Privacy Policy
Effective date: April 20, 2026
Plain English, first
Signroad is a place where you write down goals, log signs you see, and send letters to your future self. The whole product only works if you trust us with that content. This page explains, in plain language, what we collect, why, and how we handle it.
- What we collect from you: your email and password (so you can log in), the things you write inside the app (signs, goals, letters, reflections), and basic usage data (what page you are on, when you opened the app). We do not collect contact lists, browsing history outside the app, or biometric data.
- Why we collect it: to run the service and personalize your Whispers. That is it. We do not sell personal data, and we do not use your reflections to train third-party AI models.
- Sealed letters: letters you schedule for a future date stay sealed until that date. Not even our personalization engine reads the body. The only thing it uses is that a sealed letter exists.
- Who else sees it: a short list of service providers (auth, payments, email, error reporting) that help us run the app. They are listed below.
- Your controls: you can export all of your data, delete your account, or turn off analytics cookies — all from Profile → Privacy.
- Where we keep it: on Supabase and our cloud providers, with TLS in transit and Supabase-managed encryption at rest.
If any of this surprises you, read the full text. If the full text contradicts the summary, the full text wins — but we write them so that does not happen.
1. Who we are, what this covers
This Privacy Policy describes how SignRoad ("Signroad", "we", "us", "our") handles personal information in connection with the Signroad app, website at signroad.com, and related services (together, the "Service"). Our contact for privacy questions is privacy@signroad.com.
2. Information we collect
2.1 Information you give us
- Account information — email address, a password you choose (hashed, never stored in plain text), and optional profile fields like display name, bio, location, birth date, and avatar.
- Content you create — signs you log, goals you write, letters to your future self, whispers you save, reflections, board items, habit entries, and anything else you type into the app.
- Support messages — if you email support@signroad.com, the message and any attachments.
- Payment information — if you buy a paid plan, our payment processor (Dodo Payments for web, or Apple/Google for mobile via RevenueCat) collects your payment details directly. Signroad stores the fact of the subscription, the plan, and the last four digits of the card, but not the full card number.
2.2 Information we collect automatically
- Log data — IP address, device type, operating system, browser, and request time, kept in short-lived logs (up to 30 days) for operational and security purposes. In logs stored longer than 30 days the IP is truncated or hashed.
- Usage data — which pages you visit inside the app, when sessions start and end, which buttons you tap. If you opt out of analytics cookies, we do not collect usage data beyond what is strictly needed to operate the service.
- Crash reports — if the app crashes, we collect a stack trace and device context. Personal identifiers (email, IP, and the body of letters, goals, reflections, and sign context) are stripped before the report is sent.
2.3 Information from third parties
- OAuth — if you sign in with Google or Apple, we receive your email, name, and an identifier from that provider. We do not receive your password.
- Push notifications — if you install the mobile app and allow notifications, Apple or Google gives us a device token so we can send you notifications. We do not receive your contact list.
2.4 What we do not collect
- We do not buy personal data from data brokers.
- We do not track you across the web.
- We do not use your reflections, letters, or goals to train third-party AI models.
- We do not access the content of a sealed letter before its delivery date.
3. How we use information
We use the information above to:
- create, authenticate, and protect your account, including checking a two-factor code when you have 2FA enabled;
- run the core manifestation loop: assign a daily sign, accept "I saw it" receipts, deliver letters on their scheduled date, and so on;
- generate your personalized Whisper by drawing on your past signs, goals, delivered letters, and reflections — and, for sealed letters, only the fact that one exists, never its contents;
- send you operational email (sign-in links, receipts, password resets, security alerts) and, if you opt in, product updates;
- detect and prevent fraud, abuse, and automated attacks;
- comply with legal obligations and enforce these terms.
4. Legal bases (for EU/EEA/UK users)
If you are in the European Economic Area or the United Kingdom, we process your personal data under these legal bases:
- Contract — to provide the service you signed up for.
- Legitimate interests — to secure the service, investigate abuse, and communicate operational matters. You can object to processing based on legitimate interests.
- Consent — for analytics cookies, marketing email, and anything else where we explicitly ask. You can withdraw consent at any time.
- Legal obligation — when the law requires it.
More detail for EU/EEA/UK users, including your rights and how to exercise them, is in gdpr-notice.md.
