Signatur Privacy Policy
Effective September 25, 2026
This policy explains what William Lafontaine, doing business as Signatur ("Signatur," "we," "us"), collects when you use Signatur, why we collect it, who else handles it, and how long we keep it. It covers the website at signatur.co, the web app at app.signatur.co, the Signatur Outlook add-in, and links inside Signatur signatures.
We don't sell personal data, we don't use it for advertising, and we don't track whether emails are opened.
Who this covers
- Account holders: people who sign in to Signatur.
- People managed by a team: people a team admin adds to Signatur by hand or by CSV import. They may never sign in.
- People who click links: anyone who clicks a tracked link in a Signatur signature.
What we collect
Account. Your email address and name. If you sign in with Google, your Google name, email address, and profile photo. Clerk, our sign-in provider, holds your password and records sessions, IP addresses, and browser details to keep accounts secure.
Signatures and profiles. The details entered for a signature: name, title, company, email, phone, mobile, website, office address, department, scheduling link, call to action, social links, disclaimer, certifications or licensing, custom text, and image choices. We store each saved signature, its earlier versions, and the HTML and plain text we generate from it.
Images. Headshots, logos, banners, and disclaimer images uploaded to Library: a processed PNG copy and each image's size, dimensions, and alt text. The file you upload is used only to make that copy and is deleted once it's processed.
Teams and people. Team name, members and their roles, and invitations, including the invited email address. People records a team adds: names, email addresses, profile details, department, and office. For CSV imports we keep the imported records, not the file.
Mailboxes. Where each signature is installed (manual copy, Gmail, the Outlook add-in, or Apple Mail), with the email address, status, last update, and any error. When a signature is synced or applied, we record checksums and character counts that show what was installed. We don't collect the contents of your email.
Activity history. A record of actions such as assigning a signature, connecting a mailbox, or sending an action link, with who did it and when.
Billing. Your plan, subscription status, billing period, and Stripe customer and subscription IDs. You enter card details directly with Stripe; we never see or store them.
Messages to us. Whatever you send when you email us.
How we use it
We use this data to:
- build, store, install, and sync your signatures, and run People, Mailboxes, Library, and Analytics;
- sign you in and keep accounts secure;
- bill paid plans;
- send emails you ask for, such as employee action links, and sign-in codes;
- troubleshoot, prevent abuse, and meet legal obligations.
If you're in the EU or UK, our legal bases are: providing the service you signed up for (contract), keeping it secure and preventing abuse (legitimate interests), your consent when you connect Gmail, and legal obligations such as tax records.
Images are public
Email clients load signature images from the web, so the images you upload are stored on our image host at assets.signatur.co, which serves files at public web addresses. Anyone who has an image's address can view it. Archiving an image removes it from Library, but the file stays at its address so signatures and emails that already use it keep working. Don't upload images you aren't comfortable making public.
Gmail
Signatur connects to Gmail only when you choose to connect it, or when you
complete a mailbox link from your team. It asks Google for one permission,
https://www.googleapis.com/auth/gmail.settings.basic, and uses it to:
- read your Gmail "send mail as" addresses to find your primary address;
- write your Signatur signature to that address, replacing the signature that was there;
- read the saved signature back to check that Gmail kept it intact.
This permission doesn't let Signatur read, send, delete, or search your email, and Signatur doesn't change any other Gmail setting.
What we store: your Google access and refresh tokens, encrypted with AES-256-GCM; your primary Gmail address; the permission Google granted; and sync results (status, time, errors, checksums and character counts of the signature we sent and the one Gmail saved, and whether tracked links survived). We don't store your other addresses or the signature we replaced.
How it's used and shared: Google user data is used only to install and check your signature. It isn't used for advertising, isn't sold, and isn't shared with anyone except the infrastructure providers that store and run Signatur for us. No one at Signatur reads it unless you ask us to, it's needed for security, or the law requires it.
Signatur's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting: Disconnecting Gmail in Mailboxes stops all syncing, revokes Signatur's access at Google, and deletes the stored tokens. If Google doesn't confirm the revoke, Signatur still deletes the tokens and tells you to remove Signatur from the third-party connections page in your Google Account (myaccount.google.com/connections), which you can also do at any time.
Outlook add-in
The add-in inserts your signature into messages you write in Outlook. It runs on Outlook's add-in platform and doesn't use Microsoft Graph, so Signatur gets no access to your Microsoft account or mailbox. Microsoft's privacy terms cover Outlook itself.
- Outlook lists the add-in's permission as reading and changing the current message, because inserting a signature changes it. The add-in only inserts the signature. It doesn't read message text, subjects, or recipients.
- When you complete a mailbox link from your team, the add-in reads the address you're sending from and sends it to Signatur to confirm the mailbox.
- You sign in through a Signatur window. The add-in keeps a session token, your name and email address, your chosen signature, and a copy of your latest signature (so it works offline) in Outlook's add-in storage on your device.
- Signatur's servers store only a one-way hash of the session token, the add-in's web origin, and when the session was created, last used, and expires. Sessions expire 14 days after sign-in. Signing out in the add-in ends the session and clears the add-in's storage.
- After inserting a signature, the add-in reports which version it inserted and whether it used HTML or plain text, so Mailboxes can show it's current.
Employee action links
A team admin can send someone a link to do one task: review their profile details, upload or confirm a headshot, or connect a mailbox.
- Each link is limited to one person and one task, expires after 7, 14, or 30 days (the admin chooses), and can be revoked. We store a one-way hash of the link, not the link itself.
- The admin can copy the link or have Signatur email it. Emails come from noreply@signatur.co, are sent through Resend, and contain the team name, the task, and the link. We record whether the email was sent. We don't track opens or clicks on these emails.
