PRIVACY POLICY

My Record Locker

Effective Date: June 26, 2026


1. Introduction

This Privacy Policy describes how Kryptomneme LLC, doing business as My Record Locker ("We," "Us," "Our"), collects, uses, stores, and discloses personal information through the My Record Locker platform (the "Platform"), currently accessible at my-record-locker.onrender.com (migrating to MyRecordLocker.com).

My Record Locker is a platform that delivers training modules and issues cryptographically signed Completion Records — tamper-evident records that formal instruction occurred and that a sampled identity check took place. The Platform does not guarantee, certify, or ensure regulatory compliance.

By using the Platform, you agree to the collection and use of information as described in this Privacy Policy. This Privacy Policy is incorporated into and subject to Our Terms of Service.

2. Information We Collect

2.1 Information Provided by Customers (Organization Administrators)

When a Customer organization creates an account, We collect:

2.2 Information Provided About or by Users (Learners)

When a Customer invites Users (learners) to complete training, We collect:

2.3 Information Generated During Training Sessions

When a User completes a training module, the Platform automatically collects and records:

This information is stored as an append-only, hash-chained event log and is incorporated into the Completion Record upon issuance.

2.4 Technical and Usage Information

In the course of operating the Platform, standard technical data may be processed, including:

This technical data is used to operate, secure, and troubleshoot the Service, and is not used to track Users across other websites or for advertising.

2.5 Information We Do NOT Collect

3. How We Use Information

We use the information We collect for the following purposes:

(a) Delivering the Service. Processing training-module delivery, recording session events, issuing Completion Records, and enabling record verification.

(b) Identity Verification. Performing sampled identity checks during training sessions (for example, sending a one-time-password code to the User's email address). These checks are sampled, not continuous; the Platform does not claim continuous identity assurance.

(c) Account Administration. Managing Customer accounts, processing payments (via Stripe), managing User invitations and the quizzes and records allocated to a plan, and enabling Customers to export their data.

(d) Record Integrity. Maintaining the cryptographic chain of each Completion Record, including hash chaining, digital signing, and enabling verification through the Platform's verification endpoint.

(e) Communication. Sending transactional emails, including invitation emails, one-time-password codes, and account-related notifications.

(f) Service Improvement and Security. Diagnosing technical issues, monitoring for unauthorized access, and improving the Platform's reliability and functionality.

We do not sell personal information. We do not use personal information collected through the Platform for advertising purposes.

4. Completion Records and Append-Only Storage

Completion Records are cryptographically signed, tamper-evident records. They are stored in an append-only system — once a record is issued, the underlying events and the signed record are never deleted or retroactively altered under normal operation.

The verification endpoint (publicly accessible) displays only validity information (signature and chain integrity) and non-personally-identifiable context (issuing organization, course, outcome, dates). The verification endpoint does not display the learner's name or employer reference.

Named Completion Records (containing learner-identifying information) are accessible only to the issuing Customer through authenticated export and are protected by a capability token.

If a data-deletion or anonymization request is received, personally identifiable information is removed from the record and a redaction event is appended to the chain. The cryptographic integrity of the chain is preserved — hashes remain, but identifying information is removed. See Section 8 (Data Retention and Deletion) for details.

5. Third-Party Service Providers

We use the following third-party service providers to operate the Platform. Each provider processes data only as necessary to perform its specific function:

5.1 Stripe (Payment Processing)

Stripe, Inc. processes all payments on Our behalf through hosted checkout. Kryptomneme LLC never receives or stores raw credit card numbers. Stripe's handling of payment data is governed by Stripe's own privacy policy and PCI DSS compliance.

Website: https://stripe.com/privacy

5.2 Resend (Transactional Email)

Resend is used to deliver transactional emails, including User invitations and one-time-password codes for identity verification. Resend processes recipient email addresses and email content as necessary to deliver these messages.

Website: https://resend.com/legal/privacy-policy

5.3 Render (Hosting Infrastructure)

The Platform is hosted on Render. Render provides the server infrastructure and persistent storage on which the Platform and its database operate. Render may process IP addresses, request metadata, and other technical data in the course of providing hosting services.

Website: https://render.com/privacy

5.4 Backblaze B2 (Encrypted Off-Site Backup)

Encrypted backups of the Platform's database and signing keys are stored off-site on Backblaze B2, under Kryptomneme LLC's sole control. Backup files are encrypted before upload; Backblaze receives and stores only the encrypted backup artifacts and does not have access to the decryption keys.

Website: https://www.backblaze.com/company/privacy.html

We do not share personal information with any third party for advertising, marketing, or any purpose unrelated to the operation of the Service. We may disclose information if required by law, regulation, legal process, or enforceable governmental request.