5. How we share information
We do not sell personal information, and we do not rent it. We share it only with:
5.1 Service providers ("sub-processors")
| Provider | Purpose | Where data lives |
|---|---|---|
| Supabase (database, auth, storage) | Runs our database, handles passwords and sessions, stores user content | US / EU region (depending on project) |
| Dodo Payments | Processes web payments | Global (Dodo-controlled) |
| RevenueCat | Mobile subscription management (iOS/Android) | US |
| Sentry (when enabled) | Error reporting with PII stripped | US / EU |
| Resend | Sends operational and optional product emails | US |
| Cloudflare, Vercel, or equivalent | Delivers the static frontend, DDoS protection | Global edge |
| Apple, Google | Delivers push notifications (if you opt in) | Global |
Each sub-processor is under a contract that requires them to process personal data only for the purposes we tell them to, with appropriate security safeguards. The full, up-to-date list is maintained in our sub-processor list. Business customers and partners can find DPA and EU-representative information in our business privacy page.
5.2 Legal requests
We disclose information when compelled by a valid legal order, and not otherwise. When the law allows, we notify the affected user before complying.
5.3 Corporate transactions
If Signroad is acquired or merges with another company, user information may transfer to the successor. If that happens, we notify you and honor the privacy commitments in this policy.
6. International transfers
We store data primarily in the United States and, for EU/EEA/UK users, in an EU region where available. When we transfer data out of your region (for example, to a sub-processor in the US), we rely on one of these safeguards: the EU-US Data Privacy Framework, Standard Contractual Clauses, the UK Addendum, or adequacy decisions. You can request a copy of the transfer safeguards used for a specific provider by emailing privacy@signroad.com.
7. Security
- All traffic is encrypted in transit using TLS.
- Data at rest is encrypted with keys managed by our hosting provider (Supabase). Signroad does not use end-to-end encryption — see the security architecture doc (
docs/architecture/security.md) for the reasons. - Passwords are hashed with bcrypt.
- Production database access is restricted to a small, audited set of engineers.
- Two-factor authentication (TOTP) is available for every account.
- We monitor for automated attacks and rate-limit sign-in attempts.
- No security model is perfect. If you become aware of a vulnerability, please email privacy@signroad.com; we do not take legal action against good-faith security research done under our responsible-disclosure practice.
8. Data retention
- Account and content — kept while your account is active.
- Account deletion — when you delete your account, we mark it for deletion, stop serving it to the app, and permanently remove it after 30 days. That delay exists so you can recover an account you deleted by mistake.
- Backups — included in encrypted backups for up to 35 days after deletion; the backups roll off on their own schedule.
- Logs — 30 days for operational logs; longer for aggregated analytics that cannot be linked back to a user.
- Legal holds — if we are required to preserve specific data by law, we do so until the obligation ends.
9. Your rights
No matter where you live, you can:
- Access a copy of your data — Profile → Privacy → Download my data delivers a ZIP with your boards (Vision, Proof, Messages to Myself), signs, goals, letters, sparks events, whispers history, and profile info, in both JSON and a plain-text markdown summary.
- Correct your data — most fields are editable in-app. Email privacy@signroad.com for anything you cannot change yourself.
- Delete your account — Profile → Privacy → Delete my account. Two-step confirmation, password re-auth, 30-day undo window.
- Opt out of analytics — the cookie banner on first visit, and the toggle in Profile → Privacy at any time afterwards.
- Turn off marketing email — every email has an unsubscribe link; this does not affect operational email you need to run your account.
Additional rights for EU/EEA/UK users (portability, objection, restriction, withdrawal of consent, complaint to a supervisory authority) are detailed in gdpr-notice.md.
California, Virginia, Colorado, and other US-state residents with specific privacy rights: email privacy@signroad.com with "State privacy request" in the subject. We verify the request, respond within the statutory window, and do not retaliate for exercising a right.
10. Children
Signroad is not directed at children under 16. We do not knowingly collect personal information from them. If we learn we have, we delete the account and the data. If you believe a child under 16 has created an account, email privacy@signroad.com.
11. Cookies and similar technologies
See the Cookie Policy. Short version: we use a small number of essential cookies to keep you signed in, and (only if you opt in) a single analytics cookie to help us understand how the app is used. No ad trackers.
12. Changes to this policy
We update this policy when the service changes materially. For material changes that affect your rights — for example, a new data category collected, a new sub-processor added, or a change to retention — we email the address on your account at least 30 days before the new version takes effect. Previous versions remain in the git history of this file for reference.
13. Contact
For privacy questions, data requests, or complaints:
- Email: privacy@signroad.com
- Postal: SignRoad, Privacy Team, 1309 Coffeen Avenue, Suite 1200, Sheridan, WY 82801, USA
- Data Protection Officer (EU): privacy@signroad.com
Attribution
Adapted from Automattic's Legalmattic Privacy Policy template. Original and this adaptation are both licensed under CC-BY-SA 4.0.