← CredibleID

Privacy Policy

Last updated 27 July 2026 · CredibleID is a student project built for a Year 11 Applied Computing assessment.

1. What we collect

Account data (name, email address, Student ID or organisation name) and, for students, the certificate details issued by institutions (qualification, year, grade). For employers and schools we also keep a usage record for billing and an audit log of verifications.

2. Where it lives

Data is stored in Google Firebase (Cloud Firestore and Firebase Authentication). Passwords are hashed by Firebase Authentication — CredibleID never sees or stores your password. Certificate records are immutable by design: server rules refuse any edit after issue. The iPhone app keeps a copy of a student's own wallet on their device for offline use.

3. Who can see what

Your certificates are visible to signed-in users only when they have your Certificate ID or QR code — you choose who to give it to. The administrator can see account records to manage the service. We do not sell or share data with anyone else, and there is no advertising or analytics tracking.

4. Emails

We send account emails only: password set-up links for accounts created for you, and password reset links you request. These are sent by Firebase Authentication.

5. Your choices

You may reset your password at any time, and may ask us to delete your account by emailing support@molii.my. Note that issued certificate records are immutable and remain on the ledger; deleting an account removes the login and profile, not the institution's issued records.

6. Compliance intent

The design follows the principles of Malaysia's Personal Data Protection Act 2010: collect the minimum, use it only for the stated purpose, and secure it.