Skip to content

Privacy Policy

MATERIAL
FIRST SEEN 2026-08-11 · VERSION 20260811_rev01 · FIRST CAPTURED VERSION

What changed, in plain language

How reviews are made

The prior snapshot for this policy was empty, so the entire Let's Encrypt (ISRG) Privacy Policy shows up as newly added text. This is a baseline capture rather than a real revision — nothing here is confirmed to be a new loss of rights. On its own terms the policy is unusually consumer-friendly: it states plainly that ISRG does not sell any data, does not use contact info for marketing without consent, and spells out EEA access/deletion/complaint rights. The parts worth knowing about are inherent to running a public certificate authority: if you request a certificate, your IP addresses and request logs are kept for at least two years, may be impossible to delete, and some of that information is published (for example in Certificate Transparency logs).

Changes that may affect you

Certificate request records kept at least two years and may never be deletedMATERIAL
DATA RETENTION

If you request a certificate, your IP addresses and full request logs are stored for a minimum of two years, and the policy says some of it may be impossible to delete at all because the public relies on it to judge whether certificates are trustworthy. Deletion requests, including from people in Europe, can be refused for this reason. Note this is a baseline capture, so this is almost certainly a long-standing term rather than something newly imposed.

“Please note that we may be unable to delete information, including IP addresses, as this information is necessary for others to rely on in determining the trustworthiness of our certificates.”

What you can do — Assume anything tied to a certificate request is permanent. Use a dedicated email address for your certificate account rather than a personal one if you would rather not link the two.

Some certificate information is published publiclyMATERIAL
DATA SHARING

Details connected to your certificate requests can be posted where anyone can see them, including public Certificate Transparency logs, a public API, and public discussion threads. Your email address is not part of what gets published, but domain names you request are.

“This information may be made public in a number of ways, including via public API, public repositories such as Certificate Transparency (CT) logs, and/or public discussions.”

What you can do — Do not request certificates for domain or subdomain names you want to keep secret — treat every name you request as public.

Broad logging of certificate requests and third-party analyticsMINOR
DATA COLLECTION

For certificate users, the logging is extensive: every inbound and outbound request, all resolved IP addresses, and details inferred from your software. For website visitors and email subscribers, Google Analytics tracks your browsing and Salesforce tracks email opens and clicks. Both tracking tools come with opt-outs that the policy explains.

“full logs of all inbound HTTP / ACME requests, all outbound validation requests; and information sent by or inferred from your client software”

What you can do — Install the Google Analytics Opt-out Browser Add-on, and use the unsubscribe link in ISRG emails to stop marketing email tracking.

Disclosure to law enforcement, and account recovery info shared in emergenciesMINOR
DATA SHARING

Personal information can be given to third parties under a subpoena or court order, and account recovery details can be shared without a court order if the organization believes it is needed to prevent death, injury, property damage, or major financial loss. This is narrower than most policies and comes with a promise to warn you first when legally allowed.

“We may also disclose account recovery information when we have a good faith belief it is necessary to prevent loss of life, personal injury, damage to property, or significant financial harm.”
Data can be moved to countries with weaker privacy lawsMINOR
JURISDICTION

Your information may be stored or processed in the United States and other places that protect privacy less strongly than the EEA does. Standard Contractual Clauses approved by the European Commission are used as a safeguard.

“Your personal data may be collected from or transferred to jurisdictions where we and our service providers store or process data, including the United States.”

What you can do — If you are in the EEA and want details of the transfer safeguards, email privacy@abetterinternet.org.

Changelog

  1. + ADDEDFull policy text captured for the first time

    There was no readable earlier version to compare against, so every section appears as an addition. The items below describe what the policy says, not changes that were made to it.

    The Let's Encrypt Privacy Policy describes how we collect, use, and disclose your information in three different contexts:

  2. + ADDEDThree types of people covered

    The policy treats you differently depending on whether you are just visiting an HTTPS site that uses a Let's Encrypt certificate, someone who requests certificates, or someone browsing the Let's Encrypt website and forum.

    - When you are a Visitor to the Let's Encrypt web site, community discussion forum, other web pages under letsencrypt.org, and third-party social media sites on which Let's Encrypt operates an account.

  3. + ADDEDShort log keeping for ordinary web browsing

    If your browser checks whether a certificate is still valid, Let's Encrypt may log your IP address, browser, and operating system, but says these logs are usually deleted within a week and are not used to profile you.

    Temporary server logs are used for operational purposes only and are normally deleted in less than seven days.

