 days.

Two honest caveats. Where the records belong to your provider’s programme, we pass the request to them, because it is their programme and theirs to decide — we will tell you who we passed it to. And a provider may be required to keep a record of a qualification it awarded even after you close your account. Everything that is ours to delete, we delete.

Changes to this page

We will update this page as the platform changes, and the dates at the top will say when. If a change matters to you, we will tell you rather than rely on you noticing.

Contact

Privacy questions, requests for a copy of your data, and deletion requests:

hello@accredit.store

Read the terms of use

accredit.

A home for professional education.

ProductOur approachContact
Universities & institutesProfessional associationsSpecialist trainingMedical educationRecords & reporting
© 2026 Accredithello@accredit.storePrivacyTermsPhotography credits