Privacy Policy
Zero Telemetry
No analytics, tracking pixels, or usage reporting
No Cloud Required
Runs 100% offline (except when you choose Azure/TSA)
No Cookies
This website sets no tracking cookies
Keys Stay Local
Your .pfx files never leave your machine
1 Introduction
At TechRuzz ("we", "us"), we believe your code, certificates, and signing keys are your business — not ours. This Privacy Policy explains what limited data we collect, why, and how we protect it.
Code Signing Toolkit is designed with an offline-first philosophy. The core application does not require an internet connection and does not communicate with our servers during normal operation.
2 Data We Collect
2.1 Data Stored Locally (On Your Machine)
- License keys — stored in
pro_license.keynext to the executable - Hardware IDs — CPU and MAC address hashes used to bind licenses
- Certificates (.pfx files) — stored wherever you choose to save them
- Signtool path — remembered between sessions
- Theme preference — light/dark mode stored in memory
None of this data is transmitted to our servers.
2.2 Data We May Collect (Website Only)
- Download counts — aggregated, anonymous tally of installer downloads
- Email address — only if you contact support or purchase a license
- Hardware ID — only if you voluntarily submit it to activate a Pro/Team license
- Payment info — processed by our payment processor (we never see card details)
2.3 Data We Do NOT Collect
- ❌ Your source code or signed binaries
- ❌ Certificate contents or private keys
- ❌ File names or paths you sign
- ❌ Telemetry, crash reports, or usage analytics
- ❌ IP addresses tied to application usage
- ❌ Browser fingerprinting or tracking pixels
3 Hardware ID & Licensing
To prevent unauthorized redistribution, Pro and Team licenses are cryptographically bound to a hardware fingerprint. This fingerprint is:
- Generated locally from your CPU ID + primary MAC address
- Hashed using HMAC-SHA256 (only an 8-character prefix is used)
- Stored in your license key — we do not store your raw hardware ID on our servers
4 Third-Party Network Requests
The Software only makes outbound network connections when you explicitly trigger them:
- Azure Trusted Signing — connects to your Azure Key Vault when you sign with Azure credentials
- RFC 3161 Timestamp Servers — connects to DigiCert, Sectigo, SSL.com, or GlobalSign when you timestamp a signature
- Windows SDK download link — opens your browser only when you click the link
We do not control the privacy practices of these third parties. Please review their respective policies.
5 Website Cookies
This website does not use cookies, tracking pixels, Google Analytics, or any form of user tracking.
We use a single localStorage flag to remember if you dismissed the "no cookies" notice. That is the entirety of our client-side storage.
6 Data Retention
- Support emails — retained until resolved, then archived for 1 year
- Purchase records — retained as required by tax law (typically 7 years)
- License keys — stored only to enable re-downloads; deleted upon request
7 Your Rights
Regardless of jurisdiction, we honor the following rights:
- Access: Request a copy of any data we hold about you
- Deletion: Request deletion of your purchase records (subject to legal retention)
- Portability: Receive your license keys and purchase history
- Opt-out: You can deactivate your license and uninstall at any time
To exercise these rights, email support@codesigningtoolkit.com.
8 Children's Privacy
The Software is a developer tool not intended for children under 16. We do not knowingly collect data from children.
9 Changes to This Policy
We may update this Privacy Policy. Material changes will be announced on our website. The "Last updated" date at the top reflects the most recent revision.
10 Contact
For privacy-related questions or requests:
- Email:
support@codesigningtoolkit.com - Website: codesigningtoolkit.com