Privacy Policy
Last updated: August 6, 2026
PDF SignCheck is built from the ground up as a privacy-first utility. We do not save, store, sell, or analyze your uploaded PDF documents or camera scans. All cryptographic calculations and barcode/QR scans occur strictly in volatile system memory or locally on your device, and are immediately discarded. The one exception is our optional Tamper-Proof PDF feature: when you choose to seal a document, we store a one-way cryptographic fingerprint of it (never the file itself) together with the details you enter, so its integrity can be verified later. Full details are in Section 1 below.
1. What information do we collect?
To provide you with our secure digital certificate checking tools, we collect the minimum necessary data:
- Uploaded & Password-Protected Files (Zero Retention): When you upload a PDF document for signature validation or barcode extraction, the file is temporarily loaded in-memory on our secure servers, programmatically inspected, and immediately discarded after returning the results. For password-protected documents (such as encrypted government IDs), you may enter the document password which is securely processed in-memory solely to enable local decryption and barcode extraction; neither your password nor the decrypted document bytes are ever written to persistent disk or storage.
- Camera & Scan Data (Zero Retention): When you use the mobile application's camera scanner to read QR codes or barcodes from physical documents, the camera feed and capture processing are executed entirely offline and locally on your mobile device using native machine learning. No video feeds, images, or document contents from your camera are ever transmitted, uploaded, or stored on external servers or APIs.
- Tamper-Proof PDF Records (Opt-in): When you use the optional Tamper-Proof feature to seal a document, we generate and store a cryptographic fingerprint of the sealed file — one-way SHA-256 hashes of the whole document and of each page, plus short extracted text snippets that are used only to describe what changed if the document is later edited — together with the identity details you choose to attach (name, email, and phone). We never store the PDF file itself. This information exists solely so that you, or anyone you share the document with, can later verify inside the app whether the document has been altered and who sealed it. The QR code placed on the document contains only an opaque, randomly generated identifier; your personal details are never encoded into the QR code and are disclosed only through an authenticated in-app verification. You may request deletion of these records at any time (see Section 7).
- Account Information: If you register or authenticate an account (including Google OAuth sign-in), we store your email address, name (if provided), and account credentials. This authentication is managed securely in partnership with Neon Auth.
- Payment Data: Payment processing is handled entirely by Dodo Payments. We do not store or process your credit card numbers, billing addresses, or specific payment credentials on our systems.
2. How do we use your information?
We use collected information solely to support the active features of PDF SignCheck:
- To inspect and stamp cryptographic validity badges on your requested PDF files in real-time.
- To track daily rate limits associated with your account tier and top-up credits.
- To send transaction receipts, password reset links, and critical security update notices.
3. Do we use cookies and analytics?
We use secure, standard HTTP-only cookies to handle user authentication state sessions. These cookies do not track your activity across external web spaces.
4. What third-party integrations do we use?
We partner with select trusted services to deliver the platform infrastructure:
- Neon Auth: Provides passwordless login, database encryption, and security credentials management.
- Google Cloud Platform: Facilitates Google Account OAuth logins to save you from typing passwords.
- Dodo Payments: Handles PCI-compliant billing pipelines and invoice receipts securely.
- Google AdSense & DoubleClick DFP: Serves contextual and personalized advertisements on our website.
- Google AdMob: Serves advertisements within our mobile applications using advertising identifiers.
5. Google AdSense & DoubleClick Cookie Policy (Web & Mobile Ads)
PDF SignCheck uses Google AdSense and Google AdMob to serve advertisements across our web and mobile services. Please review our third-party advertising disclosures below:
- Third-party vendors, including Google, use cookies and/or device identifiers to serve ads based on a user's prior visits to our website or other websites on the Internet.
- Google's use of advertising cookies (such as the DoubleClick DFP cookie) enables it and its partners to serve targeted ads to our users based on their visit to PDF SignCheck and/or other sites across the web.
- Users may opt out of personalized advertising by visiting Google Ads Settings (or by visiting aboutads.info for non-Google third-party vendor cookies).
- On mobile devices, users may reset or limit advertising identifiers (GAID/IDFA) via device settings (e.g., Settings > Privacy > Ads).
- For more detailed information on how Google collects and processes data when you use our website, please visit How Google uses information from sites or apps that use our services.
6. How is data retention and security handled?
We apply modern industry-standard transport level encryption (SSL/TLS) for all data transfers. File inspection blocks run inside isolated server environments with no persistent storage volumes attached. Account records and Tamper-Proof PDF fingerprint records are kept securely until you request their deletion.
7. How can you contact us regarding privacy?
For questions regarding this policy, to request account deletion, or to submit feedback, contact us at: hi@pdfsigncheck.com