Letsencrypt
- The documents do not say whether your data trains AI.
- Your data is used for personalized ads, including by third-party ad companies.
- They say they do not sell or share your data.
- The documents do not say who can read your content.
They log IPs and cert data for years, may publish it, use Google Analytics, and do not sell your data.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
IPs, browser and OS logs, certificate proof data, and for donors name, address, and email.
Read the exact line
Privacy policy
“If your browser makes such a request, our servers may automatically record your IP address, browser, and operating system in temporary server log files.”
Training
They use logs to run certificates, may publish subscriber data, and use Google Analytics on the site.
Read the exact line
Privacy policy
“This information may be made public in a number of ways, including via public API, public repositories such as Certificate Transparency (CT) logs, and/or public discussions.”
Sharing
They say they do not sell data; payment and analytics partners and sometimes the public or police can see it.
Read the exact line
Privacy policy
“We do not sell your data or information. This includes Relying Party, Subscriber, and Visitor data and information.”
Kept
Certificate logs are kept at least two years and they may be unable to delete IPs.
Read the exact line
Privacy policy
“We will store this information for a minimum of two years per trusted root program requirements.”
Controls
EEA users can email for a data report, correction, or deletion; you can unsubscribe from emails.
Read the exact line
Privacy policy
“Request that your information be corrected or deleted by contacting us at privacy@abetterinternet.org.”
Fine print
Terms can change the moment they post them; they say they are not for website damages.
Read the exact line
Terms of service
“Your continued use of the Websites following the posting of changes constitutes your acceptance of such changes.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Request a data report, correction, or deletion
Email privacy@abetterinternet.org
Opt out of Google Analytics
Google Analytics Opt-out Browser Add-on and Google Ads Settings page, as described in the privacy policy
Unsubscribe from emails
Unsubscribe link in emails, or privacy@abetterinternet.org / press@abetterinternet.org
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
If you get a certificate, they may keep your IP and related proof data even if you ask them to delete it.
Read the exact line
Privacy policy
“As a result, we may be unable to delete information, including IP addresses.”
For example, you cannot fully wipe the IPs used when you proved you own a domain.
Certificate-related data can be published so anyone can see it.
Read the exact line
Privacy policy
“This information may be made public in a number of ways, including via public API, public repositories such as Certificate Transparency (CT) logs, and/or public discussions.”
For example, domain and issuance details can show up in public Certificate Transparency logs.
Subscriber authentication and management data is kept for at least two years.
Read the exact line
Privacy policy
“We will store this information for a minimum of two years per trusted root program requirements.”
For example, full ACME request logs from when you issued a cert stay on file for years.
The websites and marketing emails can be tracked by Google and Salesforce.
Read the exact line
Privacy policy
“ISRG may from time to time deploy third-party web and email analytics tools, specifically Google Analytics for our websites and Salesforce Account Engagement for our marketing emails.”
For example, Google Analytics can record which pages you visit on letsencrypt.org.
They say they will not pay if the websites cause you harm or do not work.
Read the exact line
Terms of service
“ISRG for any damages arising from the use or inability to use these Websites, including but not limited to direct, indirect, incidental, punitive, and consequential damages.”
For example, if the site is down and you lose time, these terms say they are not .
They can change the website rules instantly by posting new text.
Read the exact line
Terms of service
“Any changes will be effective immediately upon posting on this page.”
For example, you might keep using the site without a heads-up email that the terms changed.
They state they do not sell your information.
Read the exact line
Privacy policy
“We do not sell your data or information. This includes Relying Party, Subscriber, and Visitor data and information.”
For example, they say they will not sell your IP or donor email to advertisers.
Certificate-check logs are not used to profile people who visit HTTPS sites.
Read the exact line
Privacy policy
“We do not use this data to build profiles or identify individuals.”
For example, they say they will not build a dossier from your browser’s revocation checks.
Everyday relying-party logs are usually wiped within a week.
Read the exact line
Privacy policy
“Temporary server logs are used for operational purposes only and are normally deleted in less than seven days.”
For example, the IP from a normal certificate status check is typically gone in under seven days.
Subscriber emails are for service, not ads, unless you agree.
Read the exact line
Privacy policy
“We will not use your contact information for marketing or promotional purposes without your consent.”
For example, giving an email for account recovery should not put you on a promo list by default.
Words to know
Legal words from the lines above, in plain English.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- limitation of liability
- A cap on what the company will ever pay you if something goes wrong, often only what you paid in the last year. For example, if a leak of your data costs you thousands, the most you may get back is a month's subscription fee.
- consent
- Your clear agreement to something, given by an action like ticking a box or tapping Accept. For example, a pop-up asking if the app may use your location is asking for consent.
How we got here · grade D · score 37/100 · 14 of 15 policy answers backed by a verified quote · 6 not stated
What does the app collect beyond what it needs to work?
They collect IPs, browser and OS, certificate validation logs, and for visitors analytics plus donor name, address, and email.
Does it record your voice, face or body, and what happens to that?
The documents do not describe collecting voice, face, or body data.
Are your chats and uploads used to train AI models, and is that off by default?
Not stated in the documents.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
They use Google Analytics on websites and Salesforce Account Engagement on marketing emails.
Do they sell or share your data, and can you opt out?
They say they do not sell your data. Subscriber cert data may still be published in public logs, and they share with payment and analytics providers.
What rights do they take over what you type and what the AI makes?
Not stated in the documents.
How long do they keep your data after you delete it, and can you delete it in the app?
Subscriber data is kept at least two years and they may be unable to delete IPs. Relying-party logs are usually deleted in under seven days. Deletion is by email request.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
They say they do not use relying-party logs to build profiles or identify individuals.
Do they commit to basic security, and have they leaked data?
Not stated in the documents.
Is there a real age gate, and are teens protected?
Not stated in the documents.
Will they tell you when the rules change, and is the policy specific?
Neither document is dated. Terms say changes take effect when posted and continued use means you accept them.
Can they close your account without warning, and can you get your data out first?
Not stated in the documents.
If something goes wrong, who pays?
They say they are not liable for any damages from using or not being able to use the websites.
Do subscriptions renew on their own, and can you get a refund?
Certificates are not described as a paid subscription. Donations go through third-party processors; no auto-renew subscription terms are given.
The privacy policy is 1,990 words at a college graduate level (Flesch reading ease 35.3); the terms are 363 words at a fairly hard level.