SignSecure
Log inSign up

Privacy Policy

Last updated: 2026-07-07

SignSecure is operated by Baltic AI SIA(“we”, “us”). This policy explains what we collect when you use our website and mobile apps to sign documents and complete identity verification (KYC), and why.

What we collect

  • Account data — email address and password (stored as a salted hash, never in plain text).
  • Identity verification data — when you complete KYC, our verification processor Didit collects your government ID document and a live selfie/face scan to confirm you are who you say you are, and returns a verification decision to us. We store that decision and its supporting metadata, not raw copies of your ID images — those are held by Didit under its own privacy policy.
  • Documents you upload or sign — the files themselves, your signature, and an audit trail (who signed, when, from what IP) so signed documents remain verifiable.
  • Login and security data — IP address, user agent, and login timestamps, used to detect suspicious logins (which can trigger a live face-match recheck) and to secure your account.
  • Billing data — if you subscribe to a paid plan, payments are processed by Stripe; we store your plan tier and subscription status, not your card number.

Why we collect it

To provide the core service: verifying your identity before you sign or countersign a document, keeping a tamper-evident record of signatures, securing your account against takeover, and billing subscriptions. We do not sell your data or use it for advertising.

Who we share it with

Only the processors needed to run the service: Didit (identity verification), Stripe (payments), and our infrastructure/database providers. Each processes data under its own agreement with us and does not use it for its own purposes.

Retention

We retain account, verification-decision, and signed-document records for as long as your account is active and as needed to keep the audit trail of any document you signed legally meaningful. You can request deletion of your account data at any time, subject to records we're required to keep for fraud prevention or legal compliance.

Your rights

As a company established in the EU (Latvia), we handle personal data under the GDPR. You can request access to, correction of, or deletion of your data, or object to its processing, by contacting us below.

Contact

Questions about this policy or your data: kyc@baltic-ai.xyz