Privacy Policy

Effective date: July 8, 2026

How we collect, use, and protect your data under the GDPR and Spanish LSSI. Free-tier documents are processed entirely in your browser and never uploaded.

1. Who is responsible for your data

When an account holder sends a document to recipients for signature, the sender decides the recipients and the document content: for the recipients' personal data processed in that flow, the sender acts as data controller and we process it on the sender's behalf to provide the service (see the Data Processing Addendum). For account and billing data, we are the controller.

The data controller is the entity identified in the Legal Notice published on this site (the "Operator", "we"). This Policy explains what personal data we process, why, on what legal basis, and what rights you have under the EU General Data Protection Regulation (GDPR) and Spanish data-protection law.

2. The free signer: your documents are never uploaded

Documents you open in the free, in-browser signer are processed entirely on your device. They are not uploaded to, stored on, or readable by our servers, and no copy of the document or your signature leaves your browser. This behaviour is enforced by an automated test suite that fails our release process if the free signer ever transmits a document.

The same applies to the offline Lite application: it runs locally and sends nothing to us.

3. What personal data we process

Account data (paid features): email address, name, and profile details received from you or your sign-in provider (Google SSO), and your plan and settings.

Billing data: handled by our payment processor Stripe. We receive limited information such as your email, the product purchased, amounts, and payment status, never your full card number. For Lite purchases without an account, Stripe collects your email at checkout and we use it solely to deliver the download link.

Vault content (paid): documents and saved signatures you choose to store, kept in private, encrypted storage and accessible only to your account through short-lived signed URLs.

Signature requests: recipient names, email addresses, the messages you write, and delivery/signing events, processed so we can send and track the request on your behalf.

Audit events: append-only records of document events (who viewed/signed and when, with technical metadata such as IP address and browser user agent), the electronic-signature consent given by recipients, and SHA-256 fingerprints of document versions, created to support the evidentiary value of signatures. When a request completes, a certificate of completion summarising these records (including signer email addresses and IP addresses) is generated and sent to the parties to the request.

AI-assisted placement (optional, paid): when you use it, page images or excerpts of the document you selected are sent server-side to our AI provider (Anthropic) to locate signature fields, and are not used to train models.

Usage data: server logs, device and browser information, and analytics and advertising identifiers (see Section 5).

4. Purposes and legal bases

We process data to provide the Service and fulfil contracts with you (Art. 6(1)(b) GDPR): accounts, vault, signature requests, audit trail, billing, and Lite delivery.

We process data for our legitimate interests (Art. 6(1)(f)): securing and improving the Service, preventing fraud and abuse, measuring usage, and funding the free tier with advertising. Where consent is required (Art. 6(1)(a)), for example for certain cookies or marketing, we rely on your consent, which you can withdraw at any time. We also process data to comply with legal obligations (Art. 6(1)(c)), such as tax and accounting rules.

5. Advertising and analytics

The free and marketing pages are ad-supported and use Google AdSense and analytics services (Google Analytics, Vercel Analytics). These providers may set cookies or use device identifiers to measure audiences and serve ads, and process data under their own policies. You can limit ad personalisation through your Google settings (adssettings.google.com) and control cookies through your browser.

Ads and third-party analytics never run inside the paid application area, and no document content is ever shared with advertising providers.

6. Who receives your data (processors)

We use a small set of service providers acting on our instructions: Vercel (hosting), Supabase (database, authentication, storage), Stripe (payments), Resend (transactional email), Google (sign-in, advertising, analytics), and Anthropic (optional AI placement). We do not sell personal data and we do not share your documents with advertisers.

7. International transfers

Some providers process data outside the EU/EEA (notably in the United States). Where they do, transfers are protected by an adequacy decision (such as the EU–US Data Privacy Framework) or by Standard Contractual Clauses, together with supplementary measures where appropriate.

8. How long we keep data

Audit events and signature-request records are retained for as long as the related document remains stored in the sender's vault, and are deleted together with the document. Certificates of completion emailed to the parties remain in the recipients' mailboxes outside our control.

Account and vault data are kept while your account is active and deleted or anonymised after account deletion, subject to short backup windows. Billing records are kept for the periods required by tax law. Audit events tied to signed documents are retained as long as the related document or request exists, because their purpose is long-term evidence. Signature-request tokens expire automatically. Lite purchase emails are kept as proof of purchase.

9. Your rights

You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior processing. To exercise them, contact the address in the Legal Notice; we will respond within the statutory deadlines. You can also delete your account (and its vault content) directly from the app.

10. Security

We apply technical and organisational measures appropriate to the risk: encryption in transit, private encrypted storage with per-user access rules, short-lived signed URLs, hashed share tokens, append-only audit logs, and strict separation of server-side secrets. No system is perfectly secure; if a breach affects your rights, we will notify you and the authority as required by Arts. 33–34 GDPR.

11. Children

The Service is not directed at children under 14, and we do not knowingly process their data. If you believe a child has provided us personal data, contact us and we will delete it.

12. Complaints

If you believe we process your data unlawfully, you may lodge a complaint with the Spanish supervisory authority (Agencia Española de Protección de Datos, aepd.es) or with your local authority in the EU/EEA.

13. Changes to this Policy

We may update this Policy as the Service evolves. Material changes will be announced on this page and, for account holders, by email or in-app notice. The date at the top indicates the current version.