Privacy Policy
Effective Date: January 1, 2025 Last Updated: January 1, 2025
SignRoad ("we," "our," or "us") operates the SignRoad mobile application (the "App"). This Privacy Policy explains how we collect, use, and protect your information.
1. Information We Collect
Account Information
- Email address: Used for authentication (magic link sign-in) and account recovery.
- Display name: Optional, used for personalization within the App.
- Authentication provider ID: If you sign in with Apple or Google, we receive a unique identifier from that provider. We do not receive your password.
Practice Data
- Sign observations: Records of signs you notice, including timestamps and optional notes.
- Receipts: Generated artifacts of your sign observations.
- Letters: Content you write to your future self, stored encrypted until delivery.
- Mood entries: Daily mood selections (stored as anonymous enumerated values).
- Companion selection: Your chosen companion character.
Technical Data
- Device information: Device model, operating system version, and app version (for crash reporting).
- Error logs: Anonymous crash reports sent to Sentry for app stability.
- Usage analytics: Anonymous aggregate data about which features are used (no individual tracking).
2. Information We Do NOT Collect
- Location data
- Contacts or address book
- Browsing history
- Health or fitness data
- Financial information (purchases handled entirely by Apple/Google)
- Photos (processed on-device; uploaded to your account storage only with your explicit action)
3. How We Use Your Information
- To provide and maintain the App's core practice features
- To authenticate your account
- To deliver letters at the scheduled time
- To generate and store your receipts
- To improve app stability through anonymous crash reporting
- To send transactional emails (letter delivery, account security)
We do NOT use your data for: - Advertising or ad targeting - Selling to third parties - Profiling or behavioral prediction - Social features or comparison with other users
4. Data Storage and Security
- All data is stored in a Postgres database hosted on Supabase (US-East-1 region).
- Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Authentication uses industry-standard JWT tokens with ES256 signing.
- Photos and receipt images are stored on Cloudflare R2 with access-controlled URLs.
5. Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database and authentication | Account data, practice data |
| Cloudflare R2 | File storage | Photos, receipt images |
| Sentry | Error monitoring | Anonymous crash reports |
| Apple/Google | In-app purchases | Transaction data (handled by platform) |
We do not share your personal data with any other third parties.
6. Data Retention
- Your account data is retained for as long as your account is active.
- Upon account deletion, all personal data is permanently removed within 30 days.
- Anonymous crash reports and aggregate analytics may be retained for up to 12 months.
7. Your Rights
You have the right to: - Access your data (request an export via support@signroad.com) - Delete your account and all associated data (in-app or via support@signroad.com) - Correct your account information (in-app profile settings) - Withdraw consent for optional data collection at any time
For California Residents (CCPA)
We do not sell personal information. You have the right to know what data we collect and to request deletion. Contact support@signroad.com.
For EU Residents (GDPR)
Our legal basis for processing is contract performance (providing the service you signed up for) and legitimate interest (app stability monitoring). You have the right to data portability, rectification, and erasure. Contact support@signroad.com.
8. Children's Privacy
SignRoad is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy in the App and updating the "Last Updated" date above.
10. Contact Us
For privacy questions or data requests:
- Email: support@signroad.com
- Web: https://signroad.com/support