1. The short version
- HiSign™ has no account system, advertising, tracking, or Insight Velocity‑operated analytics, telemetry, crash reporting, remote configuration, or contact server. Insight Velocity does not receive your profile, contacts, cryptographic keys, QR image pixels, decoded QR values, verification phrases, or PINs.
- Everything you put into HiSign — your profile, your contacts, and your cryptographic keys — is stored on your device with industry‑standard authenticated encryption and is unlocked only by your device biometrics or device passcode. Information you choose to exchange goes directly to the participating peer device.
- Contact exchange happens peer‑to‑peer between two phones (NFC tap or QR code). Nothing about that exchange goes through Insight Velocity or any third‑party server.
- Any in‑app purchase is processed entirely by the Apple App Store or Google Play Store. HiSign never sees your payment information.
The current Android release uses ZXing Core to decode QR camera images locally on your device and does not include Google ML Kit. As of September 10, 2026, rollout of the release without ML Kit is complete on Google Play. Current QR scanning adds no scanner‑specific network or telemetry traffic.
The rest of this document spells out exactly what that means.
2. Information Insight Velocity does not receive
HiSign does not send any of the following to Insight Velocity:
- Your name, email address, phone number, postal address, or any other contact information you enter for yourself or your contacts.
- Your contact list from the operating system. HiSign keeps its own separate, encrypted contact store and never reads the OS address book.
- Your location (precise or approximate). The app does not request the location permission on either platform.
- Photos, videos, microphone audio, calendar entries, files, SMS messages, call logs, or browsing history.
- Advertising or tracking identifiers, the device serial number, or any other persistent device fingerprint.
- Crash reports, performance metrics, usage analytics, telemetry, or any other diagnostic data sent to Insight Velocity automatically.
- Payment information. All in‑app purchases are completed inside the Apple App Store or Google Play sheet; HiSign never sees your card, bank account, or billing address.
HiSign contains no advertising or attribution SDKs and no Insight Velocity‑operated analytics, telemetry, crash‑reporting, or tracking service. The current Android QR scanner uses ZXing Core locally and adds no scanner‑specific network or telemetry path.
3. Information that stays on your device
The following data is created or entered by you and is stored only on your device, in an encrypted local database:
- Your profile: the optional name, alias, phone numbers, email addresses, and notes you choose to add to your HiSign identity card.
- Your contacts: the HiSign cards you receive from other people, along with any nickname or notes you add about each one.
- Cryptographic key material: your personal identity key pair created on first launch, the per‑contact verification secrets exchanged with each peer, and a short fingerprint of each peer's public key (used to detect impersonation if a peer's key ever changes).
- App preferences: screen‑lock timeout, theme, widget pin choices, and similar local settings.
- Optional in‑app purchase record: if you choose to make an in‑app purchase, a small local record indicating the purchase has been made, kept only so the app can re-verify the purchase locally on launch. This record is never transmitted off the device and never sent to Insight Velocity.
How that data is protected
- All on‑device records are encrypted with industry‑standard authenticated encryption, using a per‑install random key.
- On iOS, that key — together with your private identity key — is stored in the iOS Keychain with an access policy that requires the device to have a passcode set, restricts the key to this device only, and requires the current Face ID / Touch ID / Optic ID enrollment for retrieval.
- On Android, the same per‑install key is wrapped by a hardware‑backed key (where the device supports it) in the Android Keystore, configured so that the wrapping key is destroyed if the user's biometric enrollment changes.
- The app requires device‑owner authentication — Face ID, Touch ID, Optic ID, or your device passcode — to unlock the encrypted store on every cold launch, and again after the background grace period elapses. The passcode is an accepted way in, not only a fallback when biometrics fail.
- Backups, when you choose to export one, are encrypted with a password you choose, using a slow password‑based key derivation function and authenticated encryption tuned to make brute‑force attacks computationally expensive on modern hardware.
