Privacy Policy
Effective date: March 2026 — Last updated: August 14, 2026
SignArmor ("we," "our," or "the app") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights under the EU General Data Protection Regulation (GDPR) and other applicable privacy laws.
Data Controller
The data controller for the personal data processed through the app is I12Y Limited (Michailidi 9, Limassol 3026, Cyprus), trading as SignArmor. For all privacy-related matters, you can contact us at support@signarmor.app.
1. Data We Collect
- Account information: Your email address, provided via Apple Sign-In (iOS), or Google Sign-In or a one-time email code (web).
- Waitlist: If you voluntarily submit your email address on our website (landing page or paywall) to be notified when SignArmor becomes available on your platform, we store that email address, the signup source, and the time of submission. We do not store your IP address.
- Contract text: Your contract file never leaves your device. Text is extracted locally on your device and only that extracted text is transmitted for analysis. We do not keep your contract text after the analysis is generated. The analysis report itself is stored, and it quotes the specific clauses it flags so that you can find them again later; those short excerpts are therefore retained as part of the report, and are deleted with it when you delete your account.
- Analysis results: The AI-generated analysis of your contracts (safety scores, red flags, recommendations, etc.).
- Subscription status: Your current plan (free, single, basic, or pro) and related billing metadata managed by Apple.
- Usage data: Number of analyses performed, rate-limit counters, and timestamps.
- Crash diagnostics: If the app crashes, we collect diagnostic data via Sentry (app version, device model, and OS version). Personal-information collection in Sentry is disabled. We do not collect advertising identifiers, precise location, or browsing history.
Legal Basis for Processing (GDPR Article 6)
We process your personal data based on the following legal grounds:
- Contract Performance (Art. 6(1)(b)): Processing your uploaded contracts is necessary to provide you with the analysis service you requested.
- Legitimate Interest (Art. 6(1)(f)): We process certain data (rate-limit counters and crash diagnostics) to ensure security and reliability. We balance our interests against your rights and freedoms.
- Consent (Art. 6(1)(a)): Where we ask for it, we obtain your explicit consent before any optional processing. Submitting the waitlist form is such consent, given so that we can notify you when SignArmor becomes available on your platform.
2. How AI Processes Your Documents
Text extraction happens entirely on your device — the original contract file is never uploaded. The extracted text is sent to OpenAI's API for AI-powered review. OpenAI does not use data submitted through its API to train its models; per OpenAI's API data usage policies, API inputs may be retained for a limited period for abuse monitoring and are then deleted. Your contract text is never used to train AI models.
3. Data Storage
- Analysis results are stored in a Supabase-hosted PostgreSQL database (cloud infrastructure) and are retained until you delete your account.
- Contract files are never uploaded to our servers — they stay on your device. Only the extracted text is transmitted for analysis, and it is not stored after the analysis is generated.
- Authentication data is managed by Supabase Auth with industry-standard security practices.
4. Third-Party Services
We use the following third-party services to operate SignArmor:
- Supabase — Database and authentication.
- OpenAI (API) — AI-powered contract analysis.
- Apple — Sign-In with Apple for authentication and in-app purchase payment processing.
- Google — Google Sign-In for authentication on the web.
- Sentry — Crash and error diagnostics (app version, device model, OS version; no personal identifiers).
Each service has its own privacy policy. We recommend reviewing them for complete details.
5. International Data Transfers
Your data is primarily stored in the European Union — our database and backend are hosted in the eu-central-1 region. Contract text sent for AI analysis is processed by OpenAI in the United States. Such transfers rely on appropriate safeguards, including OpenAI's certifications and contractual commitments (Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework, as applicable).
6. Automated Analysis (GDPR Article 22)
The AI analysis is informational only and does not produce any legal or similarly significant automated decisions about you. A human contact is always available at support@signarmor.app for any questions about an analysis.
7. Your Rights (GDPR Articles 15-22)
If you are in the European Economic Area (EEA), you have the following rights:
- Right of access (Art. 15): Request a copy of all data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate data.
- Right to erasure (Art. 17): Request permanent deletion of your account and all associated data.
- Right to data portability (Art. 20): Export your data in a machine-readable JSON format.
- Right to restrict processing (Art. 18): Request that we limit how we use your data.
- Right to object (Art. 21): Object to processing of your personal data.
8. How to Exercise Your Rights
In the app: Go to Settings > Delete Account or Settings > Export Data.
By email: Contact support@signarmor.app. We will respond within 30 days.
9. Data Retention
- Analysis results are kept until you delete your account.
- Contract files are never uploaded to our servers, and extracted contract text is not stored after the analysis is generated.
- When you delete your account, all data (profile and analyses) is permanently and irrevocably erased.
- Waitlist entries are kept until you ask us to remove them — write to support@signarmor.app at any time.
10. Children's Privacy
SignArmor is not intended for users under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us immediately at support@signarmor.app.
11. Data Security
We implement industry-standard security measures including encrypted data transmission (TLS), encrypted storage, row-level security policies, JWT-based authentication (ES256), and rate limiting to protect your data.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will notify you through an in-app notification and update the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You have the right to request deletion of your personal information. You can do this directly in the app via Settings > Delete Account, or by emailing us.
- Right to Opt-Out: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise these rights, use the in-app controls or contact us at support@signarmor.app. We will respond within 45 days.
13. Contact
For privacy-related questions or requests, contact us at:
support@signarmor.app