Privacy
We cannot leak what we never receive.
Last updated 15 August 2026
Operator: SelfSignedCert · https://selfsignedcert.com
The short version
Certificate generation happens 100% in your browser. SelfSignedCert does not upload, store, log, or back up certificates, private keys, CSRs, PFX files, or passphrases. If our servers were emptied tomorrow, your keys would not be on them — they were never there.
What never leaves the device
- Private keys
- Certificate PEMs, DERs, and PKCS#12 bundles
- Certificate signing requests
- PFX passwords
- The form values used to mint a certificate, unless you choose to keep local metadata
What may live in this browser
If you use the dashboard, SelfSignedCert can keep a metadata history in your local storage: common name, SANs, algorithm, timestamps, and fingerprints. That data is not a backup of the certificate. Clearing site data removes it. We cannot recover a private key from it.
Accounts
You can sign in with Google. We store your Google account id, name, email, plan, usage count, and login times so we can apply Free / Plus / Studio limits. That account data is not a certificate and is not a private key. You can delete the account from Settings.
Live SSL checks
The SSL checker is the one tool that leaves your browser: we open a TLS connection to the public hostname you type and read the certificate that site presents. We do not store the lookup. Private keys are never sent.
Payments
Paid plans are processed by Dodo Payments when checkout is enabled. SelfSignedCert receives plan and payment metadata only — never card numbers and never private keys.
Analytics and contact
We may collect anonymous traffic metrics and the contents of messages you send via the contact form. Those channels are unrelated to certificate issuance. Do not paste a private key into a message.
Ask us
Privacy questions: selfsignedcert@klickleads.com. If you need a DPA or a written architecture note for a security review, ask. The answer will still be: we do not hold the material.