Nobody can see it until you decide otherwise. Publication is switched off by default on every account, and it stays off until you turn it on.
There are two separate ways to show somebody your record, and they work differently.
Publishing puts your record at your public profile address, where anyone who knows your username can read it.
Until you publish, a request for that address returns your name and nothing else. Not your score, not your band, not your outcomes.
Turning it off takes effect immediately. Links other people already hold stop showing your record straight away.
Unpublishing is never blocked, including on an account under moderation. Withdrawing your own data from public view is a right rather than a privilege, so there is no state your account can be in where that button stops working.
One detail worth knowing: an unpublished profile is not reported as "no such person". Saying the username is free would be untrue and would break links other people already hold. It says the record is not being shown.
A share link is separate from publishing. It is a single link you mint and hand to one person, and it works whether or not you have published your profile. It is created the first time you open the share section of your dashboard, and it only resolves for somebody holding the link.
You choose how much it shows: the full score, the band only, or a minimal view. Credentials you download take the same three choices.
You can rotate the link, which kills the current one and issues a fresh one, or revoke it entirely. Revoking withdraws the record and every credential issued from it, so any badge or link you embedded anywhere stops working.
A care coordinator applying for agency work can send a full-score link to one agency and revoke it after the interview. That is the intended use.
The score and band you chose to present, with the line explaining how it was worked out.
Your qualifications and projects, each one labeled verified or self-reported.
The measures over your confirmed outcomes.
A signed credential they can check for themselves without Credda being online.
Who confirmed anything. Not a name, not an email address, not an initial, not a company. What they see is the type of relationship and how many, never an identity. Neither the person nor the company page carries a field that names a confirmer, and there is no way to work one out from what is shown.
If nobody has confirmed anything yet, it says so plainly. It does not show a zero, because an unmeasured thing shown as zero reads as a bad result rather than a missing one.
Anything else about you. A share link shows the record. It is not a door into your account.
One thing that is not hidden, and is worth knowing before you publish: a published profile can list the agreements themselves, including the name you typed for the other side. That may be a person's name or a business's name, depending on what you entered. Their email address can never appear.
Every public read of your record carries the same boundary statement, at every scope. In short: it is not a consumer report and Credda is not a consumer reporting agency; it is not a background check and nothing has been screened against criminal, credit, identity or public records; it is not a hiring recommendation; and it is not a claim about anything you have not been reported doing, so a thin record means little was reported, not that little happened.
That last line exists for you. A recruiter reading a sparse record is told, on the page, not to read it as a record of failure.
A business cannot pull your record because they are curious about you. There is no way for a company you have no relationship with to request it, and there is no browsable directory of people by score. The link is the consent, and you mint it.
Credda also holds no consumer register, no no-show list and no blacklist of any kind.
You can see how many times your record was read. There is no list of who, and there will not be one. Credda stores a one-way daily code per viewer and nothing else, so a viewer cannot be identified, and the same person visiting on two days cannot be linked, even by Credda. That is a design decision, not a missing feature.
The web app asks search engines not to index a withdrawn record. That instruction currently comes from the page in the reader's browser and not from the server, and a published and an unpublished record share the same address shape, so the site cannot ask search engines to ignore that whole area.
So do not treat unpublishing as a guarantee that a page a search engine has already picked up will disappear. If something of yours is already showing in search results, unpublish first, then use that search engine's own removal process for the cached copy.
You can switch off the weekly summary about confirmations you are waiting on, in your email preferences. The job that sends it checks the setting, so it is enforcement rather than a courtesy.