Privacy and data · Updated October 4, 2026

Your key and your public record

Dev Autographs is operated by Axiom Risk Group LLC. It links signing keys to a GitHub identity and publishes provenance metadata. This page describes the current product's data flows, including the signing-key copy uploaded during sign-in. Contact info@axiomriskgroup.com for privacy questions.

Why information is processed

We process account and signing information to connect devices, verify submitted records, deliver requested features and maintain registry integrity. Service and request information may be used to diagnose failures, protect accounts, prevent fraud and respond to support or rights requests. If you email support, we receive your address, message and any attachments you choose to send.

Depending on applicable law and the activity, processing relies on providing the service you request, legitimate interests in secure operation, legal obligations, or consent where required. You can decline account sign-in and use the publicly available website. Do not send secrets or sensitive personal data in support attachments or public labels.

Kept on your device

The web desk creates an Ed25519 signing key in your browser and saves it in this site's local storage. This browser copy is not encrypted by Dev Autographs. Sign-in deposits the private key so the registry can seal an encrypted copy. A later sign-in on another computer downloads that copy and signs this browser out.

Downloading an identity or setup file exports your private key. Setup files encode the key but do not encrypt it. Keep these files private and delete a setup file after use. Anyone holding a copy can use the signing key until it is revoked.

The site also saves theme and guide preferences, pending device-login state and a cached release label in browser storage. Clearing site storage removes these local values; it does not revoke a key or erase the public registry.

Windows key storage in 0.2.9

The Windows desktop and CLI in version 0.2.9 encrypt the stored signing key with Windows DPAPI for the current Windows user. The setup script passes the exported identity to that CLI through standard input; it does not create a plaintext identity staging file. The CLI validates an existing identity before changing it and refuses to fall back to plaintext when protection fails.

This protects the stored key, not code already running as your Windows user. Use version 0.2.9 or later with this protected format; version 0.2.8 cannot read it. On macOS and Linux, the CLI uses a file restricted to the owner rather than Windows DPAPI. Browser local storage and downloaded identity or setup exports remain unencrypted.

Sent to the registry

GitHub sign-in provides your public GitHub login and account ID. The registry associates these with your public key, fingerprint, autograph wording and profile style. It also stores the deposited private key with AES-256-GCM, using the registry's server secret. Public account pages do not return that private key. Sign-in does not request access to your email or repository contents.

Publishing a seal or attestation sends signed provenance metadata, such as content hashes, signer keys, timestamps and contributor information. Repository features can also publish repository identifiers and names. Submitted signed records may include file-path metadata. Do not put secrets or personal information in public autograph labels.

The browser desk provides public account and provenance lookups. Published metadata and downloadable reports should be treated as public; signing proves integrity, not confidentiality.

Marketplace connection, when enabled

Marketplace onboarding is disabled unless the registry operator enables it. When enabled, it supports personal GitHub accounts and checks purchase eligibility with GitHub; a plan ID in a browser URL does not grant access.

The registry then stores the GitHub account ID and type, plan ID, subscription state, effective and verification dates, trial timing, pending plan changes and cancellation or deletion deadlines. Webhook records contain a delivery ID, a payload digest, a received date and a keyed account digest. The application does not retain the full webhook payload, billing details, prices or email fields in those records.

Marketplace cancellation and data-retention policy must be configured by the operator before a public launch. This page does not promise an active automatic deletion service or erasure of external logs, backups or copies.

Retention, unlinking and requests about your data

Unlinking asks the registry to revoke the browser's signing key. The desk removes the local key only after the registry acknowledges that request. Earlier signatures and published history are not erased by unlinking. Account information, security records and public provenance can remain after unlinking, including where needed for record integrity, dispute handling or legal obligations. No fixed universal retention period is promised here.

The desk does not currently offer a self-service account-deletion workflow. Contact info@axiomriskgroup.com about access, correction, removal or portability of your information, or an objection to processing. Depending on your location, you may have these and other privacy rights, a right to withdraw consent for processing based on consent, and a right to complain to a privacy regulator. We may need to verify your identity without requesting your private signing key. Requests are assessed under applicable law, including its exceptions and response deadlines.

Historical cryptographic records, legal records and external copies may remain where removal is not technically possible or is lawfully restricted. This page does not promise complete erasure of already published copies. Ask us about a disputed profile or record before publishing further information.

External services

Sign-in and release downloads use GitHub. The website and registry use external hosting providers. Website fonts are served by this site without requests to a separate font provider. Opening the support community uses Discord. Those services process their own requests under their own policies.

These application descriptions do not specify a retention period for hosting-provider request logs. Ask the maintainer before submitting information you are unsure about sharing.

Storage, recipients and safeguards

Website and registry infrastructure may process request information such as IP addresses, browser details and timestamps in provider logs. Data may be processed where our infrastructure or service providers operate. Public provenance is visible to anyone using public lookups or downloading reports. Hosting and account-service providers process information needed for their functions; information may also be disclosed when required by law or to address abuse, security incidents or rights disputes.

Browser local storage is used for the identity and preferences described above. No optional analytics or advertising tracker is configured in this website source. That does not mean hosting providers receive no request data. If optional tracking is introduced, its policy and any required consent controls must be provided before activation.

Technical safeguards reduce risk but do not eliminate it. In particular, browser storage and exported identities remain unencrypted, and registry key encryption uses a server-held secret rather than end-to-end encryption. Keep your device and GitHub account secure. Do not treat the registry as a confidential vault or submit private repository details for public publication.

Children and policy changes

The product is intended for developers and is not directed to children under 13. If you believe a child has submitted personal information, contact info@axiomriskgroup.com. This policy will be updated when the product's processing changes; material changes will be accompanied by appropriate notice and any consent required by law.

Back to Dev Autographs · Support and security reports