SignetKeys

Privacy Policy

Last updated: September 9, 2026

SignetKeys is operated by PersonixHealth, Inc. (Delaware, USA). We run a code-signing service for software developers; we are not in the data business. This page says plainly what we collect, why, and who touches it.

What we collect

What we use it for

Providing the service, sending transactional email (sign-in links, enrollment and billing notices), support, and security. We do not sell personal data, run advertising, or share data with anyone except the processors below.

Who processes data on our behalf

Retention

Account data is kept while your account exists. Submitted artifacts are transient. The signing-evidence log is retained long-term because verifiable history is the product — it contains hashes and metadata, not your software. If you cancel, your evidence log remains readable to you.

Your rights

Email support@signetkeys.com to access, export, correct, or delete your personal data. We honor deletion requests fully, noting that entries in the tamper-evident evidence log may be retained where integrity or legal obligations require — those entries identify artifacts by hash, not people.

Security

Our security model — hardware key custody, zero secrets in your CI, and what we can prove about every artifact — is described in detail at signetkeys.com/security. Report security issues to security@signetkeys.com.

Changes and contact

Material changes to this policy will be announced to your account email. Contact: support@signetkeys.com · PersonixHealth, Inc., Delaware, USA.