Privacy Policy
Last updated: 25 July 2026
Done By Humans is a certification project. To issue a badge we need a small amount of information about the person or organization applying for it. This page explains, in plain language, exactly what we collect, what we do with it, and what we will never do with it.
The short version: we do not sell, rent, trade, license or otherwise share the data of our certificate holders with any third party. We use it for one purpose only — to run the certification and to promote our badge holders and the project itself on social media.
What we collect
When you apply for a badge you provide us with:
- Name of the individual or organization.
- Website address of the certified work.
- Description of what you do and how humans make it.
- Contact person — the name of the person we can talk to.
- Email address — used to reach you about your certification.
- Password — stored only as a one-way encrypted hash. We cannot read it, and neither can anyone who gets hold of our database.
- Logo — optional, uploaded by you to be shown on your public badge page.
- Social media handles — optional, for Bluesky, Instagram, LinkedIn, Facebook, X and TikTok.
- Date of the application.
When anyone visits the website we also collect basic, anonymous usage statistics (pages viewed, approximate country, type of device) through Google Analytics. This is not linked to your certificate record.
We do not collect payment details, government identity documents, location tracking data, or any special categories of personal data. We do not ask for them, and please do not send them to us.
What is public and what is not
A certification only means something if it can be verified, so part of what you submit is published on your public badge page.
Public
- Name of the individual or organization
- Website address
- Description of the certified work
- Logo, if you uploaded one
- Social media handles, if you provided them
- Badge and certification status
Never public
- Your email address
- The name of your contact person
- Your password (in any form)
- Any private correspondence between us
Everything in the “public” list is information you asked us to publish when you applied for a public badge. Everything in the “never public” list stays with us and is visible only to the small team that operates Done By Humans.
We do not share your data with third parties
This is the core commitment of this policy, so we want to be unambiguous about it. We do not:
- sell your data, to anyone, ever;
- rent, trade, license or barter your data;
- pass your email address or contact details to marketing lists, mailing list providers or newsletter partners;
- share your data with advertising networks, ad exchanges, data brokers, data enrichment services or lead generation companies;
- place advertising or third-party tracking pixels on this site;
- sell or supply your data for training artificial intelligence models — this project exists to defend human authorship, and monetising your data to train AI would contradict everything we stand for;
- hand over your data to sponsors, investors, partner organizations or other badge holders;
- use your email address to send you anything unrelated to your certification.
There are exactly two exceptions, and both are narrow:
- Service providers that run the service for us. Our website hosting, database, image file server and email delivery are operated by suppliers. They process the data only in order to keep the service working, on our instructions, and are not allowed to use it for their own purposes. They are our infrastructure, not an audience for your data.
- The law. If we ever receive a valid, legally binding order from a competent authority, we have to comply. If that ever happens and we are permitted to tell you, we will.
How we use your data on social media
Beyond running the certification itself, promotion is the only thing we use your data for. Certification is worth more when people see it, so we post about new and existing badge holders on the Done By Humans accounts on Bluesky, LinkedIn, Instagram and similar platforms.
Those posts are built only from the information that is already public on your badge page:
- your name;
- your website;
- your description, or a short excerpt of it;
- your logo;
- your social media handles, so that we can tag or mention you and the post reaches your own audience.
We never publish your email address or your contact person’s name in a social media post. We do not create accounts, profiles or advertising audiences from your data on those platforms, and we do not upload contact lists to them.
Posts serve two purposes at once: promoting you as a badge holder, and promoting the idea of human-made work in general. If you would rather not be featured, tell us and we will stop — see Your choices and your rights below. Your certification stays valid either way.
Cookies
We use two kinds of cookies, and no more:
- An essential session cookie, set only when you log in to your account, so that the site remembers you are signed in. It disappears when you log out.
- Google Analytics cookies, which give us anonymous statistics about how many people visit the site and which pages they read. We use this only to understand whether the project is reaching people.
We do not use advertising cookies, retargeting cookies, social media tracking pixels, or any cookie that follows you to other websites.
How long we keep your data
We keep your certification record for as long as your badge is active, because the badge is meant to be publicly verifiable. If you ask us to delete your record, we remove it from our database and take your badge page down. Copies may remain for a short period in routine technical backups before they are overwritten.
Social media posts that were already published stay on the platforms where they were posted unless we delete them. If you ask us to remove past posts about you, we will delete the ones we control.
Your choices and your rights
Your data belongs to you. At any time you can ask us to:
- tell you exactly what we hold about you;
- correct anything that is wrong or out of date;
- delete your record and your badge page entirely;
- stop featuring you in social media posts, or remove posts we have already published;
- remove your logo or your social media handles from your public badge page;
- send you a copy of your data.
You can edit most of this yourself from your account. For anything else, write to thisisdonebyhumans@gmail.com and we will act on it. There is no form to fill in and no retention team to argue with.
Security
Passwords are stored as one-way hashes, never as readable text. Access to the certificate database is limited to the people who operate Done By Humans. We keep the amount of personal data we hold deliberately small — the less we store, the less there is to lose.
Children
Done By Humans is intended for creators, businesses and organizations. We do not knowingly collect data from children under 16. If you believe a child has submitted data to us, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page. If a change ever affects how we use certificate holders’ data, we will tell badge holders by email before it takes effect. We will not introduce data selling or third-party sharing through a quiet policy update.
Contact
Questions about this policy, or about anything we hold about you: thisisdonebyhumans@gmail.com.