4. Biometrics
HiSign uses biometric authentication (Face ID, Touch ID, or Optic ID on iOS; fingerprint or face unlock on Android) solely to unlock the encryption key that protects your local data.
- Biometric matching is performed entirely by the operating system.
- HiSign never sees, stores, or transmits your biometric templates, fingerprint images, or face data. Apple's and Google's platform documentation describes how these systems work.
- If biometrics are unavailable or have been removed, the app falls back to your device passcode; if neither is enrolled, HiSign cannot unlock the encrypted store and will prompt you to enable a screen lock.
5. Peer‑to‑peer contact exchange
Adding a contact in HiSign happens directly between two phones:
- NFC tap — two phones held back‑to‑back exchange a short signed payload over the operating system's NFC stack.
- QR code — one phone displays a signed QR code on screen, the other scans it with the camera.
- Manual exchange — for unusual cases, both sides type a short PIN‑encrypted code that may be delivered through any channel of your choosing.
In every case, the payload travels only between the two devices involved. Insight Velocity does not operate, route, or relay any contact‑exchange traffic, and does not receive a copy of the exchange. Live‑exchange payloads are short‑lived, and every payload is signed with the sender's identity key so the receiver can verify it has not been tampered with.
6. Network activity
HiSign is offline‑first. Its expected current network activity consists of the periodic clock‑integrity check and Google Play Billing on Android or the App Store on iOS when you choose to make a purchase. QR scanning in the current Android release adds no scanner‑specific network connection.
Clock‑integrity check
The app periodically checks its clock against a public time service, to detect a tampered or badly skewed device clock that could otherwise weaken the rotating verification phrase. This check uses the standard Network Time Protocol; only the timestamp fields the protocol defines are sent and received, and no account is involved.
That request:
- Is a standard NTP query and reads only standard NTP timestamp fields from the response.
- Goes to a short, ordered list of independent public time sources, contacted one at a time until one answers — never several at once. The shipped defaults are the U.S. National Institute of Standards and Technology (
time.nist.gov) and the U.S. Naval Observatory (tock.usno.navy.mil). The list is capped at four sources, and Google and Cloudflare time services are excluded by policy. - Sends no user data, no identifiers, no contact data, and no device fingerprint beyond what any standard internet request would reveal to any public server (your IP address and the timestamps the protocol requires).
- Is processed by the third party operating that service; Insight Velocity does not see or receive its results.
If every source fails, the app carries on offline using the operating system's clock.
Google Play Billing (Android)
If you make the optional purchase described in §7, the Google Play Billing service handles it, and that involves network traffic between your device and Google. Insight Velocity operates no part of it and receives none of it. On iOS the equivalent is handled by the App Store. If you do not make a purchase, this traffic does not occur.
QR scanning on Android
The current Play‑distributed Android release uses ZXing Core to decode QR camera images locally on your device and does not include Google ML Kit. The scanner does not send camera images, decoded QR content, profile data, contact data, or cryptographic material to Insight Velocity or a scanner service.
Insight Velocity verified the Play‑distributed release against the retained release bundle and inspected the Play‑signed package. Controlled observation on a Galaxy S25 during scanner initialization, idle preview, and a successful scan found expected NTP and Google Play activity but no scanner‑specific network or telemetry traffic.
Earlier Android releases — historical disclosure
The rollout of the release without ML Kit is complete. An older copy already installed on a device may still use ML Kit until that copy is updated. The following disclosure applies only to those older releases.
Earlier Android releases, including HiSign 1.1.0 (25), used the bundled Google ML Kit barcode scanner. Google’s ML Kit data disclosure states that ML Kit collects device and application information, per‑installation identifiers, performance metrics, API configuration, feature input and output sizes and versions, event types, and error codes for diagnostics and usage analytics. Google states that this information is encrypted in transit using HTTPS and is not transferred to third parties. Google’s disclosure does not list QR image pixels or decoded QR content as collected data for HiSign’s former configuration. People with an older installed Android release should update to 1.1.1 (32) or later for the current local ZXing scanner boundary.
