Privacy policy

Version 2026-09-20.

1. Who is responsible

This service is run by the operator of this website.

When someone uses the service to send you a document to sign, that person or organisation (the "sender") decides what is sent, to whom, and how long it is kept. They are responsible for that use of your data, and this service acts on their behalf. Their name and email address are shown at the top of the signing page and in the email you received.

2. Quick sign keeps nothing

The Quick sign page works entirely in your browser. The PDF you choose, your signature and the signed result are never uploaded, and nothing about them is stored or logged by this service.

3. What is stored, and why

WhatWhyHow long
Account: name, email address, a hash of the password (never the password), when the account was created and last usedTo let you sign in and to contact you about your documentsUntil you delete the account
Documents you upload, and templates made from themTo show them to the people you ask to signUntil you delete them, or automatic deletion does (section 5)
Signers: the name and email address the sender enteredTo create a personal signing link and show progress to the senderAs long as the document
What signers place: signature picture, text, dates, check marksTo produce the signed PDFAs long as the document
The record of each signature and of the document's history: date and time, network (IP) address, browser descriptionSo that a signature can be attributed and the document's history shown; printed on the signing certificateAs long as the document
A saved signatureOnly if an account holder ticks "save for next time"Until they forget it or delete the account
Sending log: recipient address, kind of email, whether it was deliveredTo enforce daily sending limits and detect abuse90 days
Counters of failed sign-ins and rejected signups, by network addressTo block password guessing and bots3 days
Web server logs: network address, time, page requested. Signing links are not in them: the secret part of a link is never sent to the server as part of an address.Operation and securityAs set by the hosting, usually a few weeks

The documents' contents are not read, analysed, used for advertising or to train anything.

4. Cookies and other sites

One cookie is set, when you sign in to an account, to keep you signed in. It is necessary for that and is not used for anything else. People who only sign a document get no cookie. There are no analytics, no advertising and no social media components, and the pages load every script, font and style from this site alone.

5. Deletion

A signed PDF that someone has downloaded is theirs; deleting here does not reach it.

6. Who else handles the data

The data is stored on servers rented by the operator, and emails are delivered by an email delivery provider. They act on the operator's instructions. Data is not sold, and is not given to anyone else unless the law requires it.

7. Security

Connections are encrypted. Passwords are stored only as salted hashes. Signing and download links are secrets addressed to one person: anyone who has your link can act as you, so do not forward it. No system is perfectly secure; if you believe a link or an account has been misused, tell the sender and the operator.

8. Your rights

Depending on where you live, you may have the right to see the data held about you, to have it corrected or deleted, to object to its use, to receive a copy, and to complain to a data protection authority. Account holders can do most of this themselves on the Account page. If you were asked to sign a document, ask the sender first, since the document is theirs; you can also write to the operator.

9. Changes

When this policy changes in substance, the version date shown at the top changes with it.