Privacy Policy

Effective date: April 20, 2026

Plain English, first

Signroad is a place where you write down goals, log signs you see, and send letters to your future self. The whole product only works if you trust us with that content. This page explains, in plain language, what we collect, why, and how we handle it.

If any of this surprises you, read the full text. If the full text contradicts the summary, the full text wins — but we write them so that does not happen.


1. Who we are, what this covers

This Privacy Policy describes how SignRoad ("Signroad", "we", "us", "our") handles personal information in connection with the Signroad app, website at signroad.com, and related services (together, the "Service"). Our contact for privacy questions is privacy@signroad.com.

2. Information we collect

2.1 Information you give us

2.2 Information we collect automatically

2.3 Information from third parties

2.4 What we do not collect

3. How we use information

We use the information above to:

4. Legal bases (for EU/EEA/UK users)

If you are in the European Economic Area or the United Kingdom, we process your personal data under these legal bases:

More detail for EU/EEA/UK users, including your rights and how to exercise them, is in gdpr-notice.md.

5. How we share information

We do not sell personal information, and we do not rent it. We share it only with:

5.1 Service providers ("sub-processors")

Provider Purpose Where data lives
Supabase (database, auth, storage) Runs our database, handles passwords and sessions, stores user content US / EU region (depending on project)
Dodo Payments Processes web payments Global (Dodo-controlled)
RevenueCat Mobile subscription management (iOS/Android) US
Sentry (when enabled) Error reporting with PII stripped US / EU
Resend Sends operational and optional product emails US
Cloudflare, Vercel, or equivalent Delivers the static frontend, DDoS protection Global edge
Apple, Google Delivers push notifications (if you opt in) Global

Each sub-processor is under a contract that requires them to process personal data only for the purposes we tell them to, with appropriate security safeguards. The full, up-to-date list is maintained in our sub-processor list. Business customers and partners can find DPA and EU-representative information in our business privacy page.

5.2 Legal requests

We disclose information when compelled by a valid legal order, and not otherwise. When the law allows, we notify the affected user before complying.

5.3 Corporate transactions

If Signroad is acquired or merges with another company, user information may transfer to the successor. If that happens, we notify you and honor the privacy commitments in this policy.

6. International transfers

We store data primarily in the United States and, for EU/EEA/UK users, in an EU region where available. When we transfer data out of your region (for example, to a sub-processor in the US), we rely on one of these safeguards: the EU-US Data Privacy Framework, Standard Contractual Clauses, the UK Addendum, or adequacy decisions. You can request a copy of the transfer safeguards used for a specific provider by emailing privacy@signroad.com.

7. Security

8. Data retention

9. Your rights

No matter where you live, you can:

Additional rights for EU/EEA/UK users (portability, objection, restriction, withdrawal of consent, complaint to a supervisory authority) are detailed in gdpr-notice.md.

California, Virginia, Colorado, and other US-state residents with specific privacy rights: email privacy@signroad.com with "State privacy request" in the subject. We verify the request, respond within the statutory window, and do not retaliate for exercising a right.

10. Children

Signroad is not directed at children under 16. We do not knowingly collect personal information from them. If we learn we have, we delete the account and the data. If you believe a child under 16 has created an account, email privacy@signroad.com.

11. Cookies and similar technologies

See the Cookie Policy. Short version: we use a small number of essential cookies to keep you signed in, and (only if you opt in) a single analytics cookie to help us understand how the app is used. No ad trackers.

12. Changes to this policy

We update this policy when the service changes materially. For material changes that affect your rights — for example, a new data category collected, a new sub-processor added, or a change to retention — we email the address on your account at least 30 days before the new version takes effect. Previous versions remain in the git history of this file for reference.

13. Contact

For privacy questions, data requests, or complaints:


Attribution

Adapted from Automattic's Legalmattic Privacy Policy template. Original and this adaptation are both licensed under CC-BY-SA 4.0.