  4. + ADDEDCertificate requesters have detailed logs kept for at least two years

    If you request a certificate, Let's Encrypt records your IP addresses, all the addresses your domain resolves to, full logs of your requests, and information about your client software, and keeps it for a minimum of two years because certificate rules require it.

    We will store this information for a minimum of two years per trusted root program requirements.

  5. + ADDEDSome certificate data is made public and may not be deletable

    Because the public has to be able to check that certificates are trustworthy, some of this information is published, and Let's Encrypt says it may not be able to delete it even if you ask.

    This information may be made public in a number of ways, including via public API, public repositories such as Certificate Transparency (CT) logs, and/or public discussions.

  6. + ADDEDYour email address stays private and is not used for marketing without consent

    Contact information you give for account recovery is not published, and Let's Encrypt promises not to use it for marketing unless you agree. You can unsubscribe from service emails at any time.

    We will not use your contact information for marketing or promotional purposes without your consent.

  7. + ADDEDDonation handling and the companies involved

    Donations go through named payment and record-keeping companies, and ISRG collects your name, mailing address, and email, plus things like t-shirt size for donor gifts. Card and bank details are not kept by ISRG.

    We do not collect or retain any credit card or bank information related to donations.

  8. + ADDEDA clear promise not to sell data

    The policy has its own section stating that no data about any category of user is sold.

    We do not sell your data or information. This includes Relying Party, Subscriber, and Visitor data and information.

  9. + ADDEDGoogle Analytics and email open tracking

    ISRG may use Google Analytics on its websites and Salesforce to see who opens and clicks its marketing emails. Both have described opt-outs.

    ISRG may from time to time deploy third-party web and email analytics tools, specifically Google Analytics for our websites and Salesforce Account Engagement for our marketing emails.

  10. + ADDEDLaw enforcement requests, with advance notice where possible

    Information can be handed over in response to a subpoena or court order, or to prevent serious harm. Let's Encrypt says it will try to tell you first so you can object, and reserves the right to fight requests it thinks are improper.

    we will attempt to provide you with prior notice (unless we are prohibited, or it would be futile) that a request for your information has been made in order to give you an opportunity to object to the disclosure

  11. + ADDEDData may be stored in the United States

    Your data can be moved to countries with weaker privacy protection than your own, including the US, with EU-approved contract terms used as a safeguard.

    These jurisdictions may not provide the same level of data protection as your jurisdiction, including the EEA.

  12. + ADDEDSpelled-out rights for people in Europe

    EEA residents can request a copy of their data, ask for corrections or deletion, object to processing, and complain to their national privacy regulator, with email addresses given for each.

    Individuals located in the European Economic Area (EEA) have certain rights in respect to their personal information, including the right to access, correct, or delete personal data we process through your use of our sites and services.

