Privacy notice

Version 1.0. Last updated 2 October 2026. This notice covers the website at meatproxycertification.org. The hostnames meatproxycertification.com, www.meatproxycertification.com, www.meatproxycertification.org, meatproxycertification.net, www.meatproxycertification.net only redirect to it and serve nothing of their own.

Compliance note

This site is satire. The certificate is a joke and is not a real credential. This notice, however, is not a joke: it describes literally what the site collects, which is very little, and what happens to it.

The short version

Who is responsible

The data controller is TyDData LLC, 3710 Del Prado Blvd South #174, Cape Coral, FL 33904, United States, United States. "The Guild of Tenured Meat Proxies" is a fictional body and not a legal person. For anything about your data, write to [email protected]. The imprint has the other contact addresses. We have not appointed a data protection officer; on our reading of the law, the small scale of this processing does not require one.

What the site stores in your browser

The site sets no cookies and uses no localStorage or IndexedDB. It uses sessionStorage, which your browser clears when the tab closes, for four things only: your exam progress, your accessibility settings for the exam (hiding the clock, one approval per key press), the name you typed for the certificate, and the email address you typed into the email form. These stay on your device. This is the "strictly necessary" category that needs no consent, and the site does nothing else with storage.

Every page loads only from meatproxycertification.org. There are no web fonts, no embedded videos and no third-party scripts, with the single exception of Turnstile described below.

The exam and the certificate

The exam makes no network requests. When you pass and type a name, the browser builds a certificate link of the form /verify/<track>/#<data>. Everything after the # (the name, the track, the date and your exam statistics) stays in the browser: it is not sent to any server, does not appear in any request log, and is not seen by us. If you share the link, whoever you share it with can see the name in it. That is your choice to make.

Because anyone can create such a link with any name, the certificate page checks the name against a small, public block list of hashes (not names) and refuses to render a match. If someone has put your name on a certificate without your permission, write to [email protected] and we will add it.

The optional certificate email

On the certificate page you can ask for the certificate by email. This is optional. The form asks for an email address and for two confirmations: that you are 18 or older, and that you have read the Terms and understand the certificate is satire. If the mailing list is switched on, a third, separate, unticked box offers Guild news (see Mailing list).

When you submit the form, your browser sends us the certificate data (the name, the track, the date and the statistics), the email address, your two confirmations and a Turnstile token. Our code checks the data, rebuilds the certificate text and the PDF on the server from those fields, and sends one message. The message contains the certificate text and the name, the certificate link, a line saying that the name was typed by whoever requested the email, the parody notice, our legal name and postal address, the abuse address and a link that blocks all further mail. It contains no images, no tracking pixel and no click tracking.

Limits. We send at most 90 certificate emails a day and 2900 a month, in total, and at most one per exam track to any address in any 30 days. When the daily or monthly allowance is used up, the page tells you immediately and nothing about your request is stored. We do not queue addresses.

What we keep. The plain address and the name exist in our server's memory only for the duration of the request. We do not log request bodies, addresses or names. What remains in our database is listed in How long we keep things: a keyed hash of the address (not the address) with the track and the time of sending, for 30 days; two counters with no personal data in them; and, only if you ask for it, a block-list entry or a mailing-list record.

The keyed hash. Before hashing, the address is lower-cased, anything from a + onwards in the local part is removed, and for Gmail addresses dots in the local part are removed, so that trivial variants count as the same address. The result is run through HMAC-SHA256 with a secret key held only on our server. The hash cannot be turned back into the address, but because it identifies an address for anyone holding the key, we treat it as personal data. Mail is sent to the address exactly as you typed it.

What the email provider keeps. We send through Resend (Plus Five Five, Inc., San Francisco, United States). Resend necessarily receives the address as typed, the message content, including the name on the certificate and the PDF if one is attached, and the delivery result. Resend keeps email content and delivery logs for 30 days on the plan we use; this period is fixed by Resend and cannot be shortened in its settings (checked 2 October 2026). Resend also keeps its own suppression list of addresses that bounced or complained, which it uses to stop further sending. Resend stores this data in the United States.

Bounces and complaints. If a message bounces or the recipient reports it as spam, Resend tells our server, which adds the keyed hash of the address to our block list with the reason "bounce" or "complaint" so that we do not send to it again.

If someone else enters your address. Anyone can type any address. If you receive a certificate email you did not ask for, it is because someone entered your address on our site. The message says so, names us, and carries a link to a page where you can block all mail from us. Our basis for the one-off delivery in that case is our legitimate interest in delivering a message that was requested, balanced by the fact that it is a single message with an immediate and permanent opt-out.

Cloudflare Turnstile

To stop bots from burning through the daily email allowance, the email form is protected by Cloudflare Turnstile. The Turnstile script is not loaded when a page opens. It is loaded only when you press the control that opens the email form, and the control carries a notice saying so. Until then, nothing on this site contacts Cloudflare's challenge service.

