Who this covers
This policy applies to BearSignal Field — the mobile application used by licensed agencies to record evidence in the field — and to the public website at bearsignal.com.
BearSignal Field is issued to adult professionals working under a licensed institution. It is not offered to the general public and is not directed to children. Accounts are created by the institution, not by self-registration.
The application contains no advertising, no advertising identifiers, and no third-party analytics or tracking SDKs. We do not sell personal information and we do not share it for advertising or cross-context behavioural purposes.
What the application collects
Evidence you deliberately record
- Photographs and video captured with the in-app camera.
- Audio recordings captured with the in-app recorder.
- Documents and other files attached to an assignment.
Capture is always an explicit action you take. The application takes photographs live through the camera; it does not import from your photo library, and it does not capture in the background.
Context recorded alongside each capture
- Precise location at the moment of capture, so that a piece of evidence carries a verifiable place of origin. Location is requested only at that moment and is not tracked in the background. If you decline, the capture is still recorded — without a place of origin.
- Capture time, set on the device at the moment of capture.
- Integrity record — a SHA-256 digest computed on your device at the moment of capture, plus chain-of-custody metadata describing when the item was captured, uploaded and verified.
- Device characteristics — platform, model, operating-system version and an application-installation identifier, combined into a single descriptor stored with the record.
Account information
- Your institution identifier, seat identifier, work email address and display name, created for you by your institution.
- Operational records such as sign-in times and assignment activity, kept for security and audit.
What we do not collect
- Your contacts, calendar, messages, or photo library.
- Background or continuous location.
- Advertising identifiers, or any behavioural profile.
- Payment card details (billing, where applicable, is handled at the institution level).
Why each item is collected
- Evidence, capture time and integrity record — to establish that a recorded item has not been altered between capture and storage. The digest computed on your device is recomputed on our servers after upload; if the two disagree, the record is marked as not matching rather than accepted.
- Precise location — to attach a place of origin to a piece of evidence.
- Account identifiers — to route assignments to the correct person and to keep each institution's records separate from every other institution's.
- Device characteristics and operational records — for security, troubleshooting and audit.
On what the integrity record does and does not prove. The on-device digest and the server-side recomputation together give evidence that a file was not altered in transfer or storage. They are not a claim that the device itself is tamper-proof, and we do not present them as one.
Who receives the information
- The licensed institution that issued your account. Evidence and assignment records belong to the institution's case file. Within an institution, each person sees only the assignments allocated to them; institution administrators oversee the institution's own cases. No institution can see another institution's data.
- BearSignal Research Corp., which operates the platform on the institution's behalf.
- Infrastructure providers that host storage, databases and delivery for us, acting on our instructions and not for their own purposes.
- Courts, regulators or law enforcement, where we are legally required to produce records.
We do not sell personal information, and we do not disclose it to data brokers or advertisers.
Cross-border handling
The platform runs as two deployments. The deployment serving institutions in mainland China acts as an intake layer; the deployment in the United States holds the authoritative record. Where a transfer occurs, it is one-way, from the intake layer to the authoritative record, and it happens only when an institution administrator hands a case off — not when an individual submits work.
Material is transferred in the language it was entered in. Machine translation, where used, is produced separately for reading and is never substituted for the original and never enters the transfer path.
Field-level rules governing what may cross are maintained as an explicit, versioned policy, and each transfer is recorded against the policy version in force at the time.
The legal basis and permissibility of cross-border transfer for any given institution is determined with counsel, not by the application.pending legal review
Retention and deletion
Evidence records are kept for a defined retention period established for evidentiary purposes.
Sealed evidence cannot be deleted during the retention period. Once a recorded item passes server-side verification, the original is written to a write-once store. For the duration of the retention period that copy cannot be modified or deleted — including by BearSignal. This is deliberate: an evidence record that could be quietly removed would not be worth relying on.
This means a deletion request cannot reach sealed evidence while the retention period is running. It can reach everything else.
Account and operational data can be corrected or deleted. Your account details, sign-in history and operational records can be amended or removed on request, subject to the institution's own obligations. Accounts can be disabled by your institution's administrator at any time; disabling an account revokes access immediately.
To ask about access, correction or deletion, write to privacy@bearsignal.com. Because accounts are issued by institutions, we may direct a request to your institution where it is the party responsible for the case record.
Security
- All network traffic uses TLS; stored objects are encrypted at rest.
- Uploads are authorised one object at a time, scoped to a single assignment — an authorisation to upload one item does not grant access to anything else.
- Access to systems follows least privilege; the application component that writes sealed evidence is not granted permission to delete it.
- Verification is performed server-side. A mismatch is recorded as a mismatch; the system does not report success it has not verified.
- Evidence held on your device pending upload is stored inside the application's private storage area and is removed once it has been accepted.
No system is perfectly secure. We describe our measures accurately rather than promising outcomes we cannot guarantee.
Your choices
- Camera, microphone and location are each controlled by your device's operating-system permissions and can be changed at any time in system settings.
- Declining location does not prevent you from recording evidence; the record is simply stored without a place of origin.
- Declining camera or microphone prevents the corresponding kind of capture and nothing else.
The website
bearsignal.com serves static pages. It does not run advertising or third-party analytics. Standard server and content-delivery logs — including IP address and request metadata — are generated for delivery, security and abuse prevention.
Changes and contact
If this policy changes, the updated version is published on this page with a new effective date. Material changes affecting how evidence is handled will also be communicated to institutions.
Questions, requests and complaints: privacy@bearsignal.com.