Privacy Policy
Last updated: 5 September 2026
This Privacy Policy explains how Cred Farmer ("we", "us", or "our") collects, uses, shares, and protects your personal data when you use the Service. For the purposes of India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"), Cred Farmer is the Data Fiduciary and you are the Data Principal.
1. Data we collect
We practise data minimisation and collect only what we need to run the Service:
- Account data — name, email address, and avatar received from your OAuth provider (Google or GitHub) when you sign in. We never receive or store your provider password.
- Study data — your progress, practice and mock-test answers, streaks, and calculated readiness scores.
- Usage and technical data — feature-usage events collected server-side via PostHog, plus limited technical data (such as IP address and request metadata) processed to operate and secure the Service.
We do not knowingly collect special-category or financial data, and we do not use third-party advertising or cross-site tracking cookies.
2. Purposes and legal basis
We process your personal data on the basis of your consent, given when you create an account, and where applicable for the performance of our agreement with you and our legitimate interest in securing and improving the Service. We use your data to:
- create and authenticate your account;
- power your dashboard — compute readiness scores, track streaks, and remember your place in the study guides;
- understand feature usage in aggregate to improve the platform;
- read the private feedback you choose to send us, so we can fix and improve things;
- send you occasional email about the Service — new study content, features, and tips relevant to the certifications you are studying for;
- publish a testimonial you have separately and explicitly consented to publish (see section 4);
- share the readiness data described in section 4a with an organisation you have explicitly joined, so it can decide whether to sponsor your exam; and
- maintain security, prevent abuse, and meet legal obligations.
We do not sell your personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.
2a. Email we send you
We send two kinds of email, and you control them differently.
- Service email — messages you cannot switch off because they are part of running your account, such as confirming that you deleted it or replying to something you sent us. We keep these to a minimum.
- Marketing email — occasional messages about new content, features, and study guidance for the certifications you enrolled in. We send these on the basis of our legitimate interest in telling existing users about a service they signed up for, and we send at most one a week.
Every marketing email carries an unsubscribe link that works in one click, without signing in, and takes effect immediately and permanently. You can also switch marketing email off at any time under Settings, or by writing to us at the address in section 10. Unsubscribing never affects your access to the Service.
We record an unsubscribe against your email address rather than your account, and we keep that record even if you later delete your account. We do this so that the request continues to be honoured — without it, deleting your account would make your address contactable again, which is the opposite of what you asked for. That record contains nothing but the address and the fact that it must not be contacted.
3. Sharing and processors
We share personal data only with service providers who process it on our behalf under contract, including our authentication providers (Google, GitHub), analytics provider (PostHog), and cloud hosting infrastructure. We may also disclose data where required by law or to protect our rights. Apart from a testimonial you have explicitly asked us to publish (section 4) or an organisation you have explicitly joined (section 4a), we do not otherwise share your data with third parties.
4. Public testimonials
If you submit a testimonial and tick the publication box, and we then approve it, the following becomes publicly visible on Cred Farmer: the text you wrote, the rating you gave, the optional context line you wrote, the certification it relates to, the date it was published, and — only if you separately tick the name box — the display name you typed. If you do not tick the name box, it appears as “Verified learner”.
We never publish your email address, your profile photo, your account identifier, or any private feedback or private note you send us. The two consent choices are recorded separately, with a timestamp and the version of the wording you agreed to.
Public pages are indexed by search engines and may be copied, cached, or archived by services we do not control. Please treat anything you publish here as permanently public, even after removal.
Withdrawing. You can withdraw a testimonial at any time from your account settings, with no need to contact us. It disappears from our live pages immediately. Because our public pages are pre-built, we then rebuild the site — we aim to do so within 7 days — and copies may persist in third-party caches and search indexes beyond that. Withdrawing consent here does not affect your account or anything else about your use of the Service.
4a. Sharing with an organisation you join
Employers and sponsors can use Cred Farmer to fund certification exams for people who are ready to sit them. An organisation can only invite you; it can never add you. Nothing about you reaches an organisation until you open its invitation, read what would be shared, and explicitly agree.
What is shared, with the owner and admins of that organisation only: the name, email address and sign-in provider of the account you accept with; which certifications you are enrolled in now or enrol in later, and whether you have recorded earning each one; for each certification, your readiness score, gate state, mock attempt count, study progress percent and last active date; and the pass or fail result of any real exam you record.
What is never shared: your individual questions and answers, your confidence ratings, your drill results, and your scaled exam score. An organisation never receives these, and no organisation-facing page or export can contain them.
Stopping it. You can leave the organisation at any time from your account settings, and sharing stops immediately. It also stops immediately if the organisation removes you, or if the organisation is deleted. Your own study data is unaffected either way.
Your agreement is recorded with a timestamp and the version of the wording you were shown. If we ever change what is shared, we will ask you again, and the organisation will see nothing beyond your name and contact details until you agree to the new wording.
5. International transfers
Cred Farmer is operated from India. Where a processor is located outside India, we transfer personal data only in accordance with the DPDP Act and subject to appropriate contractual safeguards.
6. Retention and deletion
We retain your personal data for as long as your account is active and as needed to provide the Service. When you delete your account, we delete or irreversibly anonymise your personal data within a reasonable period, except where retention is required by law. You can export your own study data at any time from the settings page, and you can request deletion by contacting us (see section 7).
7. Your rights
As a Data Principal under the DPDP Act, you have the right to:
- access a summary of the personal data we process and the processing activities;
- request correction, completion, or updating of inaccurate or incomplete data;
- request erasure of your personal data;
- withdraw consent at any time (which does not affect processing already carried out); and
- nominate another individual to exercise your rights in the event of death or incapacity, and to grievance redressal.
If you are located in a region with additional data-protection laws (such as the EEA/UK or California), you may have further rights, including the right to lodge a complaint with your local supervisory authority.
8. Grievance redressal and contact
Under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed the following Grievance Officer:
[Grievance Officer Name], Grievance Officer
Cred Farmer, Gurugram, Haryana, India
privacy@credfarmer.com
To exercise your rights under the DPDP Act or raise any other grievance, write to the Grievance Officer at the address above. We will acknowledge your complaint promptly and resolve it within 15 days (or such other period prescribed by applicable law). For general support, contact hello@credfarmer.com.
9. Children
The Service is not directed to children below 16 years of age, and we do not knowingly create accounts for them. Where a user is a child under applicable law, we process their data only with verifiable parental or guardian consent, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us data without proper consent, contact us and we will delete it.
10. Security
All traffic to our servers is encrypted over HTTPS. We do not handle or store passwords, relying on secure third-party OAuth providers, and your session is maintained through a secure, HttpOnly cookie (see the Cookie Policy). We apply reasonable technical and organisational safeguards and will notify you and the Data Protection Board of India of a personal-data breach as required by law.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date above and, where appropriate, notified within the Service.