For the PQC Wallet mobile app, the PQC Wallet browser extension, and the e-signature service at pqc-imza.com.
Your signing keys are generated on your own device and never leave it. We cannot see them, recover them, or sign anything on your behalf. Everything else in this policy is about the account and document data you send us deliberately when you use the e-signature service.
When a document is anchored to the blockchain, the document hash, signature hashes, wallet addresses and timestamp become public and permanent. Nobody — including us — can edit or delete them afterwards. Read What goes on the blockchain before you anchor anything.
The following never reaches our servers, in any form:
These are held in the Android Keystore or the iOS Keychain, and are released only after you authenticate with your fingerprint, face or device passcode. Biometric data itself is handled entirely by your operating system; the app never receives it. Because we never hold your keys, we cannot restore access if you lose your device without a backup.
| Data | Why | When |
|---|---|---|
| Name | Identifies you as a signatory on documents | Registration |
| National ID number | Binds a signature to a legally identifiable person | Registration |
| Email address | Signature requests, completion notices, account recovery | Registration |
| Wallet address and public key | Verifying your signatures. Both are public by design | Registration and signing |
| Device name | Labels an active sign-in so you can identify and revoke it | Sign-in |
| Documents and their contents | Storing, displaying and signing the documents you create or upload | When you use the e-signature service |
| Signature records | Proving who signed what, and when | Each signature |
| Language preference | Showing the interface in your language | In use |
Your national ID number is sensitive personal data. We collect it because a signature that cannot be tied to an identifiable person has little evidential value, and we use it for nothing else.
When a completed document is anchored to SciChain, this is written to a public ledger:
This is what allows anyone to verify a signature independently, without trusting us. It is also permanent: a blockchain record cannot be altered or erased by anybody, so anchoring is a deliberate step you choose, not something that happens automatically. Your name, national ID, email and the document contents are never written to the blockchain.
| Service | What it receives | When |
|---|---|---|
| Google Sign-In | Your Google account email and name | Only if you choose to sign in with Google |
| Google Gemini | The text of the document you are drafting | Only when you use the AI drafting assistant |
| İyzico / Eppay | Payment details, handled entirely by them | Only when you buy credits. We never see or store card numbers |
| SciChain network | The public anchoring record described above | Only when you anchor a document |
We do not share your data with anyone else. We may disclose data if legally required to do so by a court or competent authority.
Under Turkish data protection law (KVKK, Law No. 6698) and equivalent regulations, you may ask us to:
Write to info@scimatic.org and we will respond within 30 days.
The limit on deletion: we can delete your account, documents and personal details from our systems. We cannot remove anything already written to the blockchain, because no one can. Those records contain hashes and wallet addresses — not your name, ID number or document contents.
These applications are not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to us and we will remove it.
If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle your data, we will tell you in the app before it takes effect.
Questions about this policy, or requests about your data:
info@scimatic.org
İmza anahtarlarınız yalnızca kendi cihazınızda üretilir ve cihazınızdan hiçbir zaman çıkmaz. Bu anahtarları göremeyiz, kurtaramayız ve sizin adınıza imza atamayız. Anahtarlar Android Keystore veya iOS Keychain içinde saklanır ve yalnızca parmak izi, yüz tanıma veya cihaz şifrenizle doğrulama yaptıktan sonra kullanılabilir.
Ad soyad, T.C. kimlik numarası, e-posta adresi, cüzdan adresi ve açık anahtar, cihaz adı, oluşturduğunuz veya yüklediğiniz belgeler ve imza kayıtları. T.C. kimlik numarası özel nitelikli kişisel veridir; yalnızca imzanın hukuken belirli bir kişiye bağlanabilmesi için toplanır ve başka hiçbir amaçla kullanılmaz.
Hiçbir analitik, reklam veya takip yazılımı kullanmıyoruz. Konum, rehber, fotoğraf veya mikrofon verisi toplamıyoruz. Kişisel verilerinizi hiç kimseye satmıyoruz.
Bir belge blokzincire kaydedildiğinde belgenin SHA-256 özeti, imza özetleri, cüzdan adresleri ve zaman damgası herkese açık ve kalıcı olarak yazılır. Bu kayıtlar hiç kimse tarafından — bizim tarafımızdan da — değiştirilemez veya silinemez. Adınız, kimlik numaranız, e-postanız ve belge içeriğiniz blokzincire hiçbir zaman yazılmaz.
Google ile Giriş (yalnızca tercih ederseniz), yapay zekâ taslak asistanı için Google Gemini (yalnızca kullandığınızda, belge metni), ödeme için İyzico ve Eppay (kart bilgilerinizi görmüyor ve saklamıyoruz), belge kaydı için SciChain ağı.
6698 sayılı KVKK kapsamında verilerinize erişme, düzeltilmesini, silinmesini veya taşınmasını isteme ve işlenmesine itiraz etme haklarına sahipsiniz. Talepleriniz için info@scimatic.org adresine yazabilirsiniz; 30 gün içinde yanıt veriyoruz.
Silme talebinin sınırı: hesabınızı, belgelerinizi ve kişisel bilgilerinizi sistemlerimizden silebiliriz. Blokzincire yazılmış kayıtları ise hiç kimse silemez. Bu kayıtlar yalnızca özet (hash) ve cüzdan adresi içerir; adınızı, kimlik numaranızı veya belge içeriğinizi içermez.
Bu bölüm İngilizce metnin özetidir. Ayrıntılar için yukarıdaki İngilizce bölüme bakınız.