Last updated: 18 July 2026
SureSign is a mobile application published by BigHelpers ("we", "us", "our"). It verifies digital signatures in PDF documents, can add AES-256 open- password protection to a PDF, and offers an optional Secure Vault for encrypted document storage. This policy describes the app's current behaviour.
You can verify signatures, protect PDFs, scan QR codes and keep local records without a login or account. We do not ask for your name, email address or phone number.
If you choose to create a Secure Vault, you invent a Vault ID and password. We store the Vault ID and a one-way password hash needed to authenticate the account. There is no email address, phone number or password-recovery contact on the account, so we cannot reset a lost password.
api.karyayogi.in.We retain a minimal operational record containing page and signature counts, computed trust facts and score, a SureSign client tag and a technical platform string. It does not include the document or your identity.
We cannot recover or remove a PDF password for you. If you use the in-app password generator, save the generated password before leaving the screen.
If you save a document to the Vault, we store an encrypted copy until you delete it. Each document has its own encryption key. We also store the item name, file size, SHA-256 hash, verification outcome and trust score or protection algorithm, and upload time. A Vault session token is kept in your device's encrypted secure storage, expires after 12 hours, and is revoked when you sign out.
Optional biometric unlock is performed by Android or iOS on your device. SureSign and our server never receive your fingerprint, face image or other biometric data.
Saved reports, result images, raw result JSON, Trust Passports, “What Changed?” records, Trust Heatmap data and your trusted-authorities list stay in the app's private storage. They leave the device only if you choose to share them. Temporary copies created to open or share a PDF are automatically removed within minutes and swept again on the next launch.
The camera is used live on your device only when you choose a QR-scanning feature. The camera feed is not recorded, saved or uploaded. Aadhaar, GST invoice, PAN and DigiLocker QR data is decoded and checked on the device. If a QR contains a signed-PDF link, the linked document is fetched and verified as described above.
You can delete any individual Vault document inside the app. This immediately destroys that document's encryption key and cannot be undone.
To permanently delete the entire Vault account and all its documents:
The account, all stored documents and their encryption keys are deleted, all sessions are revoked, and all signed-in devices are signed out. For help with a deletion request, email admin@bighelpers.in and include the Vault ID; we may need to verify that you control the account.
Local-only data can be removed by clearing SureSign's app storage or uninstalling the app.
Verification uploads and Protect passwords are not retained after the request. Vault documents are retained, encrypted, until you delete them or delete the account. Vault sessions expire after 12 hours. All app-server traffic uses HTTPS. Documents saved to a Vault are encrypted at rest, each with its own key.
SureSign is a general-purpose document utility and is not directed at children. It does not ask any user for identity or contact details and does not build advertising or analytics profiles.
If SureSign's data handling changes, we will update this page and its “Last updated” date. Questions, privacy requests and grievances may be sent to admin@bighelpers.in.