← Primust · Legal

Privacy Policy.

Effective April 23, 2026. Primust separates marketing-site analytics, account data, and signing metadata from the governed content itself.

Summary
Product proof and customer content are intentionally separated.

Signing requests contain commitment hashes and related metadata, not the underlying content being governed. Marketing-site analytics are separate from the dashboard, API, and offline verification flow.

Scope

This Privacy Policy describes how Primust, Inc. ("Primust," "we," "us," or "our") collects, uses, and protects information when you use our public website, APIs, dashboard, and related services (collectively, the "Services").

The policy separates three categories of information: marketing-site analytics, account and billing data, and signing metadata used to issue credentials.

Marketing site

Website analytics. The public marketing site uses Vercel Analytics and Vercel Speed Insights to measure page traffic, navigation patterns, and page performance.

Those tools are limited to the public website. They are not part of the dashboard, API, signing path, or offline verification flow.

Primust does not use business-visitor identification on the marketing site.

Information we collect

Account information. When you create an account, we collect your name, email address, and organization name. If you subscribe to a paid plan, we collect billing information through our payment processor.

Service metadata. We collect usage and reliability metadata such as API call volumes, error rates, request timing, and feature usage patterns needed to operate and secure the Services.

Signing requests. When you submit a VPEC for signing, we receive commitment hashes and related execution metadata. We do not need the underlying governed content in order to issue a credential.

How we use information

We use the information we collect to provide, maintain, secure, and improve the Services; process transactions; send service communications; investigate abuse or service failures; and comply with legal obligations.

We do not sell personal information. We do not use customer data for advertising.

Data retention

Account information is retained for the duration of your account and as needed for billing, tax, and legal compliance. Service telemetry may be retained in aggregated form for operations and security analysis.

Signing metadata is retained for 90 days by default unless a longer retention period is required for abuse prevention, support, or legal compliance.

Verification boundary

Primust is designed so that a credential can be verified later with the open-source verifier and published public keys. A relying party does not need a live API call to Primust in order to validate a credential.

Because governed content does not need to transit Primust for signing, the privacy boundary is part of the product architecture, not just a contractual promise.

Third parties

We use third-party service providers for infrastructure hosting, payment processing, and marketing-site analytics. Those providers may process information only to perform services on our behalf, subject to contractual and legal restrictions.

We may disclose information if required by law, subpoena, or court order.

Cookies

We use essential cookies for authentication and session management. The public website may also use analytics-related browser storage through Vercel’s tooling. You can control non-essential browser storage through your browser settings.

Your rights

You may request access to, correction of, or deletion of your personal information by contacting us. Some jurisdictions provide additional privacy rights under applicable law.

Changes

We may update this policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the effective date.

Contact

For privacy inquiries, contact us at privacy@primust.com.

Primust, Inc.