Skip to content
Legal

Privacy Policy

Last updated: August 2026. This policy explains what data the Academy collects, why, and the choices you have.

Who we are

Engineering Management Academy (“EMA”, “the Academy”, “we”) operates www.engineeringmanagement.academy, an independent certification platform for engineering management. For any privacy matter, contact us via the details on the Contact page.

What we collect

  • Account data — when you sign in with Google, we receive your name, email address, and profile photo from your identity provider. We do not receive or store your password.
  • Profile data — information you choose to add, such as a username, headline, or public profile settings.
  • Examination records — your examination sittings, answers, scores, and outcomes. These form the basis of any credential we issue and are retained as part of the certification record.
  • Credential data — issued certificates, including the holder name printed on them, credential IDs, dates, and status.
  • Waitlist data — your email address, if you join a certification waitlist.
  • Research survey data — answers to the State of Engineering Management survey are anonymous; an email address is stored only if you choose to provide one to receive the report, and is never linked to your answers in published analysis. Only aggregated results are published, with small segments suppressed.

We do not run advertising trackers and we do not sell personal data.

Cookies and browser storage

Two kinds, and only two. The first kind is necessary to run the site and cannot be turned off without breaking sign-in. The second kind is analytics, which we ask about before setting anything and which the site works fine without.

  • Authentication (necessary) — Supabase sets cookies that keep you signed in. Without them, every page would ask you to sign in again.
  • Administration session (necessary) — a signed, HTTP-only cookie used only by Academy staff signing into the admin area.
  • Your analytics answer (necessary) — one entry in your browser’s local storage recording whether you accepted or declined analytics, so we stop asking.
  • Analytics (optional, off until you accept) — PostHog records which pages are visited and how features are used, under a random identifier. It is not started at all unless you accept, and it is never used for advertising.

How we use it

  • To operate the platform: delivering and scoring examinations, and issuing credentials.
  • To provide public credential verification — by design, anyone with your credential ID can confirm your name, certification, dates, and status. This is the purpose of a verifiable credential.
  • To send transactional email about your account, sittings, and credentials.
  • To protect examination integrity, including investigating suspected misconduct.

Public information

Credential verification responses are public for anyone holding your credential ID. Your public profile page is visible to anyone with the link; you control whether your certifications appear on it from your profile settings. Note that disabling profile visibility does not disable credential verification — verification exists for third parties relying on the credential.

Where your data lives

The platform is hosted on Vercel, with data stored in Supabase (Postgres) and transactional email delivered via Resend. Authentication is provided by Google OAuth through Supabase Auth. An encrypted nightly backup of the database is held by GitHub, so that a failure at Supabase cannot take the only copy of your records with it; those copies are kept for 14 days and then deleted. Each processor handles data under its own security and compliance programs.

Retention

Examination and credential records are retained for as long as the credential may need to be verified — including after expiry, so that historical verification remains possible. Account data is retained while your account is active. Payment records are retained for as long as tax and accounting law requires.

Getting a copy of your data

From Profile → Settings → Your Data you can download everything we hold about your account as a single JSON file: your profile, examination sittings and results, credentials, payments, waitlist entries, and any survey response submitted under your email address. No request or waiting period — the file is generated when you ask for it.

Deleting your account

You can delete your account from the same screen. Deletion is in two stages, and we tell you plainly what survives it.

  • Immediately — your account is deactivated, your public profile stops resolving, and we stop emailing you. Nothing has been erased yet.
  • After 30 days — your personal data is erased: name, email address, photo, headline, location, LinkedIn URL, biography, username, notification preferences, the answers you gave in any examination, and the answer-level detail of sittings you completed. This step is irreversible. Signing back in during those 30 days cancels the deletion.

What we keep, and why. A credential you earned stays in the verification registry after your account is gone — the credential ID, the certification, the issue and expiry dates, its status, and the holder name printed on it. This is the point of a verifiable credential: an employer given your credential ID two years ago must still be able to check it, and a certification that silently disappears is worth nothing to the people who hold one. We also keep the examination result the credential rests on, because it is the evidence behind the claim — though not the answers you gave. Payment records are kept for tax and accounting purposes. If you would rather have a credential withdrawn entirely, contact us and we will retire it, which makes verification report it as withdrawn rather than valid.

Your rights

Access and erasure are self-serve, as described above. You may also ask us to correct your data, object to processing, or request your data in another format, by contacting us. If you are in the UK or EU and think we have handled your data badly, you have the right to complain to your data protection authority.

Changes

We will update this policy as the platform evolves and revise the “last updated” date above. Material changes will be communicated to account holders by email.