SelfBadge (the website and app at selfbadge.com) gives people one verified, public profile that AI assistants, search engines and other systems can read. This policy explains what information SelfBadge collects, what we publish, what we keep private, and the choices you have.
SelfBadge is operated by Buzz Dealer (Cyprus) Ltd, Agias Filaxeos 122A, Limassol 3087, Cyprus ("SelfBadge", "we", "us"), which is responsible for your information. For privacy questions, write to [email protected].
The short version
- A SelfBadge profile is public by design. You choose what goes on it, and every field has a public or private switch.
- When you sign in with LinkedIn or Google we receive your name, email address and profile photo. We never receive your password.
- Your sign-in email is used to verify you and to contact you about your account. It is never shown on your profile.
- We never collect phone numbers, home addresses or information about your family.
- We do not sell personal information and we do not show ads.
- You can edit or delete anything on your profile, and anyone can ask us to remove a profile about them.
Information we collect
When you sign in
You can sign in with LinkedIn (using "Sign In with LinkedIn using OpenID Connect") or with Google. The provider sends us:
- your name (and first and last name when available),
- your email address and whether the provider has confirmed it,
- your profile photo address, if you have one,
- an account identifier from the provider.
We do not receive your LinkedIn or Google password, your connections, your messages or your posts, and we do not post anything on your behalf. We do not keep the provider's access tokens after sign-in is complete.
What you add to your profile
Anything you enter in the editor: for example your job title, employer, education, credentials, awards, topics, languages, links to your accounts, articles and mentions, and a photo you upload or link to. Some optional fields (birth date, birthplace, nationality, gender and home city) are private unless you switch them on.
When you verify a fact
When you connect an account or verify a website, a work email or a credential, we record how and when it was verified (for example "work email verified on a date"). We keep the account's identifier, handle and profile address. For a work email we send a one-time code and keep only a secure hash of it.
Accounts you connect
When you press Connect next to an account, you log in on that platform and it tells us only what proves the account is yours. We use the access it gives us once, during that request, and never store it. What we read:
- ORCID: your ORCID iD and name.
- YouTube (read-only access): the ID, title and handle of the channel you own.
- Google Search Console (read-only access): the list of sites you verified as owner. We keep only the sites you choose to show.
- Facebook: your app-scoped account ID and name. Facebook does not share your profile address, so the address on your profile stays "added by you".
- Instagram (Business and Creator accounts): your user ID and username.
- TikTok: your account ID and username.
- X, GitHub and LinkedIn (through our sign-in provider): your account ID and, for X and GitHub, your handle.
SelfBadge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never use data from connected accounts for advertising and never sell or share it. Google access is revoked right after the check.
Profiles created from public sources
Some profiles are created from openly licensed public sources, starting with Wikidata (public domain, CC0) and later public-domain government filings. These profiles show where each fact came from, stay out of search engine indexes until the person claims them, and never include birth dates, gender, any special category of data (such as political party, religion or trade union membership), or anything taken from LinkedIn. We read the birth year only to leave out people born before 1940, and never keep it. Photos on these profiles come only from Wikimedia Commons, with credit and license. If a profile about you was created this way, you can claim it, correct it, or have it removed (see "Removal" below). Profiles from public sources explains exactly who is included, which fields we take and never take, why, and how to claim, correct or remove a profile.
When you send a report
The report form asks for the profile, a reason, your email address (needed to remove a profile or report impersonation, optional otherwise) and any details you give. We use them only to handle that report: for removal and impersonation we email you a one-time link to confirm it is you, and keep only a secure hash of that link. To stop abuse we count reports per network address for an hour, keeping only a keyed hash of the address, in memory.
Technical information
Our hosting and security providers process technical information such as IP addresses, browser type and request logs to deliver pages, stop abuse and keep the service secure. We use only the cookies needed to keep you signed in. We do not use advertising or cross-site tracking cookies, or analytics.
