Skip to content
CertSprout
PathsFor teamsSign inSign up

Privacy notice

CertSprout is operated by The Trustee for M J & J M Samios Trust trading as Samios Software Solutions, Australia (ABN 29 966 784 797). Contact hello@certsprout.app for privacy questions, access requests or complaints.

Information we use

We store your account email, profile, timezone, preferences, credential import links and issuer records, study plans, check-ins, quiz results, achievements and team membership. Authentication and security systems process sign-in identifiers, device records and network information to protect your account. We use this information to provide the service, display progress and send the notifications you select.

Profile photos

If you upload a profile photo, we store a cropped, compressed copy in Cloudflare object storage. We remove location, camera and other embedded metadata from uploaded photos. Public and unlisted photos can be viewed by people who can view your profile; a private photo is available only to you. You can replace or remove it in account settings. Removing a photo or deleting your account immediately disables access to its old URL and triggers deletion of the stored image; failed storage cleanup is retried automatically.

Your cert guide and exam offers

If you save a direction in the guide, we store your chosen career direction, experience, study time, exam budget and optional country and student status. The guide uses these preferences with your credentials and goals to suggest certifications and relevant exam offers. It uses rules within CertSprout; it does not send these preferences to an AI service. These preferences are private, can be changed in the guide, and are included in your account export and deletion. Following an offer link opens the provider’s website, which applies its own privacy policy.

Who can see your information

Public profiles and leaderboards can show your name, handle, credentials and progress. An unlisted profile can be viewed by anyone with its link. Private visibility hides the public profile. Joining a team shares your credential information with that team; managers can export team reports and share a capability link. People who receive an export or view a public page may keep their own copy. Change your visibility in account settings.

App administration

Authorised CertSprout app administrators can access account details, certification records, study activity summaries, team memberships and subscription status to operate the service and provide support. This is separate from a team administrator’s access to their own team. We record administrative changes, the responsible administrator, the affected account or team, the time and the reason in an internal audit history. These records support security and accountability and may remain after account deletion where needed for those purposes. Authentication tokens, payment credentials and private integration tokens are not shown in the admin panel.

Service providers

Cloudflare provides application hosting, database storage and email delivery. Issuer sites receive requests when we import or refresh records you link. If you choose a third-party sign-in provider, it processes your sign-in. Team administrators can configure notifications to an external webhook destination. These services may process information outside Australia; the service does not promise Australian-only data residency. Paid billing, when enabled, uses Chargebee and its configured payment processor; CertSprout does not store card numbers.

Your choices and deletion

Use account settings to correct your profile, change email preferences, download your personal data or delete your account. Deletion removes your account and linked study data from the active application database. Team owners must first transfer ownership. Copies in service-provider backups, security logs, email systems or records required by law may remain until their applicable retention periods expire. Contact support about those records or information already shared with a team.

Country, currency and study resource links

We store your selected exam country and display currency to show regional exam information and planning estimates. Change these in settings or the Study area. They are private and included in account export and deletion. We fetch public price and exchange-rate data without sending your identity or study history. External study links open the provider’s site. Links identified as paid affiliate links may pass a public campaign identifier and send you through an affiliate network, which may process your IP address, browser details, cookies and purchase information under its own policy. We do not append your CertSprout email, account ID, credentials or study preferences to those links. We do not load affiliate tracking scripts on CertSprout; a direct provider link is also available beside an affiliate link.

Sign-up and bot protection

We save your onboarding progress and choices so you can resume setup. Cloudflare Turnstile helps protect sign-up and sign-in from automated abuse. It processes browser, device and network signals for its security check. CertSprout validates the short-lived challenge token on the server before sending an authentication email. Your account starts with a private profile; you can choose another visibility during setup or in settings.

Cookies and local storage

We use authentication cookies to keep you signed in and local storage to remember your display theme. Sign-in emails are necessary to authenticate; study recaps and expiry emails can be switched off in settings.

Questions or complaints

Email support with the details of your request. We may verify your identity before disclosing or changing personal information. If you are dissatisfied with our response, you can contact the privacy regulator relevant to your location, including the Office of the Australian Information Commissioner.

CertSproutGrow your skills. Collect your wins.

CertSprout is not affiliated with CompTIA, Microsoft, Cisco, ISC2, AWS or any other certification body. CertSprout reads credentials from issuers’ public records at the credential holder’s request.

For teamsPrivacyTermsSupportAbout our botCreated by Samios Software Solutions