Privacy Policy
Effective Date: July 20, 2026 • Applicable to ViViD eSigner (esign.vividapp.in)
Our Privacy Commitment
At ViViD eSigner (a product of ViViD App Studio), your privacy and cryptographic document security are our core principles. We do not sell your personal data, nor do we access the contents of your signed documents for advertising purposes. This policy explains what information we collect, how it is encrypted, stored, processed, and protected.
1. Information We Collect
We collect minimal data necessary to issue digital certificates and sign PDF documents:
- Account Details: Your name, email address, and profile picture collected via Google Authentication.
- Digital Identity Metadata: X.509 certificate fields you create or import, including Common Name (CN), Email, Organization (O), Organizational Unit (OU), Country, and Certificate Fingerprints (SHA-256).
- Uploaded & Signed PDF Documents: PDF document binaries uploaded for signing, visual signature box coordinates, reason, location, and final signed PDF output files.
- Audit Log & Technical Telemetry: Network headers, session timestamps, and sequence numbers recorded during file upload, signing, or public verification.
2. Cryptographic Private Key Safety
We enforce strict boundary separation depending on your signing method:
- In-App Digital ID (.p12): Private keys generated or imported in-browser are encrypted with your chosen passphrase and uploaded to secure, isolated object storage (
users/{uid}/certs/). The raw unencrypted private key is never written to public logs. - Apple Keychain & Touch ID Bridge: If you use our macOS Keychain Extension, your private key never leaves your local Mac. Signing is performed locally via macOS Security Framework after biometric Touch ID approval; our server receives only the mathematical digest signature to attach to the PDF.
3. How We Use Your Information
Your data is processed strictly for the following functional purposes:
- To embed verifiable PAdES digital signatures, visual signature stamps, and clickable verification link annotations into your PDF documents.
- To power the public verification portal (
esign.vividapp.in/verify) allowing recipients to check PDF hash matches and identity details. - To maintain immutable audit trails (upload, sign, verify events) for legal non-repudiation.
- To enforce per-IP rate limits using secure edge memory to prevent API scraping or Denial of Service (DoS) attacks.
4. Data Storage & Infrastructure Security
ViViD eSigner leverages enterprise-grade serverless edge architecture:
- Secure Edge Compute & Object Storage: All files and API routines run on a global secure edge network with TLS 1.3 encryption in transit and AES-256 at rest.
- Distributed Relational Database: Metadata and audit logs are isolated per account with strict foreign-key integrity.
- Google Identity Authentication: User authentication tokens are validated on every protected API call using OAuth 2.0 / RSA public keys.
5. Data Retention & User Deletion Rights
You maintain complete control over your stored assets:
- You can delete any Digital ID or Document from your Dashboard at any time.
- Deleting a Digital ID permanently removes the corresponding
.p12certificate binary file from secure object storage and purges database records. - Public verification data remains tied only to the SHA-256 document hash of signed files to preserve recipient verification integrity.
6. Contact & Privacy Inquiries
If you have any questions regarding this Privacy Policy or wish to exercise data rights, please contact our privacy team at:
Publisher: ViViD App Studio
Website: https://esign.vividapp.in