How we use information
| Purpose | Information | Legal basis (EU and UK) |
|---|---|---|
| Create and run your account and profile | Sign-in details, profile content | Performing our agreement with you |
| Publish your profile for people and machines | Only the fields you make public | Performing our agreement with you |
| Verify facts about you | Verification records | Performing our agreement with you |
| Send account and verification emails | Sign-in email | Performing our agreement with you |
| Create profiles from open public sources | Public facts from Wikidata and similar sources | Legitimate interests (accurate public information), balanced by removal on request |
| Handle reports, corrections and removal requests | The report, your email address, the profile concerned | Legal obligations (your data protection rights) and legitimate interests (preventing impersonation and keeping profiles accurate) |
| Security and abuse prevention | Technical information | Legitimate interests |
What we publish
The public fields of your profile appear on your page at selfbadge.com/your-handle and in machine-readable versions of it (structured data in the page, a JSON file, a text file for AI systems, and sitemaps). AI assistants, search engines and other services can read, copy and index this information. Once information is public, copies may remain in other services after you change or delete it here; we tell search engines when a page changes or is removed, but we cannot control copies others have made.
How each fact was verified is shown next to it. Your sign-in email, private fields and verification codes are never published.
Who we share information with
We use these service providers to run SelfBadge. They process information only on our instructions:
- Supabase: database, sign-in and photo storage, in Frankfurt (EU).
- DigitalOcean: application hosting, in Frankfurt (EU).
- Cloudflare: DNS only. Cloudflare does not process visitor traffic for selfbadge.com. If the report form's bot check (Cloudflare Turnstile) is switched on, Cloudflare processes technical information about people who open that form.
- Resend: sending account and verification emails. Resend stores the email address and message in the United States, covered by the EU-US Data Privacy Framework and the Standard Contractual Clauses in Resend's data processing agreement.
- LinkedIn and Google: only when you choose to sign in with them.
- ORCID, Google (YouTube, Search Console), Meta (Facebook, Instagram), TikTok, X and GitHub: only when you choose to connect an account.
- Stripe: payments and identity checks, only if you choose a paid plan or ID verification (later).
We may also disclose information when the law requires it, or to protect people from impersonation, fraud or harm.
International transfers
Our main database and servers are in the European Union. Some providers may process information in other countries, including the United States: for example Resend, which sends our emails from the United States under the EU-US Data Privacy Framework and the Standard Contractual Clauses in its data processing agreement. Where information leaves the European Economic Area we rely on such safeguards: an adequacy decision (the Data Privacy Framework), or the European Commission's Standard Contractual Clauses in each provider's data processing agreement.
How long we keep information
- Your profile and account: until you delete them.
- Verification records: while the verified fact is on your profile, and up to 12 months after, as an audit trail.
- Removal requests: we keep a minimal record of removed people permanently so that automated imports never recreate their profile.
- Reports and the email address sent with them: up to 24 months after the report is closed. Unused confirmation links expire after 24 hours.
- Server logs: up to 30 days.
Your choices and rights
- Edit any field, switch it between public and private, or delete it, at any time in the editor.
- Unpublish your profile, or delete your account and profile.
- Ask for a copy of your information, or ask us to correct or erase it.
- Object to how we use information, or ask us to restrict it.
- Complain to a data protection authority: our lead authority is the Commissioner for Personal Data Protection (Cyprus) (www.dataprotection.gov.cy), and you can also complain to the authority where you live or work.
Self-service export and account deletion arrive in settings shortly after launch. Until then, email [email protected] and we will act within 30 days.
Removal and impersonation
Anyone, including people who do not use SelfBadge, can ask us to remove a profile about them with the removal form, linked as "Remove this profile" on every profile. Removal of a profile created from public sources needs only an email confirmation: when you open the link we send, the profile is removed and added to our suppression list, so it is never created again. If you report impersonation and confirm your email, we hide the profile at once while we review the report.
Children
SelfBadge is not for anyone under 16. We do not knowingly create or keep profiles of children.
Security
Access to data is limited by database rules on every table, the keys that can bypass them stay on our servers, connections are encrypted, and administrative actions are logged. No system is perfectly secure; if we learn of a breach that affects you, we will tell you as the law requires.
Changes to this policy
We will post any change here and update the date at the top. If a change is significant, we will also email account holders before it takes effect.
Contact
Buzz Dealer (Cyprus) Ltd, Agias Filaxeos 122A, Limassol 3087, Cyprus. Email: [email protected].