HiSign Privacy Policy

Effective date: April 23, 2026

Last updated: May 10, 2026

Version: 1.1

Applies to: HiSign for iOS and HiSign for Android.

HiSign is published by Insight Velocity LLC. Questions about this policy can be sent to privacy@insightvelocity.io.

1. The short version

The rest of this document spells out exactly what that means.

2. Information HiSign does not collect

HiSign does not collect, transmit, or have access to any of the following:

There are no analytics SDKs, no ad SDKs, no attribution SDKs, and no third‑party tracking libraries embedded in HiSign.

3. Information that stays on your device

The following data is created or entered by you and is stored only on your device, in an encrypted local database:

How that data is protected

4. Biometrics

HiSign uses biometric authentication (Face ID, Touch ID on iOS; fingerprint or face unlock on Android) solely to unlock the encryption key that protects your local data.

5. Peer‑to‑peer contact exchange

Adding a contact in HiSign happens directly between two phones:

In every case, the payload travels only between the two devices involved. Insight Velocity does not operate, route, or relay any contact‑exchange traffic, and does not receive a copy of the exchange. Live‑exchange payloads are short‑lived, and every payload is signed with the sender's identity key so the receiver can verify it has not been tampered with.

6. Network activity

HiSign is built to function fully offline. The only network request the app may make is a periodic clock‑integrity check against an authoritative public time service, used to detect a tampered or badly skewed device clock that could otherwise weaken the rotating verification phrase. This check uses the standard Network Time Protocol; only the timestamp fields the protocol defines are sent and received, and no account is involved.

That request:

There is no other network traffic. There is no HiSign‑operated server to talk to.

7. In‑app purchases

HiSign may offer an optional one‑time purchase. Whether you make this purchase has no effect on what data HiSign collects, how it is processed, or where it is stored — there is no extra data collection associated with making, restoring, or declining the purchase. The purchase is:

HiSign never receives, stores, or transmits your card number, bank information, billing address, Apple ID, or Google account email.

8. Home‑screen widgets

HiSign offers optional home‑screen widgets that surface a small subset of your local contact data (such as the names you have chosen to pin) for quick access. Widget content is rendered by the operating system from data already stored on your device and is visible according to your device's lock‑screen and home‑screen privacy settings. No widget data is transmitted off the device.

9. Optional diagnostic log sharing

If you choose to use the in‑app Report an issue option, HiSign will offer to attach a diagnostic log file. That file contains only event timestamps and high‑level event names (for example, "app launched", "biometric prompt shown", "NFC exchange started") and is composed entirely on your device at the moment you request it. It does not contain your contacts, your phone numbers or email addresses, your verification phrases, your cryptographic keys, or the contents of any exchange. You choose where the file is sent — HiSign does not transmit it.

10. Permissions used by the app

The app only requests the permissions it needs to function. The exact wording of each request is shown by the operating system when the permission is first needed. At a high level:

HiSign does not request location, your operating‑system contact list, microphone, photos, calendar, SMS, phone state, "query all packages", or any other sensitive permission.

11. Children

HiSign is a general‑purpose utility and is not directed at children under 13 (or the equivalent age in your jurisdiction). Because HiSign collects no data on a server, we cannot determine the age of any user. A parent or guardian who believes a child has been using HiSign on a device they manage can clear all of the app's data using the in‑app Delete all data option, which immediately and irreversibly wipes the local encrypted database and key material.

12. Your rights and choices

Because all data is on your device:

HiSign has no servers, so there is nothing for us to delete or hand back on your behalf — your control over the data is your control over your device.

European users (GDPR), UK users (UK GDPR), California users (CCPA/CPRA), and users in other jurisdictions with similar laws have the rights granted by those laws. For the categories above, the practical answer is the same in every jurisdiction: HiSign does not collect personal data on a server, does not "sell" or "share" personal data, and does not engage in cross‑context behavioural advertising. The lawful basis under GDPR Art. 6(1)(b) is "performance of a contract with the user" — i.e. running the app you installed.

13. Data breach

There is no central HiSign database to breach. If your device itself is lost, stolen, or compromised, your HiSign data remains protected by the on‑device encryption and the biometric/passcode gate described in §3. If we ever discover and confirm a vulnerability that could materially weaken that protection, we will publish details and mitigation guidance through an in‑app notice and through the support contact below.

14. Changes to this policy

If we change this policy:

We will not retroactively reduce the privacy protections described here without notifying you in‑app first.

15. Change log

16. Contact

Insight Velocity LLC
Privacy contact: privacy@insightvelocity.io
General support: support@insightvelocity.io

We aim to respond to privacy inquiries within 30 days.