Skip to main content

Legal

Privacy Notice

What we collect when you send or sign a document, why we keep it, and what you can ask us to do with it.

Last updated August 2026.

What we collect

We collect two different kinds of information, and it is worth keeping them apart.

  • Account information: your name, email address, password hash, language and interface preferences, and your sign-in history.
  • Document information: the files you upload, the names and email addresses of the people you ask to sign them, and the signatures and initials you create.
  • Evidence: for every action taken on a document we record what happened, when, from which IP address, and with which browser. This is the audit trail.

Why we keep the audit trail

A signature is only worth anything if it can be defended. The audit trail is what lets you show, later and to somebody sceptical, that a particular person received a particular document, proved their identity with a one-time code sent to their email, and signed it at a particular moment.

That is why the audit trail is append-only and why it survives even when a document is deleted from your account.

Who can see your documents

Access is narrower than most people expect, and deliberately so.

  • You can see your own documents. Nobody else on the platform can.
  • Recipients see only the document they were asked to sign, and only after verifying a one-time code.
  • Our administrators can see that a document exists, who it was sent to and what happened to it. They cannot read its contents.
  • Anyone you give a public download link to can download the signed copy. That link is off by default and you can revoke it.

One-time codes

We email a six-digit code to a recipient before their signature is recorded. We store only a hash of that code, never the code itself, and we keep a record of each attempt so that repeated failures are visible in the audit trail.

How long we keep things

Documents and their audit trails are kept for as long as your account exists, because a signed agreement is a record you may need years later.

If you delete your account we remove your personal information. We retain the minimum evidence needed to show that signatures made through us were validly made, because deleting that would undermine every document you ever signed.

Who we share with

We do not sell your information and we do not use your documents to train anything.

We use service providers to send email and to store files. They process this information on our instructions and for no other purpose.

What you can ask us to do

Whatever your local law entitles you to, these are available to everyone:

  • Get a copy of the information we hold about you.
  • Correct anything that is wrong.
  • Delete your account and the personal information in it.
  • Object to a particular use, and have a person rather than a process review the answer.

Security

Documents are stored on private storage and streamed through the application rather than served from public URLs. Signing links and one-time codes are stored only as hashes. Passwords are hashed and never recoverable.

No system is perfect. If you find a weakness, tell us and we will treat it seriously.