01
Who this is for
Two different people read this page, and they are owed different answers.
If you have an account, you signed up and you send documents. We decide what is held about you and why, so we are the controller and everything below is our answer.
If someone sent you a document, you never made an account and never chose us. The sender decides what is in that document and who receives it — they are the controller, and we act on their instructions. To change or remove it, ask them first. If you cannot reach them, write to [email protected] and we will help.
02
What we collect
From account holders
- Name and email. Phone number, job title and photo only if you add them.
- A password hash, or a passkey's public key. We never hold the password itself, and passkey biometrics never leave your device.
- Your workspace, your role in it, and your plan.
- Preferences: timezone, date format, notification settings.
- Failed sign-in counts, so an account can be defended from guessing.
From signers
- Name and email — that is how the document reached you.
- A phone number, only if the sender asked for SMS verification.
- What you type into the document's fields, and the signature you draw, type or upload.
- Your reason, if you decline.
From everyone
- The documents themselves, and their file names.
- Your IP address and browser, recorded against actions on a document. That one has consequences — see the audit trail.
We run no analytics, no advertising, no session recording and no tracking pixels. There is no Google Analytics, no tag manager, and no third-party script on the marketing pages. Our emails carry no tracking pixel, so we cannot tell whether you opened one.
03
Your documents
Every document is encrypted with AES-256-GCM before it is written to disk, under a key unique to that file. Profile photos and workspace logos go the same way. A stolen disk, a leaked backup or someone browsing the storage volume yields nothing readable.
We do not open your documents, and we do not train anything on them.
One thing we would rather tell you than have you assume: the database itself is not encrypted at the application layer. Names, email addresses, IP addresses and the values typed into a document's fields are ordinary columns. Passwords, session tokens, API keys and any third-party credentials you give us are hashed or encrypted.
04
The audit trail
This is the clause most policies would leave out, and the one worth your time. A signature is only as good as the evidence behind it, so every meaningful action on a document — sent, opened, consented, signed, declined — is written to a trail built so it cannot be rewritten quietly.
Three consequences follow, and they are real.
- Each entry records an IP address and browser, with the name and email of whoever acted, as they were at that moment.
- Those IP addresses appear on the completed document's certificate, which is attached to the signed PDF every party receives. Sign something and the other signers can see where you signed from. That is deliberate — it is what makes the signature evidence — but you should know it before you sign, not after.
- Entries can never be edited. Not by you, not by the sender, not by us: the database refuses updates to them outright. We cannot redact a line on request. Removing one means deleting the whole document it belongs to.
When a completed document is kept as a record, its trail is kept with it — including the name and email of people who have since closed their account. Without it the document would stop being provable, which is the only reason anyone signed it here.
06
Services we use
A short list, kept short on purpose. Each receives only what it needs to do its job.
| Service | What it receives | When |
|---|---|---|
| Our email provider | The recipient's address, and a message naming the sender and the document | Every email we send |
| Google reCAPTCHA | Your IP address and browser signals, to tell a person from a bot | Sign-in, sign-up, password reset, unlocking a share link |
| Twilio | A signer's phone number, to send a verification code | Only if the sender turns on SMS verification |
| Google or Dropbox | A request for the file you pick, using the access you grant | Only if you connect the account yourself |
| Timestamp authority | A hash of the sealed document — never the document | When a document is sealed, if timestamping is on |
Some are in the United States; where that is so we rely on the transfer safeguards those providers publish.
One exception worth naming. A workspace on the Business plan can send through its own mail server instead of ours. If the workspace that sent you a document has done that, the email — and so your address and the document's title — passed through a server that belongs to them, not to us.
We do not sell your data. There is no arrangement under which we would.
07
How long we keep things
- Completed and declined documents are kept as records. A signed agreement that disappears because one party closed their account is not evidence, and both sides relied on it.
- Deleted documents sit in the trash for 30 days, then go along with their files.
- A closed account has 30 days' grace, with a reminder a week before. After that the account, its sessions, passkeys, saved signatures, connected accounts and API keys are deleted.
- Sign-in codes and magic links expire in minutes and are cleared shortly after.
- Sessions expire after 7 days, or 30 with “Remember me”.
Drafts and anything never sent go with the account. What survives is the record of what was actually signed.
08
Your rights, and two limits
Ask us for a copy of your data, a correction, deletion, or to object to how we use it — [email protected] reaches a person. From inside the app you can already export your data and schedule deletion under Account settings, without asking us at all.
Two limits, stated plainly rather than discovered the hard way:
- An audit trail cannot be edited or partly redacted. Where a record must go, the document and its trail go together.
- We may keep a signed document despite a deletion request, where it is needed to establish or defend a legal claim — which is what a signed agreement usually is. Your account, and everything else, still goes.
If you are in the UK or EU and think we have this wrong, you can complain to your data protection authority. We would rather you told us first.
09
How we protect it
- Documents encrypted with AES-256-GCM before they reach the disk.
- Passwords hashed with Argon2id — and passkeys supported, so you can have no password at all.
- Sessions are opaque tokens; the server stores only a hash, so our database cannot be used to sign in as you.
- Every completed document is sealed, and its audit trail hash-chained so that a quiet edit breaks visibly.
- Credentials you give us — a mail server password, storage keys — are encrypted, not merely hidden.
- Our own admin tooling sees counts, titles and statuses across the platform — it cannot open a document. Files sit encrypted on disk regardless of who is asking.
No system is perfect. If you find a security problem, write to [email protected] and we will take it seriously.
10
Changes, and reaching us
If we change what we collect or who we send it to, we update this page and move the date at the top. Material changes get an email to account holders — never a silent edit.
Questions, requests, or a correction to something written here: [email protected]. It reaches a person, not a queue. The contact page works too.