For these older releases, Google governs retention and data‑rights requests concerning ML Kit diagnostic information under its own terms.
There are no HiSign‑operated accounts, contact servers, analytics, telemetry, crash reporting, or remote configuration — there is no HiSign‑operated server to talk to at all.
7. In‑app purchases
HiSign may offer an optional one‑time purchase. Whether you make, restore, or decline this purchase does not cause Insight Velocity to collect additional personal data. The store processes the transaction under its own privacy terms. The purchase is:
- Sold and processed entirely by the Apple App Store or the Google Play Store.
- Subject to the privacy policies of Apple and Google for the transaction itself.
- Verified locally on your device using the platform's standard purchase‑receipt APIs. HiSign does not run a server‑side receipt validator because no HiSign server exists.
Insight Velocity never receives, stores, or transmits your card number, bank information, billing address, Apple ID, or Google account email.
8. Home‑screen widgets
HiSign offers optional home‑screen widgets that surface a small subset of your local contact data (such as the names you have chosen to pin) for quick access. Widget content is rendered by the operating system from data already stored on your device and is visible according to your device's lock‑screen and home‑screen privacy settings. No widget data is transmitted off the device.
9. Optional diagnostic log sharing
If you choose to use the in‑app Report an issue option, HiSign will offer to attach a diagnostic log file. That file contains only event timestamps and high‑level event names (for example, "app launched", "biometric prompt shown", "NFC exchange started") and is composed entirely on your device at the moment you request it. It does not contain your contacts, your phone numbers or email addresses, your verification phrases, your cryptographic keys, or the contents of any exchange. You choose where the file is sent — HiSign does not transmit it.
10. Permissions used by the app
The app only requests the permissions it needs to function. The exact wording of each request is shown by the operating system when the permission is first needed. At a high level:
- Biometrics (Face ID, Touch ID, fingerprint) — to unlock the encryption key that protects your local data.
- NFC — to exchange contact cards by tapping two phones together.
- Camera — to scan another HiSign user's QR code when adding a contact.
- Internet (Android only as an explicit permission; iOS does not require an equivalent declaration) — for the clock‑integrity check and optional Google Play Billing described in §6. Current Android QR scanning adds no scanner‑specific network connection.
- Vibration (Android) — for haptic feedback on a successful exchange.
- Billing (Android) — to process the optional in‑app purchase via Google Play. iOS purchases use the App Store's built‑in StoreKit and require no additional permission.
HiSign does not request location, your operating‑system contact list, microphone, photos, calendar, SMS, phone state, "query all packages", or any other sensitive permission.
11. Children
HiSign is a general‑purpose utility and is not directed at children under 13 (or the equivalent age in your jurisdiction). Insight Velocity does not receive the profile, contact, key, QR content, or age data needed to determine a user’s age. A parent or guardian who believes a child has been using HiSign on a device they manage can clear all of the app's local data using the in‑app Delete all data option, which immediately and irreversibly wipes the local encrypted database and key material.
12. Your rights and choices
Because your HiSign profile, contacts, cryptographic keys, preferences, and purchase record remain on your device:
- Access / portability. You can view all of your data in the app at any time and export an encrypted backup file from Settings.
- Correction. You can edit your profile and contacts at any time.
- Deletion. Use the in‑app Delete all data option to wipe everything (encrypted database, keys, cached entitlement, and preferences). Uninstalling the app on iOS also removes its data; on Android, app data is removed when you uninstall or use Settings → Apps → HiSign → Storage → "Clear data".
HiSign has no Insight Velocity‑operated server holding those categories, so there is nothing for Insight Velocity to delete or hand back on your behalf — your control over that data is your control over your device.
