Privacy Policy
Last updated: 2026. Plain-language draft — review before commercial use.
What we collect
Account identity from your sign-in provider (email, name, and a stable user identifier); your public signing key; your team memberships, actions, requests, approvals, and activity logs; and device push tokens. We never receive or store your private key or recovery phrase — those stay on your device.
How we use it
Solely to operate the service: authenticate you, show your teams and requests, relay approvals to the webhook endpoints you configure, and send notifications. We do not sell your data. We do not use third-party advertising or tracking SDKs.
What we send to third parties
When a request reaches its threshold, we call the webhook URL you configured, sending the signed canonical message and the signers' public keys and signatures. You control that endpoint.
Retention & deletion
We retain team and audit data for as long as your team exists. Deleting a team removes its actions, requests, and logs. Removing a member revokes their access.
Security
Private keys are generated and held only on members' devices (secure keychain). Our server stores only public keys. Webhooks are signed with a per-action secret so you can verify authenticity.
Contact
Questions: support@teamsigner.com