Privacy Policy

Last updated 22 July 2026

This policy describes what we hold and what we deliberately do not. The defining fact about BA | Signet is that we prove control of a key without ever holding one.

Data controller: Aletheia Tech Ltd (UK). Contact: support@blockchainanalysis.io.

We never hold a private key

By construction we never receive, request or store a private key or seed phrase. A certificate records that a signature verified against an address; it is built from public information — the address, the challenge, the signature and the time — and nothing that could reconstruct a key.

The counterparty (the signer)

A counterparty who signs a challenge is not our customer and has no account. For each verification we hold only the minimum: the address, the challenge, the signature, the time of signing, and the reference the requester chose. We do not build an advertising or cross-site profile, and we do not process the IP address beyond what is needed to prevent abuse of the signing page.

This data forms the requester's compliance record and is retained on their behalf; it is removed on the requester's instruction or a valid request.

The requester (account holder)

For a requester account we hold your email address, the identifier from your chosen sign-in provider (Google, Microsoft, or GitHub) if you use one, and the verification requests and certificates you create.

Basic operational logs, and — if you anchor a certificate — the public on-chain record of its hash, which is permanent and outside our control.

Anchoring is permanent and public

If you anchor a certificate, a one-way hash of it is written to public blockchains. This cannot be deleted or altered, by us or anyone else. It contains no personal data in readable form, but the fact and timing of the anchor are public forever.

Your rights

You may access, correct, or delete your account data and the requests you created, from your dashboard or by contacting support@blockchainanalysis.io. Deleting a record removes it from our systems; it cannot remove an on-chain hash, which contains no readable personal data.

We use the processors listed on the Subprocessors page to run the service.