Privacy Policy

Effective

Draft pending legal review. This describes what the application actually does today, traced from the code. It has not been reviewed by a lawyer, and the bracketed items below must be filled in before launch.

This policy explains what Signoff collects, why, who else sees it, and what you can do about it. It covers the Signoff website and application.

1. What we collect

Account data. Your email address and a password hash — we never store your password itself. We also record when your password last changed, and the date and version of the Terms and Privacy Policy you accepted at signup.

Workspace content. The test suites, test cases, runs, results, bug records and reports you create, plus your workspace's name and the membership list.

Integration credentials. If you connect Jira or GitHub, the token and configuration you supply. These are encrypted at rest with AES-256-GCM; the encryption key is held in our server environment, not in the database.

Text you paste for AI drafting. Diffs or specifications you submit to have test cases drafted. See section 3.

Usage data. Page views and page-performance measurements, collected via Vercel Analytics and Vercel Speed Insights. These are aggregated and cookieless — they do not set a tracking cookie and are not used to build a profile of you across sites.

Technical data. Your IP address is used transiently to apply rate limits on signup, login and password reset. Our hosting provider processes standard server logs.

We do not ask for or store payment card details. Card payments are disabled during the beta; if they are enabled later, Stripe handles card data directly and we never see the card number.

2. Why we use it

  • To provide the service: authenticate you, store your work, and show it back.
  • To send transactional email: signup verification codes, password resets, and email-change confirmations. We do not send marketing email.
  • To file issues in Jira or GitHub when you have asked us to.
  • To protect the service: rate limiting, abuse prevention, and debugging.
  • To understand which pages are used and whether they are fast enough.

We do not sell your personal data, and we do not use your workspace content to train AI models.

3. AI processing

When you use the "draft cases from a diff" feature, the text you paste is sent to Anthropic (the Claude API) to generate the draft, along with our instructions. The generated draft is returned to you for review and is not saved until you approve it.

Only what you paste is sent — not your other test cases, your integration tokens, or your account details. Do not paste anything you are not comfortable sending to a third-party AI provider. Anthropic's handling of API data is governed by their own terms and privacy policy.

4. Who else processes your data

We use these providers to run Signoff. Each one only receives what it needs.

Provider What it handles Where
Vercel Hosting, and cookieless analytics and performance metrics Global edge
Prisma Postgres The application database — accounts and workspace content Managed cloud
Resend Transactional email delivery (your address and the message) Managed cloud
Anthropic AI drafting of test cases, from text you paste (section 3) Managed cloud
Stripe Payment processing — disabled during the beta Managed cloud
Atlassian (Jira) / GitHub Issues we create at your request, using your token Your own account

We may also disclose data where we are legally required to, or where it is necessary to investigate a security incident or a breach of the Terms.

5. Public share links

You can publish a run report at a public link. Anyone with that link can view the report without signing in. The link is unguessable, but it is not protected by a password, and we ask search engines not to index it — that is a request crawlers honour, not a guarantee.

Only publish a report you are willing to have read by anyone who receives the link. You can revoke a share link from the run it belongs to.

6. Cookies

Signoff sets one cookie: a session cookie that keeps you signed in. It is essential to the service — without it you cannot stay logged in — and it is not used for advertising or cross-site tracking.

Our analytics are cookieless, so Signoff does not set advertising or tracking cookies at all.

7. How long we keep things

  • Account and workspace content: until you delete it, or until you close your account.
  • Unverified signups: the pending record expires 10 minutes after the code is sent and is deleted once used.
  • Password reset and email-change tokens: deleted once used or expired.
  • Usage analytics: retained in aggregate by Vercel under their retention policy; it is not tied to your account.

When you close your account we delete your account record and the personal workspace that belongs to it. Content in a shared workspace you did not own stays with that workspace. Backups may retain deleted data for a short period before rotating out.

8. Security

Passwords are hashed with bcrypt. Integration credentials are encrypted with AES-256-GCM. Verification codes and reset tokens are stored as hashes, never in plain text. Traffic is served over HTTPS, with a strict Content-Security-Policy and HSTS.

No system is perfectly secure, and we do not claim otherwise. If you find a security problem, please tell us at [add a security contact email before launch] rather than disclosing it publicly, and we will work with you on it.

9. Your rights

You can:

  • Access and correct your email address and workspace content from within the app.
  • Export your content — reports are shareable and printable; contact us if you need a fuller export.
  • Delete your account and its personal workspace.
  • Object or complain — contact us, and, depending on where you live, your local data protection authority.

Depending on your jurisdiction you may have additional rights (for example under the GDPR or the Philippines' Data Privacy Act) including portability and restriction of processing. Contact us and we will honour them.

To exercise any of these, write to [add a contact email address before launch].

10. International transfers

Our providers operate globally, so your data may be processed outside the country you live in. We rely on our providers' standard contractual protections for those transfers.

11. Children

Signoff is a tool for software teams and is not directed at children. Do not create an account if you are under [minimum age — commonly 16 or 18].

12. Changes to this policy

We may update this policy. Each version is dated, and the version in effect when you signed up is recorded on your account. Where a change materially affects how we handle your data, we will tell you rather than relying on you to re-read this page.

13. Contact

Questions, requests, or complaints: [add a contact email address before launch].

The data controller is [legal entity name and registered address].