European users (GDPR), UK users (UK GDPR), California users (CCPA/CPRA), and users in other jurisdictions with similar laws have the rights granted by those laws. For the local categories above, the practical answer is the same in every jurisdiction: Insight Velocity does not collect them on a server, does not "sell" or "share" them, and does not engage in cross‑context behavioural advertising. The lawful basis under GDPR Art. 6(1)(b) is "performance of a contract with the user" — i.e. running the app you installed.
13. Data breach
There is no central HiSign database to breach. If your device itself is lost, stolen, or compromised, your HiSign data remains protected by the on‑device encryption and the biometric/passcode gate described in §3. If we ever discover and confirm a vulnerability that could materially weaken that protection, we will publish details and mitigation guidance through an in‑app notice and through the support contact below.
14. Changes to this policy
If we change this policy:
- The Last updated date and Version at the top of the document are bumped.
- A summary of the change is added to the Policy change history below.
- Material changes are surfaced to users on next app launch with an in‑app notice.
- The previous version remains available on request from privacy@insightvelocity.io.
We will not retroactively reduce the privacy protections described here without notifying you in‑app first.
15. Policy change history
- 2026‑09‑10 — v1.5. Rollout update: the Android release without Google ML Kit is fully rolled out on Google Play. The current-release summary and §6 now state that QR decoding uses ZXing Core locally and does not include ML Kit. Disclosures for older installed releases are consolidated into a historical subsection in §6. Prior change-log entries are preserved. This policy update introduces no new collection or data flow and does not reduce the protections described here.
- 2026‑08‑31 — v1.4. Accuracy and privacy improvement: the current Play‑distributed Android release, HiSign 1.1.1 (32), uses ZXing Core for local QR decoding. The Play‑downloaded release bundle matched the retained release hash, the Play‑signed package was inspected, and controlled scanner observation found no scanner‑specific network or telemetry traffic. §6 now describes that current boundary while retaining the former ML Kit diagnostics disclosure for older installed Android releases, including 1.1.0 (25). This update introduces no new collection or data flow and does not reduce the protections described here.
- 2026‑08‑26 — v1.3. Accuracy: this policy now discloses the limited diagnostics and usage‑analytics information sent to Google by the bundled Android ML Kit barcode scanner and distinguishes that processing from information received by Insight Velocity. The wording is time‑scoped to the Android release available on the effective date so that a future verified scanner change can be reflected accurately. The policy also adopts the approved HiSign™ presentation. These corrections describe behavior already present and do not introduce a new data flow or reduce protection of profiles, contacts, keys, QR images, or decoded QR values.
- 2026‑08‑02 — v1.2. Accuracy: §6 previously stated that the clock check was the only network request and that there was “no other network traffic”. That was incomplete — on Android, the optional purchase described in §7 uses Google Play Billing, which is network traffic. §6 now discloses both, names the shipped public time sources and the policy that excludes Google and Cloudflare time services, and states the offline fallback. §3 and §4 now describe unlock as device‑owner authentication (Face ID, Touch ID, Optic ID, or device passcode) rather than biometrics with a passcode fallback, and add Optic ID. No change to what HiSign collects, processes, transmits, or shares; these corrections describe behaviour that was already shipping. No reduction in the protections described here.
- 2026‑05‑08 — v1.0.1. Editorial: clarified §3 to describe the iOS Keychain and Android Keystore storage models separately, and removed an ambiguous phrase that could be read as implying a Secure Enclave–wrapped iOS identity key. The underlying behaviour is unchanged from v1.0 — iOS identity keys have always been stored in the iOS Keychain (gated by Face ID / Touch ID), not the Secure Enclave. No change to data collection, processing, or sharing.
- 2026‑04‑23 — v1.0. Initial public release of HiSign for iOS and Android. Policy rewritten from the previous PWA‑era draft to reflect the native‑app behaviour shipped in v1.0.
16. Contact
Insight Velocity LLC
Privacy contact: privacy@insightvelocity.io
Security reports: security@insightvelocity.io
General support: support@insightvelocity.io
We aim to respond to privacy inquiries within 30 days.