SignaCoreBack to SignaCore

Privacy

Clear handling for the information behind every agreement.

This policy describes the information SignaCore currently processes to provide electronic signing, document preparation, account access, billing, and delivery.

Important security boundary: SignaCore encrypts persistent files and sensitive database values, but it is not a zero-knowledge service. The application must briefly decrypt documents to detect fields, render authorized pages, flatten signatures, and deliver completed PDFs. Infrastructure administrators who control the application and encryption key may therefore have technical access.

Who operates SignaCore

SignaCore is operated by Se7en Inc. References to "SignaCore," "we," or "us" mean Se7en Inc. in this policy.

Privacy questions and requests can be sent to info@mysignacore.com.

Information we process

  • Account information: email address, display name, account type, password hash, verification status, and account timestamps.
  • Social sign-in information: a provider identifier and email or name returned by Google or Apple when you use those services. Provider identifiers and emails are encrypted or hashed for storage and account matching.
  • Workspace information: organization name, membership, role, invitations, subscription status, and administrator activity.
  • Document and signing information: uploaded PDFs, document metadata, configured fields, signer email addresses and names, entered values, signature images, signing status, timestamps, IP addresses, user agents, and the completed PDF.
  • Billing information: Stripe customer, price, subscription, and webhook identifiers and billing status. SignaCore does not receive or store full payment-card numbers.
  • Technical information: session cookies, request metadata, security events, and information needed to operate and protect the service.

Why we use it

  • To create accounts, authenticate users, verify email ownership, and provide signer OTP access.
  • To detect PDF fields, show authorized previews, collect signatures, flatten completed PDFs, and maintain document history.
  • To send account, invitation, signing, OTP, correction, and completion notifications that users request through the service.
  • To manage organizations, permissions, plan limits, subscriptions, invoices, and support requests.
  • To prevent abuse, investigate security events, enforce these terms, and comply with legal obligations.

Protection and access

Persistent PDFs, signature images, and selected sensitive values are protected with authenticated Fernet encryption. Email hashes are used where the service needs to match an address without querying encrypted text directly. Passwords and OTPs are stored as one-way hashes. HTTPS/TLS protects data in transit.

Access is limited by account, organization membership, signer verification, and administrator permissions. Workspace administrators can retrieve documents belonging to their authorized workspace. A signer receives only the assigned signing context after verifying the email link with an OTP.

Temporary plaintext files can exist inside the private service runtime while an operation is being completed and are removed after the operation. No online service can guarantee that every transmission, endpoint, or device is risk-free.

Service providers

We share only what is needed with providers that help us operate SignaCore, including configured email delivery, Stripe for billing, Google or Apple when you choose social sign-in, and the self-hosted infrastructure used to run the application and database. Providers may process information under their own terms and privacy policies.

SignaCore does not sell document contents or signer information for advertising. The current service does not use document contents to train AI models. Any future AI feature must disclose its provider, data flow, retention, and controls before document content is sent to a model.

Retention and deletion

Completed and source documents remain encrypted on server storage so authorized workspace users can access the workflow record. The current product does not promise automatic deletion or provide a universal self-service erasure control. Workspace administrators control the operational lifecycle, including voiding documents; deletion and retention schedules should be agreed and documented for each deployment.

To request access, correction, or deletion of personal information, contact info@mysignacore.com. We may need to verify the request and retain information required for security, legal, accounting, or dispute records.

Cookies and communications

SignaCore uses necessary session and security cookies to keep authenticated flows working. It does not use document contents for behavioral advertising. Transactional email delivery may generate provider-level delivery, bounce, and complaint records.

Updates

We may update this policy when the service, providers, or legal requirements change. The effective date will be updated on this page. Material changes should be communicated through the service or email where appropriate.

Last updated: September 17, 2026