MyPapers
Data & Trust

Privacy Policy

Last Updated: July 27, 2026

1. Our Approach

Student privacy is a design constraint at MyPapers, not a policy promise added afterwards. Protecting academic integrity should never mean exposing a graduate’s personal history to public indexing, scraping, or a single central database that becomes a target.

We hold the minimum necessary to answer the question a verifier is asking, and we hold everything else behind an access control. There is no searchable public registry of graduates. Nobody can browse our platform by name, by institution, or by graduating year.

2. How the Architecture Protects Students

The platform runs on two separate tiers, and the separation is the privacy control:

  • A public verification network, distributed worldwide so a scan is answered near the person scanning. It carries only a minimal published slice of each credential — enough to confirm that a certificate is genuine, and no more.
  • A secure vault, the single system of record. Transcripts, registration numbers, dates of birth, and the sealed document files live here and nowhere else. The vault is not addressable from a browser; every request reaches it through our verification network.
  • A publishing gate decides what is permitted to leave the vault for the public tier. Sensitive fields are not on the list, and the gate is enforced in code rather than by convention.
  • Single-use, expiring access. Private detail leaves the vault only when an approved verifier redeems a one-time ticket that expires within three minutes and cannot be reused.
  • No enumeration. A lookup requires the identifier printed on the certificate, drawn from a space far too large to guess, and repeated probing for identifiers that do not exist is rate-limited and locked out.

3. What Is Held Where

We would rather show you the boundary than describe it. On the public verification network, a credential is represented by:

  • its MyPapers identifier;
  • whether the credential is sealed or has been revoked;
  • an integrity hash of the sealed document;
  • the name of the issuing institution;
  • the graduate’s name — the one detail a verifier must be able to match against the certificate in their hand for the check to mean anything;
  • a routing pointer back to the vault.

Everything else stays in the vault and is never published to the global tier: the transcript and individual grades, the final CGPA, the official registration number, the graduation date, the date of birth, and the sealed certificate file itself. The date of birth is not published in any form, not even as a hash.

This is why a public verification confirms that a certificate is genuine without disclosing a graduate’s academic performance. Academic detail is released only to a verifier the institution’s policy allows, and only for the single credential they asked about.

4. Institutions & MyPapers

Where a university issues credentials through our platform, the university remains the controller of its student data and the authority over what is issued, corrected, revoked, or deleted. MyPapers acts as a processor, handling that data on the institution’s instructions to provide sealing and verification.

Each institution has its own signing key and its own console accounts. One institution’s records are never visible to another, are never used to train any model, are never sold, and are never added to the public demonstration set on this website.

We disclose records to third parties only where an approved verifier is authorised to retrieve them, or where we are compelled by law.

5. Information We Collect

  • Credential records. Supplied to us by a partner institution in order to seal and verify its certificates, as described above.
  • Enquiry details. When you contact us through the Early Access page we receive your name, institution, country, email address, contact number, and any message you write. We use these solely to respond to your enquiry.
  • Operational data. Aggregate, non-identifying analytics — pages viewed, device type, approximate region — to understand how the site is used, plus the short-lived request logs and rate limiting needed to keep the service available and to detect abuse.
  • Verification activity. Institutions can see how often their own credentials were checked. We do not build a profile of the individuals doing the checking.

6. Document Uploads

When you verify by uploading a certificate rather than typing its identifier, the file is transmitted over an encrypted connection directly to the secure vault — the only tier permitted to handle documents. It is inspected in memory to read the QR code, the hidden watermark, and the printed text, and it is then discarded.

Uploaded documents are not stored, indexed, published, copied to the global tier, or used to train any model. Only the claims already printed on the certificate are returned to the person who uploaded it.

7. Retention & Deletion

A credential is meant to outlast the platform that verifies it, so records issued by an institution are retained for as long as that institution wants them verifiable. Suspending a credential is reversible and deliberately leaves it verifiable as revoked, so that a verifier is told the truth rather than being told the certificate does not exist.

An institution may direct us to delete its records entirely. When it does, we withdraw the published copies from the global verification network before erasing the vault, so that no public tier is ever left answering for a record we no longer hold. Deletion is irreversible and covers the credentials, the sealed documents, the console accounts, and the institution’s signing key.

Enquiry details submitted through the Early Access page are kept only as long as needed to handle the enquiry and our subsequent relationship with you.

8. Security

We build on world-class infrastructure and apply the security practices expected of a system that holds academic records: encryption in transit throughout, each institution’s signing key held wrapped by a key-management service rather than in plain configuration, authenticated and separately credentialled administrative surfaces, single-use expiring tokens for private retrieval, and rate limiting against enumeration and abuse.

Our verification network is globally distributed for availability and speed, while the records themselves are consolidated in a regional vault that is kept separate from it. Extending that regional model with continent-level deployments, so that each region’s records are served and stored closest to the institutions they belong to, is an active part of our roadmap.

Institutional partners receive a fuller security description and service commitments as part of their agreement. If you believe you have found a vulnerability, please write to info@mypapers.co and give us a chance to fix it before disclosing it.

9. Your Rights

You may ask us for a copy of the personal data we hold about you, or ask us to correct or delete it. Write to info@mypapers.co.

If you are a graduate and your request concerns your credential record, your institution is the controller of that record — we will pass your request to them and support them in acting on it, since only the issuing institution can correct or withdraw a credential it issued.

Ready to make forged certificates impossible?

Early Access partners onboard first — with priority onboarding and founding-partner benefits locked in.