Your practice data is yours. We built SignRoad to store as little as possible, protect what we do store, and give you clear controls. We do not sell personal data, run ads, or train third-party AI on your reflections.
What we collect
| Data | Why we have it | How long |
|---|---|---|
| Email and password hash | So you can sign in and recover your account. | While your account is active. |
| Signs, goals, letters, reflections, receipts | To run your practice and show it back to you. | While your account is active; 30-day grace after deletion. |
| Mood check-ins and habit entries | To personalize Whispers and track your practice. | While your account is active; 30-day grace after deletion. |
| Short-lived logs | Security and operational debugging. | 30 days; IP is truncated or hashed in longer aggregates. |
| Optional analytics | To understand which flows help people, only if you opt in. | 1 year; deleted when you opt out. |
What we do not do
- No ads and no ad trackers. We do not set advertising cookies or work with ad networks.
- No data sales. We do not sell, rent, or trade personal information.
- No AI training on your content. Your letters, goals, reflections, and sign context are not used to train third-party AI models.
- No sealed-letter access. Letters scheduled for a future date are unread by us and by the personalization engine until delivery.
- No dark patterns. We do not use streak punishments, fake scarcity, countdown timers, or guilt notifications to keep you in the app.
- No cross-web tracking. We do not follow you around the web or build an identity graph from outside sources.
How we protect it
- TLS for all traffic in transit.
- Encryption at rest via our hosting provider (Supabase).
- Passwords hashed with bcrypt.
- Two-factor authentication available for every account.
- Production database access restricted to a small, audited set of engineers.
- Rate-limiting and monitoring for automated attacks.
No security model is perfect. If you find a vulnerability, please email privacy@signroad.com. We do not take legal action against good-faith security research.
Your controls
- Export your data — Profile → Privacy → Download my data gives you a ZIP with everything (JSON + plain-English summary).
- Delete your account — Profile → Privacy → Delete my account, with a two-step confirmation and password re-auth. Deletion is immediate and cannot be undone.
- Manage cookies — The cookie banner on first visit, and Profile → Privacy at any time after.
- Opt out of marketing email — Every marketing email has an unsubscribe link. Operational email (security, receipts) cannot be turned off without closing the account.
Sub-processors
SignRoad runs on a small set of service providers: Supabase (database, auth, storage), Dodo Payments (web payments), RevenueCat (mobile subscriptions), Sentry (error reporting with PII stripped), Cloudflare / Vercel (hosting and edge protection), and Apple / Google (push notifications, if you opt in). The full list lives in our sub-processor list, and we email active users 30 days before adding or replacing any provider that processes personal data.
For EU / EEA / UK users
You have the rights you would expect: access, correction, deletion, portability, restriction, objection, and withdrawal of consent. You can exercise most of these in the app under Profile → Privacy, or by emailing privacy@signroad.com. More detail is in our GDPR Notice.
For business customers
If you want to offer SignRoad as a team or employee benefit, see Business Privacy & DPA Readiness for how to request a signed Data Processing Addendum and check the status of our EU representative.
Changes and questions
For material changes that affect your rights, we email the address on your account at least 30 days before the new version takes effect. Previous versions are preserved in the git history of our legal documents.
Questions? Email privacy@signroad.com or read the full Privacy Policy, Cookie Policy, and Terms of Service.
