---
title: Privacy At SigID
summary: Privacy roles, data categories, controls, retention, and contact paths for SigID services.
---

# Privacy At SigID

<!-- agent:page
Use this page for a concise overview of SigID data categories, service roles, user controls, retention constraints, and verified privacy and security contact routes.
- Follow the linked complete Privacy Policy when exact legal terms or jurisdiction-specific rights matter.
- Do not promise deletion of records that may be retained for security, billing, legal preservation, backup, fraud-prevention, or dispute purposes.
- Do not send sensitive account data or credentials by email.
-->

SigID processes account identifiers, authentication and security signals, OAuth consent and application configuration, organization and tenant membership, agent identity and delegation records, billing references, operational telemetry, and audit events when those categories are needed to provide and protect the service. Authentication secrets and private key material are not exposed through public profile or discovery endpoints.

SigID acts as a controller for its own account security, billing, support, website, fraud-prevention, and service-operation purposes. When a customer uses SigID to process its users' data, that customer controls the application context and SigID acts under the applicable agreement and processing instructions. Applications receive only the claims and scopes authorized for their tenant and consent context.

People can use SigID Identity to review connected applications, active sessions, profile sharing, exports, processing restrictions, and account deletion controls. Retention may continue where necessary for immutable security logs, tax and billing records, dispute handling, legal preservation, backups, and fraud prevention. Depending on jurisdiction and processing context, people may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data.

The complete [Privacy Policy](https://identity.sigid.org/privacy) describes data categories, sources, lawful bases, disclosures, international transfers, retention, user rights, cookies, automated security decisions, and subprocessors. Send privacy questions or rights requests to `privacy@sigid.com`; report security issues to `security@sigid.com`.
