Privacy

Privacy Policy

Last reviewed: July 14, 2026

1. Who we are

AuthenSeal is a service for creating and verifying technical records for digital files, including cryptographic hashes, public verification pages, and PDF certificates generated from stored seal metadata.

This policy explains how AuthenSeal processes personal data in the current web application, including account registration, login, Google OAuth, file sealing, verification, billing, cookies, and account deletion.

2. Data we process

Depending on how you use AuthenSeal, we process the following categories of data:

  • Account data: email address, display name, optional company name, account plan, account creation time, last login time, password hash for password-based accounts, and external login identifiers for OAuth accounts.
  • Google OAuth data: when you sign in with Google, AuthenSeal requests email and profile information needed to create or link your account and sign you in.
  • Uploaded-file data: files submitted for sealing, verification, AI labeling, image tools, or PDF tools are read by the server to perform the requested operation.
  • Seal and certificate data: original filename, file size, MIME type, SHA-256/SHA-512 hashes, public verification token, declaration text, C2PA metadata where available, RFC 3161 timestamp data, AI-signal metadata where produced, and generated certificate data.
  • Billing data: Stripe customer/subscription identifiers and plan updates received from Stripe. AuthenSeal does not store full card numbers.
  • Security and operational data: authentication cookies, language preference cookies, preview cookies, API usage information, rate-limiting data, application logs, and security-related events.

3. Why we process data

We process personal data to provide and protect AuthenSeal. The main purposes are:

  • Creating, maintaining, and securing user accounts.
  • Signing users in through password-based login or configured OAuth providers such as Google.
  • Processing uploaded files to calculate hashes, detect file capabilities, inspect or embed C2PA data where supported, request timestamps, apply labels, and generate outputs requested by the user.
  • Creating public verification records and PDF certificates from seal metadata.
  • Enforcing plan limits, usage limits, and rate limits.
  • Processing paid plans and billing events through Stripe.
  • Responding to support, privacy, security, and account deletion requests.

4. Uploaded files and generated certificates

When you upload a file, AuthenSeal reads it to perform the operation you requested. For sealing, the service computes cryptographic hashes and stores seal metadata in PostgreSQL. For verification, the service may compute a hash and compare it with stored records. For image and PDF tools, the service processes the uploaded file to return a processed file to you.

Generated certificates are created from stored seal metadata such as filename, hashes, public token, timestamps, declaration text, and C2PA-related information where available. Public verification pages may display selected seal metadata.

5. Hosting and service providers

The current codebase and deployment use or support the following providers:

  • Railway for application hosting and PostgreSQL hosting in the current production setup.
  • PostgreSQL for account data, seal records, usage data, subscriptions, and data protection keys.
  • Google OAuth for optional sign-in using email and profile scopes.
  • Stripe for checkout, subscription billing, billing portal sessions, and webhook-based plan changes.
  • Resend for email delivery when configured, such as welcome, verification, reset, and notification emails.
  • Configured RFC 3161 timestamp authorities for timestamp requests based on file hashes, not full uploaded files.
  • Cloudflare R2 storage when configured; otherwise the application can use local file storage fallback for development or non-R2 environments.

6. Cookies

AuthenSeal uses cookies and similar server-side mechanisms needed to run the service:

  • Authentication cookie `sealit.auth`, used to keep signed-in users authenticated.
  • Internal visit analytics cookie `sealit.visit`, used to count unique homepage sessions in the admin-only analytics view.
  • Preview cookie `sealit.preview`, used to allow preview access while Coming Soon mode is enabled.
  • Language preference cookie used by ASP.NET Core localization to remember the selected language.
  • Security and framework cookies or tokens used by ASP.NET Core for authentication, antiforgery, and secure operation.

7. Payments

Paid plans are processed by Stripe. AuthenSeal creates Stripe checkout sessions and may redirect you to Stripe-hosted checkout or billing portal pages. Stripe sends webhook events to AuthenSeal so the application can update your plan.

Payment card data is handled by Stripe and is not stored by AuthenSeal. AuthenSeal stores only the billing identifiers and plan information needed to connect your account with Stripe subscription status.

8. GDPR rights

If GDPR applies to you, you may have the right to request access, correction, deletion, restriction, portability, and objection to processing of your personal data. You may also have the right to lodge a complaint with your local supervisory authority.

To exercise your rights, contact us using the privacy contact below. We may need to verify your identity before acting on a request.

9. Account and data deletion

Authenticated users can request account deletion from the Settings page. The current application soft-deletes the account and changes the stored email value so it is no longer used as an active account email.

Because seal records and public verification pages may be connected to certificates, hashes, declarations, billing history, or security records, deletion requests are reviewed and handled according to the nature of the data and applicable obligations. You can contact us for account and data deletion requests at the privacy email address below.

10. Changes to this policy

We may update this Privacy Policy when the service, providers, configuration, or legal requirements change. The version shown on this page is the current public version for AuthenSeal.

Contact

For privacy questions, GDPR requests, and account or data deletion requests, contact AuthenSeal at:

privacy@authenseal.com

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.