Legal
Privacy policy
Last updated 2026-08-11
This is a starting template, not legal advice — have it reviewed against your actual data handling and local law (e.g. GDPR/CCPA) before relying on it.
What we collect
To operate the service, we collect and store:
- Account info: name, email, and a hashed password (we never store your password itself).
- Documents you upload, and the signature images/text values recipients submit.
- Audit metadata for every meaningful action on an envelope — who did what, when, from what IP address and browser. This exists specifically to make signatures legally defensible; we don't use it for anything else.
- Billing information, handled entirely by Stripe — we never see or store card numbers.
How we use it
Solely to provide the service: rendering your documents, emailing signing invites and reminders, producing the completed signed PDF, and enforcing plan limits. We don't sell your data or use your documents to train anything.
Who else touches it
A small number of infrastructure providers process data on our behalf, under their own agreements:
- Cloudflare R2 — stores uploaded and signed documents.
- Resend — delivers signing invite, reminder, and completion emails.
- Neon (PostgreSQL) — hosts the database.
- Stripe — processes payments and manages subscriptions.
Retention
Documents and their audit trails are retained for as long as your account is active, so completed signatures remain provable. You can request deletion of your account and associated documents at any time, subject to any legal retention obligations for completed signed agreements.
Your rights
You can access, export, or request deletion of your data by contacting us. Recipients who sign a document but don't hold an account can make the same request for their own signing records.
Cookies
We use a single session cookie to keep you signed in. No advertising or third-party tracking cookies.
Contact
Questions about this policy — reach out via the contact details on your account page.