Once loaded, Turnstile runs a check in your browser and talks to challenges.cloudflare.com. According to Cloudflare's Turnstile Privacy Addendum (last updated 18 June 2025), the signals it collects are your "client IP address, TLS Fingerprint, User-Agent Header and Sitekey and associated origin", together with browser characteristics it uses to tell people from bots. Cloudflare processes these signals on our behalf, as our processor, to decide whether to issue a token. Cloudflare states that it is also an independent data controller of those signals where it uses them "to improve Turnstile's bot detection capabilities"; for that use, Cloudflare's own privacy policy applies, not ours, and we cannot access or delete that data. We never see the raw signals; our server receives only the token and asks Cloudflare whether it is valid.

Cookies and storage set by Turnstile. The site's own code sets none. Cloudflare's challenge platform may set its own cookies inside the Turnstile frame on challenges.cloudflare.com; Cloudflare's cookie reference names cf_chl_rc_i, cf_chl_rc_ni and cf_chl_rc_m for the challenge platform's internal diagnostics, and _cfuvid where a rate-limiting rule needs to tell apart users who share an address. The table below lists exactly what was observed in a clean browser profile when the form was opened on this site.

Cookies and storage observed when the email form is opened (PENDING INTEGRATION PASS: this table is completed from a clean-profile recording before launch; see LAUNCH-CHECKLIST.md)
NameSet onTypePurposeLifetime
(none)meatproxycertification.orgcookie / storageNone expected: the site sets no cookies and Turnstile's token is passed to our server in the form submission, not stored.n/a
(to be recorded)challenges.cloudflare.comcookieChallenge-platform diagnostics (per Cloudflare's cookie reference)(to be recorded)

If you do not want to load Turnstile, do not open the email form. The certificate, the print-out and the PDF do not need it.

Mailing list

The mailing list has three possible settings: off (the box does not appear and nothing is stored), double-opt-in and single-opt-in. It is currently set to single-opt-in.

When it is on, the email form shows one more checkbox, unticked, with exactly this wording (consent text version 1), which is stored with your record so we can show later what you agreed to:

Email me occasional news from the Guild of Tenured Meat Proxies, a parody site run by TyDData LLC: new exam tracks and site announcements, a few times a year at most. No third-party advertising. Unsubscribe any time from any email or at [email protected].

The record holds the address as typed, its keyed hash, the consent text version, the consent text itself, the time you consented and the time you confirmed. No IP address. It is kept until you unsubscribe, or for 24 months after confirmation if we have sent no newsletter in that time, whichever is sooner. No newsletter has been sent at the date of this notice. Any future use of the list for anything beyond what the consent text says, including any promotional use, would need a new consent text version and fresh consent; we will not reuse this consent for that. Every newsletter will carry our postal address and an unsubscribe link, and unsubscribes are honoured promptly and at the latest within ten business days.

You can withdraw consent at any time from the link in any email we send or by writing to [email protected]. Withdrawing does not affect the lawfulness of anything done before.

Purposes and lawful bases

Where the EU or UK GDPR applies, the bases below correspond to Article 6(1)(b) (performance of a contract, or steps taken at your request), Article 6(1)(f) (legitimate interests) and Article 6(1)(a) (consent). We have weighed each legitimate interest against your interests; the balancing points are noted in the table.

Purposes and lawful bases
PurposeBasis
Sending the certificate email you asked forPerformance of your request. Where the address belongs to someone else, our legitimate interest in delivering a requested one-off message, balanced by the block link in it
Keeping a keyed hash of the address for 30 days to limit repeat sendsLegitimate interest in preventing abuse of the email feature
Keeping a keyed hash on the block listLegitimate interest in, and obligation to honour, your objection
Turnstile, Cloudflare request logs, and rate limitingLegitimate interest in security
Bounce and complaint notices from the email providerLegitimate interest in not mailing dead or unwilling addresses
Mailing listConsent, withdrawable at any time
Messages you send to our contact addressesLegitimate interest in answering you

The address itself is not kept by us unless you join the list; a keyed hash of it is, as described above. Consent records for subscribers hold the timestamp, the version and the exact checkbox wording. No IP address is stored by our application for any purpose.

How long we keep things

Data in our own database (Cloudflare D1)
RecordContainsKept for
Send recordKeyed hash of the address, exam track, time of sending30 days, then deleted automatically
Send countersA count per day and per month; no personal data60 days
Block listKeyed hash, reason (blocked, bounce, complaint, or unsubscribed), timeUntil you ask us to erase it, or until we shut the email feature down. It is kept so that the block keeps working
Mailing-list recordAddress, keyed hash, consent version, consent text, consent and confirmation timesUntil you unsubscribe, or 24 months after confirmation if no newsletter has been sent
Kill switchWhether email sending is on; no personal dataIndefinitely

Expired send records and counters are deleted automatically by the server as it handles later requests, and in any case are never used once they have expired.