Full text changes

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

1The Let's Encrypt Privacy Policy describes how we collect, use, and disclose your information in three different contexts:
2
3- When, as a Relying Party, you visit a web site secured with HTTPS that uses a certificate from Let's Encrypt,
4- When you are a Subscriber, i.e., when you request and use certificates from Let's Encrypt,
5- When you are a Visitor to the Let's Encrypt web site, community discussion forum, other web pages under letsencrypt.org, and third-party social media sites on which Let's Encrypt operates an account.
6
7Let's Encrypt is a service provided by [Internet Security Research Group](https://www.abetterinternet.org/), a California (United States) Nonprofit Public Benefit Corporation.
8
9## Relying Party
10
11When you use an HTTPS web site or other TLS service with a Let's Encrypt certificate, your browser (or TLS client) may query Let's Encrypt to check whether the certificate has been revoked. If your browser makes such a request, our servers may automatically record your IP address, browser, and operating system in temporary server log files. We do not use this data to build profiles or identify individuals. Temporary server logs are used for operational purposes only and are normally deleted in less than seven days. We may retain a subset of server logs for longer periods in order to investigate software failures or abuse. If we do so, we will delete any stored logs when we are done investigating. We may also compute, retain and publish aggregate information from server logs, such as which certificates generate the largest volume of requests. We will always strive to ensure that such datasets do not contain information about the activities of identifiable users or devices.
12
13## Subscriber
14
15If you are a Subscriber, you are requesting a trusted certificate from Let's Encrypt intended to publicly vouch that you control a certain domain name or names that are reachable on the Internet. As part of the process of proving that control, Let's Encrypt will collect various information related to certificate authentication and management. That information includes the IP addresses from which you access the Let's Encrypt service; all resolved IP addresses for any requested identifiers; server information related to any validation requests; full logs of all inbound HTTP / ACME requests, all outbound validation requests; and information sent by or inferred from your client software. We will store this information for a minimum of two years per trusted root program requirements.
16
17We need to be able to demonstrate to the public, including those who rely on the trustworthiness of our certificates, that our services perform as expected. As a result, we may be unable to delete information, including IP addresses. This information may be made public in a number of ways, including via public API, public repositories such as Certificate Transparency (CT) logs, and/or public discussions.
18
19You may have the option to provide contact information, such as your email address, for account service and recovery purposes. Your contact information will not be made public, and it will only be shared per "Law Enforcement and Extenuating Circumstances," below. By providing your email address, you are consenting to receive service-related emails from us. You may unsubscribe from service-related emails at any time by clicking the "unsubscribe" link at the bottom of our emails or by contacting us at [privacy@abetterinternet.org](mailto:privacy@abetterinternet.org). We will not use your contact information for marketing or promotional purposes without your consent.
20
21You may need to download client software from a repository such as those run by Debian, Ubuntu, Red Hat, or GitHub. Your interaction with such a software repository is governed by that repository's own privacy policy and/or Terms of Use.
22
23## Visitor
24
25When you are a Visitor browsing an ISRG web site, you have the option to make a donation. Donations are processed by our trusted payment partners including DonorBox, The Giving Block, Stripe, Shopify, and PayPal, depending on the payment method selected, and stored in ISRG's Salesforce database and Sage Intacct as necessary. We collect your name, mailing address, and email address when you donate. Depending on your gift, we may also collect merchandise preferences (such as t-shirt size) to fulfill donor benefits. Once you donate, we will use your information for our legitimate interest in processing and managing your contribution, including fundraising reminders and renewals or mailing a thank-you gift. We may also use your mailing address to identify and consolidate duplicate donor records in order to maintain the accuracy of our donor database. Your interactions with [DonorBox](https://donorbox.org/privacy), [Stripe](https://stripe.com/privacy/), [PayPal](https://www.paypal.com/us/webapps/mpp/ua/privacy-full), [Shopify](https://www.shopify.com/legal/privacy), [The Giving Block](https://thegivingblock.com/about/privacy-policy/), [Salesforce](https://www.salesforce.com/company/privacy/), [Monday Merch](https://www.mondaymerch.com/us/legal/privacy-policy), [Formstack](https://www.formstack.com/legal), [BoldSign](https://boldsign.com/privacy-policy/), and [Sage Intacct](https://www.sageintacct.com/privacy_policy_website) are governed by their respective privacy policies. We do not collect or retain any credit card or bank information related to donations.
26
27You may provide your email address to receive communications related to ISRG projects through a signup on an ISRG web site and via other marketing materials. Any communication delivered via Salesforce and your interactions with [Salesforce](https://www.salesforce.com/company/privacy/) are governed by their privacy policies. With your consent, we may occasionally use your email address to send personalized communications related to ISRG and its projects. You can withdraw this consent by opting out via the footer of our emails or emailing us at [press@abetterinternet.org](mailto:press@abetterinternet.org).
28
29If you register to use an ISRG community support forum, the personal information you provide and your actions there are governed by the privacy policy of our hosting and software provider for the forum, [Civilized Discourse Construction Kit](https://www.discourse.org/privacy). We do not collect or maintain personal information through our offering of this support forum.
30
31## We Do Not Sell Your Data or Information
32
33We do not sell your data or information. This includes Relying Party, Subscriber, and Visitor data and information.
34
35## Use of Third-Party Analytics and Email Marketing Tools
36
37To enhance our understanding of how our visitors engage with our websites and emails, and to improve our fundraising and marketing strategies, ISRG may from time to time deploy third-party web and email analytics tools, specifically Google Analytics for our websites and Salesforce Account Engagement for our marketing emails.
