FIPSign
Privacy Policy

Effective date: May 18, 2026  ·  Last updated: July 26, 2026
Operated by an independent developer based in Argentina.

1. Who we are

FIPSign (fipsign.dev) is a post-quantum signing service operated by an independent developer based in Argentina. References to "we", "us", or "FIPSign" in this policy refer to that individual operator.

For any privacy-related inquiries, contact us at [email protected].

2. What data we collect

We collect the minimum data necessary to operate each product:

We do not collect names, phone numbers, payment card numbers, physical addresses, or the content of payloads signed through PQ-Sign.

Your signed payloads are not stored. When you call /sign, the payload is signed and returned to you. We do not retain the content of what you sign.
3. How we use your data

Your email address is used exclusively for:

We do not use your data for advertising, profiling, or any purpose beyond operating and improving the FIPSign service.

4. Third-party service providers

We use the following third-party services to operate FIPSign. Each acts as a data processor under our instruction:

We do not sell, rent, or share your personal data with any third party for their own purposes.

5. Data retention

We retain your email address and account data for as long as your account is active. If you request account deletion, we will remove your email address and associated account data within 30 days.

Usage logs (token consumption records for PQ-Sign) may be retained for up to 12 months for billing and audit purposes, after which they are deleted.

Connection logs (PQ-Proxy Cloud and On-Premise) are retained for the period configured at installation (default 30 days for On-Premise) or as required for service operation, after which they are deleted.

Heartbeat records (PQ-Proxy On-Premise) — IP address and version — are retained for as long as the license is active. Records not updated in 90 days are automatically purged.

Trial and purchase records (email, company name, IP address) are retained for 12 months for fraud prevention and license audit purposes.

OTP codes are automatically expired and deleted after 10 minutes.

6. Your rights

Under Argentine Law 25.326 (Personal Data Protection) and, where applicable, the GDPR, you have the right to:

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

7. Security

We implement industry-standard security measures including HTTPS/TLS for all connections, hashed storage of API keys (raw keys are never stored), HttpOnly session cookies, and infrastructure protected by Cloudflare's edge network.

No method of transmission over the internet is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.

8. Cookies and session data

FIPSign cloud products use a session cookie to maintain your authenticated session in the dashboard. This cookie is HttpOnly, Secure, and expires after the configured session duration (default 24 hours). We do not use tracking cookies, analytics cookies, or any third-party advertising cookies.

PQ-Proxy On-Premise runs on your own server. Any session cookies set by the on-premise dashboard are stored in your browser and handled entirely by your own infrastructure — they are not accessible to FIPSign.

9. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify registered users by email before the changes take effect. The effective date at the top of this page will always reflect the most recent version.

Continued use of the service after notification of changes constitutes acceptance of the updated policy.

10. Contact

For any questions or concerns about this Privacy Policy or your personal data, contact us at [email protected].