Privacy Policy
Last updated: May 28, 2026
Mark is a sovereign digital identity and signing app built by Noblestar Technologies LLC ("Noblestar," "we," "us"). This policy explains what data Mark collects, what it doesn't, and where your data lives.
What Mark stores on your device
- Your root private key — encrypted in your phone's secure hardware (iOS Keychain / Android KeyStore). Never leaves your device. We cannot access it.
- Your signing subkey — same protection as root key.
- Your identity information — display name, root fingerprint, trust tier, key lifecycle settings.
- Signed bundle archive — local copies of documents you've signed.
What Mark sends to our servers
- Service record — your public key, active subkey certificates, and revocation list. This is public by design — it's how others verify your signatures.
- Document hashes — SHA-256 hashes of signed documents (for timestamping and on-chain anchoring). We never see the documents themselves.
- Signed bundles — when you share a verification code, the cryptographic bundle is stored on our server. Bundles contain signatures and public key metadata, not the original documents.
Verification codes
When you share a signed document via verification code, the signed bundle is stored on our servers. Codes expire after 48 hours and the bundle is automatically deleted. The signed bundle file itself is permanent — if you or the recipient saved a copy, it can be verified independently of our servers.
What Mark does NOT collect
- Your documents. Mark signs document hashes. The original file never leaves your device unless you share it yourself.
- Your private keys. Root and signing keys are generated on-device and stored in hardware-protected storage. We have no access.
- Your location, contacts, or browsing history.
- Analytics or tracking data. No third-party analytics SDKs. No ad networks.
Third-party services
- Polygon blockchain — your service record (public keys, trust tier, revocation list) is published as an on-chain event log. This is permanent, public, and readable by anyone from any Polygon node.
- OpenTimestamps calendars — submits document hashes for Bitcoin-anchored timestamping.
- Pinata (IPFS) — used only for encrypted notary attestation document storage. Not used for service records or identity data.
Data sent to these services is limited to public keys, cryptographic hashes, and signatures. No personal information, documents, or private keys are shared.
Data permanence
By design, some data published by Mark is permanent and cannot be deleted:
- On-chain service records (Polygon) are published as immutable event logs. They contain your public keys, trust tier, and revocation list — never private keys or documents.
- Blockchain timestamps (Polygon, Bitcoin via OTS) are immutable once confirmed.
This is a feature, not a bug — it's what makes signatures independently verifiable forever. Only public cryptographic data (keys, hashes, signatures) is published on-chain. Private keys and original documents are never on-chain.
Your rights
You control your identity. You can delete your local identity at any time by uninstalling the app or clearing app data. Revocation entries and blockchain anchors are permanent by design — this protects the integrity of signatures already issued.
For questions or requests, contact privacy@noblestar.tech.
Changes
We may update this policy as Mark evolves. Changes will be posted at this URL with an updated date.
Noblestar Technologies LLC — Denver, CO