38
39- Google Analytics: This tool collects data on how visitors interact with our websites, including page visits, duration of page and site visits, and navigation paths. We use this information to analyze website performance and user engagement. We retain the data collected by Google Analytics as long as necessary for traffic analysis purposes. You can opt-out of Google Analytics for Display Advertising and customize Google Display Network ads using the Google Ads Settings page. Additionally, you can prevent your data from being collected by Google Analytics by downloading and installing the [Google Analytics Opt-out Browser Add-on](https://support.google.com/analytics/answer/181881). You can learn more about how Google uses data when you use our site by visiting [How Google uses information from sites or apps that use their services](https://www.google.com/policies/privacy/partners/).
40- Salesforce Account Engagement: For our marketing emails, Salesforce Account Engagement helps us understand recipient activities, such as email opens and clicks. We use this engagement data to evaluate the performance of our email campaigns and understand our audience's behavior. We retain engagement data for as long as we utilize Salesforce Account Engagement. You can opt-out of marketing communications from us at any time by using the unsubscribe link provided in our emails or by contacting us directly at [press@abetterinternet.org](mailto:press@abetterinternet.org).
41
42## Law Enforcement Requests and Extenuating Circumstances
43
44To the extent we possess it, we may disclose personally identifiable information about you to third parties in limited circumstances. Such circumstances include when we have your consent or when we have a good faith belief it is required by law, such as pursuant to a subpoena or other judicial or administrative order. We may also disclose account recovery information when we have a good faith belief it is necessary to prevent loss of life, personal injury, damage to property, or significant financial harm.
45
46If we are required by law to disclose the information that you have submitted, we will attempt to provide you with prior notice (unless we are prohibited, or it would be futile) that a request for your information has been made in order to give you an opportunity to object to the disclosure. We will attempt to provide this notice by whatever means is reasonably practical. If you do not challenge the disclosure request, we may be legally required to turn over your information.
47
48In addition, we reserve the right, solely at our discretion, to independently object to certain requests (for access to information about users of our products and technologies) that we believe to be improper.
49
50We process personal data as described in this policy. The purpose and lawful basis for information processing is as follows:
51
52**Purpose:** Providing Certificate Status Information
53
54**Lawful Basis:** Legitimate Interests
55
56**Additional Information:** We collect and process information from Relying Parties in order to reliably provide certificate status information.
57
58**Purpose:** Providing Certificate Issuance and Management Services
59
60**Lawful Basis:** Contract, Legitimate Interests
61
62**Additional Information:** We collect and process information from Subscribers in order to provide reliable and secure certificate issuance and management services, and to demonstrate to the public that our services perform as expected.
63
64**Purpose:** Providing Information to Visitors
65
66**Lawful Basis:** Consent, Legitimate Interests
67
68**Additional Information:** We collect and process information from Visitors in order to provide information via the Web and email in a reliable and efficient manner.
69
70**Purpose:** Processing Donations and Sponsorship Inquiries
71
72**Lawful Basis:** Legitimate Interests
73
74**Additional Information:** We collect and process information in order to process and support donations, fulfill donor benefits, and maintain the accuracy of our donor records.
75
76**Purpose:** Legal Obligations and Extenuating Circumstances
77
78**Lawful Basis:** Legal Obligation, Legitimate Interests
79
80**Additional Information:** We may collect and process information in order to comply with legal obligations and when we have a good faith belief it is necessary to prevent loss of life, personal injury, damage to property, or significant financial harm.
81
82Please note that we may be unable to delete information, including IP addresses, as this information is necessary for others to rely on in determining the trustworthiness of our certificates. In some cases, we may process personal data pursuant to legal obligation or to protect your vital interests or those of another person.
83
84Your personal data may be collected from or transferred to jurisdictions where we and our service providers store or process data, including the United States. These jurisdictions may not provide the same level of data protection as your jurisdiction, including the EEA. We have taken steps to ensure that our service providers provide an adequate level of protection for the personal data of EEA residents, including by entering into data processing agreements using the European Commission-approved Standard Contractual Clauses, or by using other safeguards approved by the European Commission. You have a right to obtain details of the mechanism under which your personal information is transferred outside the EU by emailing us at the contact information below.
85
86Individuals located in the European Economic Area (EEA) have certain rights in respect to their personal information, including the right to access, correct, or delete personal data we process through your use of our sites and services. If you're an individual who is a relying party, subscriber, or visitor based in the EEA, you can:
87
88- Request a personal data report by emailing us at [privacy@abetterinternet.org](mailto:privacy@abetterinternet.org). This report will include the personal data we have about you, provided to you in a structured, commonly used, and portable format. Please note that we may request additional information from you to verify your identity before we disclose any information.
89- Request that your information be corrected or deleted by contacting us at [privacy@abetterinternet.org](mailto:privacy@abetterinternet.org).
90- Object to us processing your information. You can ask us to stop using your information, including when we use your information to send you service emails. You may withdraw your consent to receive service emails at any time by clicking the "unsubscribe" link found within Let's Encrypt emails.
91- Complain to a regulator. If you're based in the EEA and think that we haven't complied with data protection laws, you have a right to lodge a complaint with your local supervisory authority.
92
93For more information, or to report a privacy issue, please contact: [privacy@abetterinternet.org](mailto:privacy@abetterinternet.org).