6. Cookies and Tracking

6.1 Essential Cookies

The Platform uses essential cookies and session identifiers necessary for the operation of the Service (for example, maintaining login sessions and tenant context). These cookies are strictly functional and are not used for advertising or cross-site tracking.

6.2 No Third-Party Tracking

The Platform does not use third-party advertising cookies, tracking pixels, social-media widgets, or analytics services that track Users across other websites. We do not participate in behavioral advertising networks.

7. Data Security

We implement reasonable administrative, technical, and physical safeguards to protect personal information from unauthorized access, alteration, disclosure, or destruction. These safeguards include:

No system can be guaranteed secure against every threat, and We do not represent that the Platform is impervious to unauthorized access. We review and improve Our security practices over time and will update this Policy to reflect material changes.

8. Data Retention and Deletion

8.1 Retention Period

Completion Records and associated event data are retained for the retention period configured at the time of record issuance. Retention periods are configured by the Customer based on the Customer's own regulatory or business requirements. Customers are responsible for determining the retention period appropriate to their use and configuring the Platform accordingly.

8.2 Deletion Requests

Because Completion Records are stored in an append-only system, deletion in the conventional sense is not performed. Upon receiving a valid deletion or anonymization request:

(a) Personally identifiable information (learner name, employer reference) is removed from the record.

(b) A redaction event is appended to the event chain, documenting that redaction occurred.

(c) The cryptographic chain (hashes, signatures) is preserved in redacted form — the existence of the record remains visible, but the identity of the individual is removed.

(d) This process is irreversible once executed.

8.3 Account Termination

Upon termination of a Customer's account, the Customer may request a full export of their data. Following export (or after a reasonable period), the Tenant Workspace is marked as terminated. Previously issued Completion Records remain verifiable through the verification endpoint for the remainder of the applicable retention period. Data is not destroyed upon account termination — it is retained in accordance with the retention policy.

9. Data Subject Rights

Depending on applicable law, individuals may have the following rights with respect to their personal information:

(a) Right of Access. The right to request a copy of the personal information We hold about you. Customers may access and export their data, including Completion Records, through the Platform's custody interface. Users (learners) may request access through their employing Customer or by contacting Us directly.

(b) Right of Rectification. The right to request correction of inaccurate personal information. Because Completion Records are append-only, corrections are appended as new events rather than retroactively modifying prior entries.

(c) Right of Deletion / Anonymization. The right to request deletion of personal information, subject to the append-only constraints described in Section 8.2 above. We honor deletion requests by anonymizing the record rather than destroying it, to preserve the cryptographic integrity of the event chain.

(d) Right to Restrict Processing. The right to request that We limit the processing of your personal information under certain circumstances.

(e) Right to Data Portability. The right to receive your personal information in a structured, commonly used, machine-readable format. The Platform supports export in CSV and JSON formats.

(f) Right to Object. The right to object to processing of your personal information under certain circumstances.

To exercise any of these rights, contact Us at the address provided in Section 15. We will respond within the timeframe required by applicable law. We may require verification of identity before processing a request.

Note: Because training records serve a legitimate business purpose for the employing Customer (documenting that training occurred), deletion requests from individual Users may be subject to the Customer's own data-retention obligations and policies. We will work with the Customer and the requesting individual to find a resolution that respects both parties' rights and obligations.

10. Multi-Tenant Architecture and Data Isolation

The Platform operates as a multi-tenant service. Each Customer's data is logically isolated within its own Tenant Workspace. We implement technical controls designed to prevent cross-tenant data access. Users in one Customer's Tenant Workspace cannot access another Customer's data through the Platform.

11. Children's Privacy

The Platform is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16. If a Customer invites a User who is under 16 to use the Platform, the Customer is responsible for ensuring that any required parental or guardian consent has been obtained in accordance with applicable law. If We become aware that We have collected personal information from a child under 16 without appropriate consent, We will take steps to anonymize or delete that information.

12. International Data Transfers

The Platform is hosted in the United States. If you access the Platform from outside the United States, your personal information may be transferred to and processed in the United States. By using the Platform, you consent to such transfer. We will implement appropriate safeguards for international transfers as required by applicable law.

13. Breach Notification

In the event of a data breach that affects the security of personal information, We will notify affected Customers and, where required by applicable law, affected individuals and relevant supervisory authorities, within the timeframe required by applicable law. Notification will include a description of the nature of the breach, the categories of data affected, the measures taken to address the breach, and recommendations for affected individuals.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to Customers via email to the account's registered address or through a notice within the Platform at least thirty (30) days before the changes take effect. The "Effective Date" at the top of this Policy will be updated to reflect the date of the most recent revision.

15. Contact Information

For questions or to exercise your data-subject rights, email hello@myrecordlocker.com

For enterprise Customers requiring a Data Processing Addendum (DPA), a standard-form DPA is available at /dpa/.