- Profile and headshot links work without a Signatur account. Submitted details update the person's record in the team's People. A submitted headshot is added to the Library of the admin who sent the link, and is public like other images.
- A mailbox link asks the person to sign in to Signatur, creating a login if needed, and confirm the mailbox through Google or the Outlook add-in. The mailbox counts as connected only if the address Google or Outlook reports matches the one the admin entered. We record the reported address, including when it doesn't match. Signing in doesn't give the person access to the team.
Link clicks
Links in a Signatur signature can be tracked so the sender can see which links get clicked. A tracked link points to a Signatur redirect address on signatur.co, which sends the visitor straight on to the destination.
Like any website, the redirect service receives the visitor's IP address. It uses it only to look up a country and network, then discards it. The IP address is never sent to Signatur's servers or stored. Signatur receives and stores only:
- which link was clicked, and when (each link belongs to a signature, a person, and an email address);
- the country;
- the network's number (ASN) and owner, such as an internet provider, mobile carrier, or company;
- a shortened, one-way hashed form of the browser's user agent;
- whether the click looks like a person, an email security scanner, a link preview, or a bot.
We don't know who clicked, and we don't try to find out. Click data is visible to the signature's owner and members of its team. Clicks are kept for 12 months, then deleted.
Signatur doesn't track email opens. It uses no tracking pixels and no read
receipts. Email (mailto:) and phone (tel:) links are never tracked.
Teams can report conversions, such as a booked meeting, back to Signatur to see which links led to results. Each team has its own signed token, and Signatur rejects conversion reports without it. A conversion holds its type, an optional value, the link or click it relates to, and any details the team includes.
Cookies and local storage
Signatur uses only the cookies needed to sign in and keep your session secure:
- Clerk's session cookies, set when you use the app, on signatur.co and its subdomains;
- a Signatur cookie that holds a one-time security code while you connect Gmail, which expires after 10 minutes.
Clerk checks new sign-ups with Cloudflare Turnstile to block automated accounts. Signatur has no analytics, advertising, or third-party tracking cookies or scripts. The Outlook add-in uses Outlook's add-in storage as described above.
Service providers
These companies handle data for us, each under its own privacy terms:
| Provider | What it does for Signatur | Data it handles |
|---|---|---|
| Clerk | Sign-in, sessions, sign-in emails | Email, name, photo, password, IP address, device details |
| Convex | Database and backend, hosted in the United States | Everything Signatur stores |
| Vercel | Hosts the web app | Web requests, including IP addresses; images and CSV files while they're processed |
| Cloudflare | Image storage and delivery (assets.signatur.co), link redirects, DNS, sign-up bot checks | Images, click requests |
| Stripe | Payments and the billing portal | Account email, billing name, payment details |
| Resend | Sends action-link emails | Recipient address and email contents |
| Gmail sync and optional Google sign-in | The signature we write to Gmail; your Google profile if you sign in with Google |
Other sharing
- Your team. Team owners and admins can see and manage the team's signatures, people, mailboxes, Library, and analytics.
- Where you send it. Signatures go to Gmail or Outlook when you sync or apply them, and out to recipients in the emails you send.
- Legal reasons. We disclose data when the law requires it, or to protect people, Signatur, or our customers from harm or abuse.
- Business transfer. If Signatur is sold or merged, data moves to the new owner under this policy.
Teams and the people they manage
When a team adds people to Signatur, the team decides what to enter and is responsible for having the right to do so. We handle that data on the team's behalf. If you're in a team's People and want your details changed or removed, ask the team's admin. You can also email us and we'll work with the team.
How long we keep data
- Account, team, signatures, people, images, activity history, and billing IDs: while the account is open. They're deleted when you ask us to delete your account.
- Link clicks and reported conversions: 12 months.
- Gmail tokens: until you disconnect Gmail or delete your account.
- Outlook add-in sessions: they expire 14 days after sign-in, or end sooner when you sign out.
- Action links: they expire after 7, 14, or 30 days. The record stays in the team's activity history.
- Cancelled plans: your data stays, and paid features lock at the end of the paid period.
- Payment records: Stripe keeps them as financial rules require.
Your choices and rights
- See and edit: most of your data (profile, signatures, People, Library) is editable in the app.
- Get a copy: email privacy@signatur.co and we'll send a copy of your data.
- Delete: email us from your account's address. We'll delete your account and its data within 30 days and confirm when it's done. If you own a team, we'll check with you about the team's data first. Deleted images stop loading in emails that used them.
- Gmail and Outlook: disconnect, revoke, or sign out as described above.
Depending on where you live, including the EU, the UK, and California, you may have the right to access, correct, delete, or port your data, or to object to or restrict how we use it. Email us to use these rights. We won't treat you differently for using them. In the EU or UK you can also complain to your data protection authority.
Security
- All Signatur traffic uses HTTPS.
- Gmail tokens are encrypted and are decrypted only on our servers when syncing.
- Outlook add-in sessions, employee action links, and team invitations are stored only as one-way hashes.
- Card details stay with Stripe.
- Only the people who run Signatur can access production data, and only to support you, secure the service, or meet legal obligations.
No system is perfectly secure. If a breach affects your data, we'll tell you as the law requires.
Where data is stored
Signatur's database runs in the United States. Our providers may process data in other countries. If you use Signatur from outside the United States, your data is transferred to and processed in the United States.
Children
Signatur is for people 18 and older. We don't knowingly collect data from children.
Changes
We'll post updates here with a new effective date. For significant changes, we'll email account holders before they take effect.
Contact
Signatur
22 Grand View Drive, Queensbury, NY 12804
privacy@signatur.co