GenAgent Trust Hub
Menu

Letsencrypt

DTier DMedium risk · 37/100
  • The documents do not say whether your data trains AI.
  • Your data is used for personalized ads, including by third-party ad companies.
  • They say they do not sell or share your data.
  • The documents do not say who can read your content.

They log IPs and cert data for years, may publish it, use Google Analytics, and do not sell your data.

Highest riskMedium riskLow risk

Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.

Privacy policy ↗Terms ↗9 min read · college graduate level17 lines verified word for word

Collected

What is collected

IPs, browser and OS logs, certificate proof data, and for donors name, address, and email.

Read the exact line

Privacy policy

“If your browser makes such a request, our servers may automatically record your IP address, browser, and operating system in temporary server log files.”

Training

How it is used

They use logs to run certificates, may publish subscriber data, and use Google Analytics on the site.

Read the exact line

Privacy policy

“This information may be made public in a number of ways, including via public API, public repositories such as Certificate Transparency (CT) logs, and/or public discussions.”

Sharing

Who may see it

They say they do not sell data; payment and analytics partners and sometimes the public or police can see it.

Read the exact line

Privacy policy

“We do not sell your data or information. This includes Relying Party, Subscriber, and Visitor data and information.”

Kept

How long it is kept

Certificate logs are kept at least two years and they may be unable to delete IPs.

Read the exact line

Privacy policy

“We will store this information for a minimum of two years per trusted root program requirements.”

Controls

Your controls

EEA users can email for a data report, correction, or deletion; you can unsubscribe from emails.

Read the exact line

Privacy policy

“Request that your information be corrected or deleted by contacting us at privacy@abetterinternet.org.”

Fine print

The fine print

Terms can change the moment they post them; they say they are not for website damages.

Read the exact line

Terms of service

“Your continued use of the Websites following the posting of changes constitutes your acceptance of such changes.”

Expand “Read the exact line” to see the source alongside the explanation.

What you can turn off

The controls and opt-outs their own documents describe, and where they say to find them.

  1. Request a data report, correction, or deletion

    Email privacy@abetterinternet.org

  2. Opt out of Google Analytics

    Google Analytics Opt-out Browser Add-on and Google Ads Settings page, as described in the privacy policy

  3. Unsubscribe from emails

    Unsubscribe link in emails, or privacy@abetterinternet.org / press@abetterinternet.org

If a switch is not where they say, the deletion request above still applies.

Line by line

The lines that matter most, worst first.

1 · How long it is kept

If you get a certificate, they may keep your IP and related proof data even if you ask them to delete it.

Read the exact line

Privacy policy

“As a result, we may be unable to delete information, including IP addresses.”

For example, you cannot fully wipe the IPs used when you proved you own a domain.

2 · How it is used

Certificate-related data can be published so anyone can see it.

Read the exact line

Privacy policy

“This information may be made public in a number of ways, including via public API, public repositories such as Certificate Transparency (CT) logs, and/or public discussions.”

For example, domain and issuance details can show up in public Certificate Transparency logs.

3 · How long it is kept

Subscriber authentication and management data is kept for at least two years.

Read the exact line

Privacy policy

“We will store this information for a minimum of two years per trusted root program requirements.”

For example, full ACME request logs from when you issued a cert stay on file for years.

4 · How it is used

The websites and marketing emails can be tracked by Google and Salesforce.

Read the exact line

Privacy policy

“ISRG may from time to time deploy third-party web and email analytics tools, specifically Google Analytics for our websites and Salesforce Account Engagement for our marketing emails.”

For example, Google Analytics can record which pages you visit on letsencrypt.org.

5 · The fine print

They say they will not pay if the websites cause you harm or do not work.

Read the exact line

Terms of service

“ISRG for any damages arising from the use or inability to use these Websites, including but not limited to direct, indirect, incidental, punitive, and consequential damages.”

For example, if the site is down and you lose time, these terms say they are not .

6 · The fine print

They can change the website rules instantly by posting new text.

Read the exact line

Terms of service

“Any changes will be effective immediately upon posting on this page.”

For example, you might keep using the site without a heads-up email that the terms changed.

7 · How it is used

They state they do not sell your information.

Read the exact line

Privacy policy

“We do not sell your data or information. This includes Relying Party, Subscriber, and Visitor data and information.”

For example, they say they will not sell your IP or donor email to advertisers.

8 · How long it is kept

Certificate-check logs are not used to profile people who visit HTTPS sites.

Read the exact line

Privacy policy

“We do not use this data to build profiles or identify individuals.”

For example, they say they will not build a dossier from your browser’s revocation checks.

9 · How long it is kept

Everyday relying-party logs are usually wiped within a week.

Read the exact line

Privacy policy

“Temporary server logs are used for operational purposes only and are normally deleted in less than seven days.”

For example, the IP from a normal certificate status check is typically gone in under seven days.

10 · How it is used

Subscriber emails are for service, not ads, unless you agree.

Read the exact line

Privacy policy

“We will not use your contact information for marketing or promotional purposes without your consent.”

For example, giving an email for account recovery should not put you on a promo list by default.

Words to know

Legal words from the lines above, in plain English.

sell or share
Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
third parties
Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
limitation of liability
A cap on what the company will ever pay you if something goes wrong, often only what you paid in the last year. For example, if a leak of your data costs you thousands, the most you may get back is a month's subscription fee.
consent
Your clear agreement to something, given by an action like ticking a box or tapping Accept. For example, a pop-up asking if the app may use your location is asking for consent.
How we got here · grade D · score 37/100 · 14 of 15 policy answers backed by a verified quote · 6 not stated
  • What does the app collect beyond what it needs to work?

    They collect IPs, browser and OS, certificate validation logs, and for visitors analytics plus donor name, address, and email.

  • Does it record your voice, face or body, and what happens to that?

    The documents do not describe collecting voice, face, or body data.

  • Are your chats and uploads used to train AI models, and is that off by default?

    Not stated in the documents.

  • Can employees or contractors read your conversations, and when?

    Not stated in the documents.

  • Are you profiled or tracked for advertising?

    They use Google Analytics on websites and Salesforce Account Engagement on marketing emails.

  • Do they sell or share your data, and can you opt out?

    They say they do not sell your data. Subscriber cert data may still be published in public logs, and they share with payment and analytics providers.

  • What rights do they take over what you type and what the AI makes?

    Not stated in the documents.

  • How long do they keep your data after you delete it, and can you delete it in the app?

    Subscriber data is kept at least two years and they may be unable to delete IPs. Relying-party logs are usually deleted in under seven days. Deletion is by email request.

  • Does it build a lasting memory or profile of you, and can you see, edit or turn it off?

    They say they do not use relying-party logs to build profiles or identify individuals.

  • Do they commit to basic security, and have they leaked data?

    Not stated in the documents.

  • Is there a real age gate, and are teens protected?

    Not stated in the documents.

  • Will they tell you when the rules change, and is the policy specific?

    Neither document is dated. Terms say changes take effect when posted and continued use means you accept them.

  • Can they close your account without warning, and can you get your data out first?

    Not stated in the documents.

  • If something goes wrong, who pays?

    They say they are not liable for any damages from using or not being able to use the websites.

  • Do subscriptions renew on their own, and can you get a refund?

    Certificates are not described as a paid subscription. Donations go through third-party processors; no auto-renew subscription terms are given.

The privacy policy is 1,990 words at a college graduate level (Flesch reading ease 35.3); the terms are 363 words at a fairly hard level.

Your privacy
has an agent now

Be in control of your online privacy in the AI Era with confidence.

Gen

From Gen, the Company BehindNorton