Privacy Policy
Effective date: 28 July 2026.
TeamSigner is a team-approval tool. This policy explains what we collect, how we use it, who we share it with, and your choices. We do not sell your data, run third-party advertising, or use cross-app tracking SDKs.
What we collect
- Account identity from your sign-in provider (Google, Apple, or GitHub): your email address, name if provided, and a stable user identifier.
- Your public signing key(s) — one per device you register. We never receive or store your private key or 24-word recovery phrase; those are generated and kept only on your device.
- Service data you create: team memberships, actions, requests, approvals, and the activity/audit log for those.
- Device push tokens, so we can notify you of pending approvals.
- Technical logs (IP address, user agent, timestamps) generated when you use the service, kept short-term for security and diagnostics and rotated/deleted regularly.
How we use it
Solely to operate the service: to authenticate you, show your teams and requests, relay approvals to the webhook endpoints you configure, send notifications, diagnose errors, and prevent abuse. We respond to your support requests using your email. We do not use your data for advertising or profiling.
What we share with third parties
- Sign-in providers (Google, Apple, GitHub) — for authentication only.
- Our hosting provider (Hetzner, in the EU) — which stores the service data, including encrypted backups, on our behalf.
- Push notification services — when we notify you of a pending approval, the notification travels through Expo (in the United States) and then Apple's or Google's push service to your device. It contains your device's push token, the action's name, who raised the request, and any reason they typed. If you'd rather not have that leave our servers, turn notifications off for TeamSigner in your device settings — the app still shows pending requests when you open it.
- Your webhook endpoint — when a request reaches its threshold, we call the webhook URL you configured, sending the signed canonical message and the signers' public keys and signatures. You control that endpoint.
- Legal authorities — only in response to a valid legal order.
We do not share your data with advertisers or data brokers, and we do not sell it.
Where your data is stored
Service data (teams, requests, public keys, logs) is stored on our servers at Hetzner in the EU. Your private key and recovery phrase are stored only on your device, in the secure keychain (iOS Keychain / Android Keystore), and never transmitted to us.
Retention & deletion
We retain team and audit data for as long as your team exists. Deleting a team removes its actions, requests, and logs; removing a member revokes their access. You can delete your account from inside the app (Account → Delete account) or by emailing us — see below. We permanently remove your account and associated personal data within 30 days of such a request.
Your rights
You may request access to or a copy of your data, ask us to correct it, or delete your account. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your data-protection authority. To exercise any of these, contact us below.
Children
TeamSigner is a workplace tool and is not directed at children. It is not intended for anyone under 16, and we do not knowingly collect data from children.
Security
Private keys are generated and held only on members' devices. Our server stores only public keys. Webhooks are signed with a per-action secret so you can verify authenticity, and every member approval is a cryptographic signature you can verify against that member's public key.
Changes
We may update this policy; we'll change the effective date above and, for material changes, give notice in the app or by email.
Contact
Questions or requests: info@teamsigner.com.