Privacy Policy

Effective date: March 2026 — Last updated: August 14, 2026

SignArmor ("we," "our," or "the app") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights under the EU General Data Protection Regulation (GDPR) and other applicable privacy laws.

Data Controller

The data controller for the personal data processed through the app is I12Y Limited (Michailidi 9, Limassol 3026, Cyprus), trading as SignArmor. For all privacy-related matters, you can contact us at support@signarmor.app.

1. Data We Collect

Legal Basis for Processing (GDPR Article 6)

We process your personal data based on the following legal grounds:

2. How AI Processes Your Documents

Text extraction happens entirely on your device — the original contract file is never uploaded. The extracted text is sent to OpenAI's API for AI-powered review. OpenAI does not use data submitted through its API to train its models; per OpenAI's API data usage policies, API inputs may be retained for a limited period for abuse monitoring and are then deleted. Your contract text is never used to train AI models.

3. Data Storage

4. Third-Party Services

We use the following third-party services to operate SignArmor:

Each service has its own privacy policy. We recommend reviewing them for complete details.

5. International Data Transfers

Your data is primarily stored in the European Union — our database and backend are hosted in the eu-central-1 region. Contract text sent for AI analysis is processed by OpenAI in the United States. Such transfers rely on appropriate safeguards, including OpenAI's certifications and contractual commitments (Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework, as applicable).

6. Automated Analysis (GDPR Article 22)

The AI analysis is informational only and does not produce any legal or similarly significant automated decisions about you. A human contact is always available at support@signarmor.app for any questions about an analysis.

7. Your Rights (GDPR Articles 15-22)

If you are in the European Economic Area (EEA), you have the following rights:

8. How to Exercise Your Rights

In the app: Go to Settings > Delete Account or Settings > Export Data.

By email: Contact support@signarmor.app. We will respond within 30 days.

9. Data Retention

10. Children's Privacy

SignArmor is not intended for users under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us immediately at support@signarmor.app.

11. Data Security

We implement industry-standard security measures including encrypted data transmission (TLS), encrypted storage, row-level security policies, JWT-based authentication (ES256), and rate limiting to protect your data.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will notify you through an in-app notification and update the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise these rights, use the in-app controls or contact us at support@signarmor.app. We will respond within 45 days.

13. Contact

For privacy-related questions or requests, contact us at:

support@signarmor.app