SnapNSign← App

Privacy Policy

Last updated: 1 October 2026

This Privacy Policy explains how SnapNSign (“we”, “us”), operated by BETA-B (the data controller), handles information when you use the SnapNSign web app at snapnsign.com (the “Service”). Contact: support@snapnsign.com.

1. Our approach in short

  • Documents are encrypted end-to-end in your browser (AES-GCM-256) before they leave your device. The decryption key is part of the share link after the “#” sign and is never sent to our servers.
  • Our server only relays the encrypted file between sender and signer. It is deleted as soon as the sender downloads the signed copy, and in any case no later than 48 hours after upload.
  • Your documents, keys and history are stored only on your device. An account is optional: it is only needed to buy and use paid credits and to sync them across devices. The account stores only your email address and your credit balance/purchase history — never documents. There is no advertising and no tracking cookies.

2. Information we process

  • Encrypted documents. Ciphertext uploaded by the sender and by the signer. We cannot read it.
  • Technical metadata. A random document ID, a random sender token, creation and expiry time, whether the document was signed, and file size.
  • Optional account data. If you sign in: your email address, account creation and last sign-in time, your free-send counters and credit balance, and a credit history (purchases and spends with the amount, the number of pages, a random document ID and the time — never document content, names or file names).
  • Sign-in codes and sessions. One-time sign-in codes are stored only as a keyed hash, expire after 10 minutes and are deleted after 5 wrong attempts. Your session is kept in a strictly necessary, HttpOnly, secure cookie (sns_session); on the server only a hash of the session token is stored.
  • Abuse protection. To prevent abuse of sign-in and uploads we keep short-lived counters keyed by IP address and by email address (rate limits), and we use Cloudflare Turnstile on the sign-in form, which may process device and browser signals to tell humans from bots.
  • Connection data. Like any website, our hosting provider processes IP addresses and request data (e.g. browser type) to deliver the Service and protect it from abuse. These logs are short-lived.
  • Aggregated analytics. We may use privacy-friendly, cookieless analytics (Cloudflare Web Analytics) that report aggregated page statistics without identifying you.

3. Information inside documents

When a document is signed, the signer’s drawn signature, the optional name they type, the signing time, the browser’s user-agent string and cryptographic hashes are embedded into the PDF and an audit page. This information is part of the encrypted document and is visible only to the sender and the signer.

4. Data stored on your device

The app stores documents, encryption keys, the list of sent and signed documents, your credit balance (or a cached copy of your account balance), language and app-lock settings in your browser’s storage (IndexedDB / localStorage). You can delete it at any time by removing documents in the app or clearing the site data in your browser. We cannot access or recover this data.

5. Purposes and legal bases

We process the information above to provide the Service you request (performance of a contract) and to keep it secure and working (legitimate interests). Where required, we rely on your consent.

6. Service providers

We use Cloudflare, Inc. for hosting, content delivery, storage of encrypted files and account data (Cloudflare D1 database), security and bot protection (Turnstile). Sign-in codes are delivered by email through Resend (Plus Five Five, Inc.), which receives your email address and the message for that purpose. When paid credits become available, payments will be processed by Paddle.com as merchant of record (Paddle handles payment details, e.g. cards or PayPal, and we do not receive your full payment data); we will update this policy before that happens. To show prices in your local currency we use the country your request comes from (as determined by Cloudflare from your IP address); it is not stored. We do not sell personal information.

7. Retention

  • Encrypted files and their metadata: deleted after the sender downloads the signed copy, otherwise automatically after 48 hours.
  • Account data (email, credits, credit history): until you delete your account — in the app under Account → “Delete account”, or on request. Sessions expire after 45 days of the cookie lifetime; used or expired sign-in codes and rate-limit counters are deleted automatically within a day.
  • Records of purchases may be kept longer where tax or accounting law requires it.
  • Server logs: kept only as long as needed for security and operations.
  • On-device data: until you delete it.

8. International transfers

Our providers may process data in countries other than yours. Where required, transfers are protected by appropriate safeguards such as Standard Contractual Clauses.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete or restrict the processing of your personal data, to object, and to data portability, as well as the right to lodge a complaint with a supervisory authority. Because accounts are optional and we cannot decrypt documents, most data can be managed directly on your device; if you have an account you can see your credit history and delete the account in the app. For any request, contact support@snapnsign.com.

10. Children

The Service is not intended for children under 16.

11. Changes

We may update this policy. We will change the “Last updated” date and, for significant changes, notify users in the app.

12. Contact

BETA-B (operator of SnapNSign), support@snapnsign.com