Legal
Privacy Policy
What we collect, why we collect it, and the controls you have — recorded plainly, the way a system of record should explain itself.
Last updated June 2026
This policy explains how AllSign collects, uses, and protects personal data when you use our websites, applications, and APIs — together, the service. The terms below are placeholder copy; a counsel-approved policy will replace them before general availability.
1. Data We Collect
We collect data you provide directly, data generated by your use of the service, and a limited amount of data from third parties you connect.
- Account data — name, email address, and authentication identifiers
- Workspace content — agreements, terms, comments, and attachments you create
- Signing metadata — timestamps, IP address, user agent, and verification events recorded in the audit trail
- Usage data — feature interactions, device and browser information, and diagnostic logs
- Integration data — the identifiers and content an integration you enable requires
2. How We Use Data
We use personal data to operate and secure the service, and for nothing that would surprise you. AI-assisted features read workspace content only within the permissions of the person or agent using them, and their actions are recorded in the audit trail like any other participant. We do not train models on your workspace content.
- Provide, maintain, and improve the service and its features
- Record signatures and maintain the integrity of audit trails
- Send transactional messages — invitations, signature requests, receipts
- Detect, investigate, and prevent abuse and security incidents
- Comply with legal obligations
3. Data Sharing
We do not sell personal data. We share it only with the parties below, and only to the extent needed to run the service.
- Workspace participants — the people and agents in the agreements you join
- Subprocessors — vetted vendors for hosting, email delivery, and support tooling
- Integrations you enable — under that integration's own terms
- Authorities — when legally required, with notice to you where permitted
4. Data Retention
Workspace content is retained while your workspace is active. Executed agreements and their audit trails remain exportable for ninety days after workspace deletion, after which they are permanently removed from our systems.
Diagnostic logs are retained for a shorter operational window and then deleted or anonymized.
6. Security
All data is encrypted in transit and at rest. Access within AllSign follows least-privilege, is logged, and is reviewed regularly. Audit trails are append-only — nobody, including us, can quietly edit a record.
7. Your Rights
Depending on your jurisdiction — including under the GDPR and CCPA — you may have the right to:
- Access a copy of the personal data we hold about you
- Correct inaccurate data or complete incomplete data
- Delete your data, subject to the retention rules above
- Export your data in a portable format
- Object to or restrict certain processing
8. Data Transfers
The service is hosted in regional data centers. Where data crosses borders, transfers rely on recognized safeguards such as standard contractual clauses. Self-hosted deployments keep all data within infrastructure you control.
9. Children's Privacy
The service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be announced in the service or by email at least thirty days before they take effect, and every version is kept available — like any other record worth keeping.
11. Contact
Questions, requests, or concerns about your data? Write to privacy@allsign.app and a person will answer.
12. Governing Law
This policy is governed by the laws of the jurisdiction in which AllSign operates. Disputes arising from this policy are subject to the exclusive jurisdiction of the courts in that jurisdiction.