Go to main content
Certyneo

Certyneo Chrome extension privacy policy

Last updated: 13 September 2026

This policy describes the data processed by the "Certyneo — PDF Sign & Verify" extension for Google Chrome. It supplements the privacy policy of the Certyneo service, which applies to the documents and data in your account.

1. Data controller

The data controller is Certyneo, 14 rue Beffroy, 92200 Neuilly-sur-Seine, France. Contact: privacy@certyneo.com. Data protection officer: dpo@certyneo.com.

2. What stays in your browser

When you verify a document, the PDF is read and analyzed by the extension on your device: structure, signatures, certificates and timestamps. Its content is not transmitted. The extension does not read the web pages you visit, does not access your history and does not inject any script into websites.

3. Data sent to Certyneo

The extension communicates only with certyneo.com. It sends: the SHA-256 fingerprint of a file you verify; the PDFs you choose to sign, send for signature, analyze or save to your vault; the names and email addresses of the signers you enter; the text of a contract you paste for analysis; anonymous usage statistics. When you act on a PDF link, the extension downloads that file from its original website to process it.

4. Purposes

This data is used only to provide the features you request: verifying a document, creating a signature or a signature request, analyzing a contract, keeping a document in your vault, and measuring the extension's usage to improve it. It is not sold, not used for advertising and not used to determine creditworthiness.

5. Signing in to your account

You sign in on certyneo.com using OAuth 2.0 with PKCE: the extension never receives your password. It keeps in the browser an access token valid for 1 hour, in session memory, and a refresh token valid for 60 days. Signing out from the extension revokes these tokens on our servers.

6. Usage statistics

The extension sends anonymous events, such as "extension opened" or "verification completed", together with the feature name and the version number. No identifier, file name, web address or email address is sent. These events are aggregated in our audience measurement tool.

7. Recipients and processors

Transmitted data is processed by Certyneo and by the Certyneo service's processors listed on the dedicated page, under the terms of the service's privacy policy. Contract analysis relies on an artificial intelligence provider acting as a processor.

8. Retention

Documents, signatures and vault deposits follow the retention periods of your Certyneo account. The text or PDF submitted for contract analysis is not kept after the response: only the volume processed and a technical fingerprint of the request are logged for cost tracking. Fingerprints sent for verification are not recorded. Expired sign-in tokens are deleted every day.

9. Deletion

Signing out erases the extension's tokens and revokes them. Uninstalling the extension deletes all the data it keeps in the browser. Deleting your Certyneo account revokes every connection of the extension.

10. Security and rights

Exchanges are encrypted (HTTPS). The extension runs no remote code and contains no secret key. You have the rights of access, rectification, erasure, restriction, objection and portability: write to privacy@certyneo.com. You may also lodge a complaint with the CNIL.

11. Chrome Web Store policies

The use of information received by the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Any change to this policy will be published on this page with its update date.

See also: Certyneo service privacy policy · List of processors