Privacy
Effective 2026-08-16
projectcert is a public research catalog. Reading any page of it requires no account, no sign-in, and no personal information. The site sets no cookies, stores nothing in the browser, and does not track visitors between sites or build advertising profiles.
What is collected
Two categories of data arise from ordinary use of the site, both processed by Cloudflare, which serves the catalog.
Aggregate usage measurement
Public pages load Cloudflare Web Analytics. It records page views, referring pages, approximate country, and browser and operating-system family. It sets no cookie and assigns no persistent browser identifier: visitor uniqueness is derived from the IP address, user-agent string, and other request headers, which are hashed and then discarded rather than stored. Because nothing is written to or read from the visitor's device, no consent banner is required under the ePrivacy Directive. The measurement is nevertheless described here because IP addresses and user-agent strings are personal data under the General Data Protection Regulation.
The analytics beacon is loaded on public pages only. The reviewer console and the embeddable map carry no analytics, so a site embedding the map does not report its visitors to this catalog.
Network and security logs
Cloudflare processes request metadata — IP address, timestamp, requested path, user agent — in the course of delivering the site and protecting it from abuse. This processing is inherent to serving a website over the public internet and is performed by Cloudflare as a processor under its own retention schedule.
The reviewer console
A separate, access-controlled area of the site allows authorized reviewers to confirm individual data points against source documents. It is not public and is excluded from search indexing. Authentication is handled by Cloudflare Access against an explicit list of permitted email addresses.
A reviewer's email address is recorded alongside each confirmation that reviewer makes, together with the date and a fingerprint of the value as it stood at that moment. That record is deliberate: a catalog that reports data as verified must be able to say who verified it and against what. Reviewer identities are not published; the public pages report only how many data points have been confirmed.
What is not done
- No cookies are set, and no data is stored in the browser.
- No advertising, no advertising networks, and no cross-site tracking.
- No personal data is sold, rented, or shared for marketing.
- No accounts, newsletters, or mailing lists exist for the public site.
- No third-party scripts load other than the analytics beacon described above.
Processors and transfers
Cloudflare, Inc. hosts the site, serves it through its global network, and provides the analytics and access control described above. Its handling of personal data is governed by its own privacy commitments, which are published at cloudflare.com/privacypolicy (opens in a new tab) . No other processor receives data from this site.
Links to state education agency sources
Every fact in the catalog cites a source document, most of which are hosted by state education agencies or legislatures. Following such a link leaves this site, and the destination's own privacy practices apply. This catalog receives no information about which external links a visitor follows.
Retention
No visitor-level records are retained by this catalog. Analytics data exists only in aggregate form within Cloudflare's dashboard, and the identifiers used to compute it are discarded at the point of collection. Reviewer confirmations persist for as long as the catalog reports the corresponding data as verified, because the provenance claim depends on them.
Legal basis and rights
Where the General Data Protection Regulation applies, the processing described above rests on legitimate interests under Article 6(1)(f): operating and securing a public research resource and understanding its aggregate use. Data subjects hold the rights set out in Articles 15 to 21, including access, rectification, erasure, and objection. In practice, because no visitor-level records are retained, there is generally no individual record to retrieve or delete.
Children
The catalog documents teacher certification policy and is intended for researchers, policymakers, teacher educators, and journalists. It is not directed at children and collects no information from them knowingly.
Changes
Material changes to this policy will be reflected in the effective date above. Because the site is published from a public repository, the full revision history of this page is preserved in the project source (opens in a new tab) .
Contact
Enquiries about this policy, and requests relating to the rights described above, may be raised on the project issue tracker (opens in a new tab) .
This policy covers https://projectcert.org and every page served from it.