Last Updated: February 24, 2026
Bit-Sign is a privacy-first platform. We minimize data collection to only what is necessary to operate the signing and identity verification service. We do not sell, rent, or share your personal data with third parties for marketing purposes.
We would rather state this plainly than let an encryption badge imply otherwise.
We are rebuilding this so that key custody sits with you and your organisation and we hold only ciphertext. Until that ships, please treat Bit-Sign as a service you trust rather than one that is technically unable to read your data.
When you use Bit-Sign, we collect and process the following:
Bit-Sign integrates with the following identity providers via OAuth 2.0:
We only request the minimum scopes required (basic profile and email). We store OAuth tokens securely to maintain your linked status. You may unlink any provider at any time, which removes the stored token and associated profile data.
User data is stored in a self-hosted database. Document content is processed in the browser where possible. Encrypted attestations and identity inscriptions are written to the Bitcoin blockchain and are permanent.
Data inscribed on the Bitcoin blockchain is permanent and immutable. This includes identity roots, identity strands, document seals, and attestation records. Once inscribed, neither Bit-Sign nor any party can delete or modify these records. You should consider this carefully before sealing or inscribing any data.
We use essential, secure, HTTP-only cookies to maintain your authentication session. No tracking, analytics, or marketing cookies are used. No third-party cookie services are integrated.
Off-chain data (vault items, profile information, OAuth tokens) may be deleted upon request. On-chain data (inscriptions, seals, identity strands) cannot be deleted due to the immutable nature of the blockchain. To request deletion of your off-chain data, contact us at the address below.
For privacy inquiries, contact: bitsignonline@gmail.com