Privacy Policy
Last updated: September 9, 2026
SignetKeys is operated by PersonixHealth, Inc. (Delaware, USA). We run a code-signing service for software developers; we are not in the data business. This page says plainly what we collect, why, and who touches it.
What we collect
- Account data — your email address, workspace name, and team membership. Sign-in is passwordless: we store only hashed one-time login tokens, never passwords.
- Billing state — your plan and subscription status, plus Paddle's identifiers for your subscription. Payment itself is handled entirely by Paddle, our merchant of record: we never see or store your card details.
- Artifacts you submit — the software your CI sends for signing (or that you upload to the free diagnostic). Artifacts are processed for the job and delivery, then deleted from working storage; they are not mined, profiled, or shared beyond the processing described below. For the free diagnostic specifically: the uploaded file is deleted the moment analysis finishes (whether it passes, fails, or errors), with a storage-level expiry rule as backstop; the resulting report and its random job id are kept for 30 days so your link works, then deleted; and if you optionally leave an email address, it is used once to send you the report link and then removed. Uploaded binaries are never executed. We retain de-identified aggregate statistics about diagnostic outcomes (artifact type, size range, and which failure types occurred, and never a filename, job id, email, or anything else that could identify you or your software) to understand and publish failure-trend information. Your report is reachable only by its unguessable link: anyone you share that link with can view the report during its 30-day life, so treat the link as you would the report itself.
- Signing evidence — cryptographic hashes of inputs and outputs, commit identifiers, workflow actor names, certificate serials, and notarization IDs. This tamper-evident log is a core feature of the product and is retained so your history stays verifiable.
- Operational logs — standard service logs (requests, errors) kept for security and debugging.
What we use it for
Providing the service, sending transactional email (sign-in links, enrollment and billing notices), support, and security. We do not sell personal data, run advertising, or share data with anyone except the processors below.
Who processes data on our behalf
- Paddle — payments, tax, and invoicing (merchant of record; your payment details go to Paddle, not us)
- Railway — application and database hosting
- Cloudflare — DNS and artifact storage
- Resend — transactional email delivery
- Apple — artifacts you sign are submitted to Apple's notarization service as an inherent part of the product
Retention
Account data is kept while your account exists. Submitted artifacts are transient. The signing-evidence log is retained long-term because verifiable history is the product — it contains hashes and metadata, not your software. If you cancel, your evidence log remains readable to you.
Your rights
Email support@signetkeys.com to access, export, correct, or delete your personal data. We honor deletion requests fully, noting that entries in the tamper-evident evidence log may be retained where integrity or legal obligations require — those entries identify artifacts by hash, not people.
Security
Our security model — hardware key custody, zero secrets in your CI, and what we can prove about every artifact — is described in detail at signetkeys.com/security. Report security issues to security@signetkeys.com.
Changes and contact
Material changes to this policy will be announced to your account email. Contact: support@signetkeys.com · PersonixHealth, Inc., Delaware, USA.