Privacy Policy

This policy explains what Signum collects when you use Signum, why we collect it, and the choices you have. It is maintained by Signum and is not a certification or third-party audit.

Last updated July 25, 2026

Who this policy covers

Signum serves two groups. Customers are the organizations and users who create workspaces, upload documents, and send them out. Recipients are the people who open a link to fill out or sign a document.

For content inside documents, the customer is the data controller and Signum is a processor acting on the customer's instructions. For account and billing data, Signum is the controller.

Information we collect

  • Account data — name, email address, workspace name, role, and authentication identifiers. Passwords are never stored in readable form.
  • Document content — the PDFs you upload, the fields you place on them, and the values recipients enter, including signature images and typed signatures.
  • Signing metadata — timestamps, signer email addresses, IP address and user agent captured at the moment of signing, and the event trail that makes a completed document defensible.
  • Billing data — plan, subscription status, and billing contact. Payment card details are handled by Stripe and never reach our servers.
  • Operational logs — error and access logs used to keep the service running and to investigate abuse.

How we use information

  • Provide the service: store your documents, render forms, route them to signers, and produce completed files.
  • Maintain the audit trail that proves who filled and signed a document and when.
  • Send transactional email such as signature requests, reminders, and account notices.
  • Bill for paid plans and enforce plan limits.
  • Secure the service, prevent abuse, and comply with legal obligations.

We do not sell personal information, and we do not use the contents of customer documents to train general-purpose AI models.

Automated field detection

When you use field detection, page images and extracted text from the document you chose are sent to our AI processing provider to locate fields. This happens only when you run detection, only for that document, and the provider processes the content solely to return the detection result. If your document contains regulated data and you would rather not use this feature, place fields manually — detection is always optional.

Sharing and subprocessors

We share data with the service providers below so that Signum can function. Each is bound by contractual confidentiality and security obligations.

ProviderPurposeLocation
Lovable Cloud / SupabaseApplication hosting, database, authentication, and file storageUnited States
StripeSubscription billing and, where enabled, payment collection at signingUnited States
AI processing provider (Lovable AI Gateway)Optional field detection and document understanding on uploaded PDFsUnited States

We also disclose information when required by law, and to a successor entity in the event of a merger or acquisition, subject to this policy.

Retention and deletion

Documents you delete move to Trash and are purged from primary storage after the retention window. Audit records are retained longer so completed documents keep a defensible history.

  • Deleted documents sit in Trash for 30 days before purge.
  • Audit events tied to completed documents are retained for up to 7 years.
  • Closing your workspace removes documents, fields, and responses on the schedule above.

Your rights and choices

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to certain processing. Customers can export or delete most content directly in the app. For anything else, or if you are a recipient asking about a document a customer sent you, contact privacy@admysterium.com. Requests about document content are forwarded to the customer who controls that document.

Security

Data is encrypted in transit with TLS and at rest by our hosting platform. Workspace data is isolated by row-level access rules, and document files are stored in private buckets reachable only through short-lived signed links. See the Security & trust page for details.

Children's privacy

Signum is a business tool and is not directed to children. Where a school or district uses Signum to process student records, the school directs that processing — see our compliance page.

Changes and contact

We will post material changes to this page and update the date above. Questions go to privacy@admysterium.com.