Data held by our processors
ProcessorHoldsKept for
ResendRecipient address, message content including the name and any PDF, delivery events; its own bounce and complaint suppression list30 days for content and logs (fixed by Resend on our plan); suppression entries until removed; everything deleted within 90 days of us closing the account
CloudflareRequest logs (IP address, request details) for every visit, as for any site it hosts; Turnstile signals when you open the email form; the database above; DNS queries from resolvers for our hostnamesThe periods in Cloudflare's privacy policy. On our plan we have no access to per-request logs and store no IP addresses ourselves
Proton MailMessages you send to our contact addresses, and our repliesWe delete correspondence 12 months after the matter is closed, except what is needed to keep a block in place or to show that a request was handled, which is kept as long as the block

Processors and international transfers

We are in the United States, so everything we hold is processed there. We use three service providers, all acting on our instructions as processors except where stated. The transfer mechanism named for each is taken from that provider's own current data processing agreement.

Cloudflare, Inc. (San Francisco, United States)
Hosts the site, serves DNS, runs the small API and database behind the email feature, provides Turnstile and applies rate limiting. Cloudflare operates a global network; data may be processed in the United States and elsewhere. Under the Cloudflare Data Processing Addendum (version 6.4, effective 3 April 2026), transfers from the EU are made under the EU Standard Contractual Clauses (Module Two, controller to processor), transfers from the UK under those clauses with the UK International Data Transfer Addendum, and transfers from Switzerland under the clauses as adapted for Swiss law; Cloudflare also states that it complies with the EU-US Data Privacy Framework, under which such transfers are not restricted. For Turnstile, Cloudflare is additionally an independent controller for improving its bot detection, as described under Cloudflare Turnstile; see its Turnstile Privacy Addendum and privacy policy (effective 4 November 2025). Cloudflare's privacy policy states no fixed retention period for the request logs it keeps as a host; we have no access to them on our plan.
Resend (Plus Five Five, Inc., San Francisco, United States)
Sends the certificate email. Stores customer data in the United States. Under the Resend Data Processing Addendum (last updated 31 December 2025), transfers from the EU are made under the EU Standard Contractual Clauses (Modules One, Two and Three as applicable), from the UK under the UK Addendum, and from Switzerland under the clauses as modified for the Swiss Federal Act on Data Protection; Resend also participates in the EU-US Data Privacy Framework and its UK Extension. Retention: 30 days, as described above.
Proton AG (Plan-les-Ouates, Switzerland)
Hosts the mailbox behind hello@, privacy@, abuse@ and [email protected]. Proton is in Switzerland, which the EU and the UK recognise as providing adequate protection, so mail reaching that mailbox from the EU or UK involves no restricted transfer. Where Proton itself transfers data outside such jurisdictions, its Data Processing Agreement (last updated 10 February 2026) relies on "Switzerland- and/or EU- and/or UK- approved and then-current standard contractual clauses". We read the mailbox from the United States.

We do not use any other processor, and we do not transfer your data to anyone else, except where the law requires us to.

Your rights

Depending on where you live, you have the right to:

How to exercise them. The quickest route is the self-serve page linked from every email we send, which offers three actions: stop Guild news, never email this address again, or delete every record we hold for the address (including any block, which means the address could be emailed again if someone enters it). For anything else, write to [email protected]. We answer within one month. There is no charge.

What we can and cannot find. Our records are keyed by a hash of the address. To find them we need either the address itself or a link from one of our emails. If you cannot give us either, we cannot identify any records as yours, and we will tell you so. When you ask us to block an address, we keep the keyed hash on the block list so that the block keeps working; we remove it on request, with the warning above. We will also ask Resend to delete any message to you that is still within its 30-day window and to remove you from its suppression list if you ask.

UK visitors. If you think we have not handled your data as the UK GDPR requires, you can complain to us directly at [email protected]. We acknowledge every complaint within 30 days of receiving it, look into it without undue delay, and tell you the outcome. You can complain to the Information Commissioner's Office at any time, before or after complaining to us.

Children

This site is for adults. The email feature requires you to declare that you are 18 or older; we do not ask for a date of birth and we do not knowingly collect any data from anyone under 18. If you believe a child has given us an email address, write to [email protected] and we will delete it.

No selling, no advertising

We do not sell personal data, share it for advertising or cross-context behavioural advertising, or use it for profiling. There is no advertising on the site and no third-party advertising in any email.

Security

The site is served only over HTTPS with a strict content security policy. There are no user accounts and no sessions. Addresses are hashed with a keyed hash whose key is held as a server secret. We do not log request bodies, addresses or names. The email feature can be switched off in seconds, and the whole database can be deleted, without redeploying the site. If a breach affected your data we would tell the competent authority and, where the risk to you is high, you, as the law requires.

Changes to this notice

We will change this notice when the site changes. Each version carries a number and a date at the top; the current version is 1.0 of 2 October 2026. A change that adds a purpose for which we use the mailing list will require fresh consent, not merely a new version of this page.