Minimal data. Clear purpose.
This notice covers the Voice AI Space certification service. It should be read alongside the main Voice AI Space privacy policy.
Voice AI Space operates the credential service. Privacy and credential questions can be sent to tbot@voiceaispace.com.
For the public beta: a random browser identifier, candidate-entered result name, assessment level, question identifiers, submitted options, timing, score, and domain results. For certification: authenticated account email and name, candidate-selected credential name, credential status, and security audit events are also processed.
The beta sets a secure, HttpOnly practice identifier cookie for 30 days. It contains a random identifier—not your email—and is used to keep your session private to your browser and enforce attempt limits. A passing result is published as a credential only after you choose to claim it and sign in.
If you pass and consent to issuance, your credential name, score, level, issue date, expiry date, credential ID, assessment version, and status are public at a stable verification URL. Your email address is not displayed.
The service stores a keyed, non-reversible identifier derived from the authenticated email for attempt controls. Open Badges 2.0 delivery uses a credential-specific salted email hash as required for recipient matching.
Data is processed to administer the requested assessment, prevent abuse, issue and verify credentials, maintain auditability, handle appeals, and meet security obligations. Public publication occurs only after the candidate declaration and a passing result.
Credential and audit records are retained while a credential remains verifiable and for a reasonable period afterward to preserve revocation and dispute history. Unfinished and failed attempts should be periodically deleted or anonymized under the operational retention schedule.
You may request access, correction, or deletion where applicable. A public credential can be revoked and de-indexed, but a minimal revocation record may be retained to prevent a previously issued credential from appearing valid.
The service uses infrastructure providers to authenticate users, run the application, and store credential records. Production launch requires processor and transfer terms appropriate to the regions served.
Correct answers are excluded from public source and browser bundles. Issuance is server-side, credentials are signed, administrator actions are restricted, and security events are logged. No system can promise absolute security.