Sigan.beta

What we collect, where it goes, how long we keep it

Only what Sigan actually stores. What we do not collect is listed too.

Effective · 2026-08-20

01

What we collect

Account — the email address and account identifier from your Google sign-in. Display name, handle, and bio are values you write yourself.

Recorder — pen coordinates, pressure, tilt, and timing while you draw; the hash of the work file you designate; undo counts; the name and last-seen time of a connected device. For troubleshooting we also receive the app version, operating system, and error messages.

Web visits — the paths you visit and where you came from (referrer, campaign tags). We do not store IP addresses — we keep only a short hash made from the IP, browser string, and that day's date, which tells us whether two visits were the same person on the same day.

Community — the posts, comments, and reactions you leave, reports you file, and your block list.

Enquiries — what you send us, and a reply address if you provide one.

Payments — subscription state and identifiers from the payment provider. Card numbers never reach us; the provider handles them directly.

02

What we do not collect

  • What you type — we count only how many times undo/redo was pressed
  • Your full screen or other applications — we do not look outside the drawing app
  • Raw IP addresses
  • Original artwork files — only a downscaled copy you attach yourself is uploaded
  • Card or bank details
03

What we use it for

To issue and verify certificates, to show you your own records, to find and fix faults, to handle payments and plans, and to act on reports. We do not sell it to third parties for advertising.

04

Where it goes

We use the services below to run Sigan. Their servers may be outside your country.

  • Supabase — database, file storage, authentication
  • Vercel — web hosting
  • Google — sign-in (OAuth)
  • Anthropic — generating the AI coach and retrospectives. What we send is numeric measures and notes you wrote yourself; artwork files and email addresses are not sent (each card states what it sends)
  • Paddle — payment processing
  • An email server — invitations, and community notifications only if you turn them on (one email a day carrying how many comments arrived and where — never who wrote what). Off by default; you can turn it off at any time in settings
  • OpenTimestamps — anchoring a certificate hash in time. Only the hash leaves; no artwork or personal data
  • Open-Meteo — weather records. Only coordinates and a date are sent, and they are not tied to a user
05

How long we keep it

Records, certificates, and community posts are kept for as long as you use the service, and deleted when you delete them.

Web visit logs are removed after 90 days; after that only daily totals remain, from which no individual can be identified.

Reports are kept after they are handled, so that repetition can be seen. Payment records are kept for the period the law requires.

06

You decide what becomes public

By default your records are yours alone. Five paths lead outward and every one can be switched off in Settings: works you publish, a public profile (display name, handle, bio), taking part in the ranking, group sharing, and a status marker in your groups (visible only to members of your own groups — “Drawing now” while your recorder uploads work, “Recorder on” when it is merely running). It never shows what or how much you drew, and other members never see a time: it is one of three states (drawing, on, nothing). Posts you leave in the community are on a public page and can be seen by people who are not logged in.

The anonymous all-user averages also mix in figures from works you kept private — without names or work details.

07

Your rights

You may access, correct, and delete your information, and withdraw consent. Most of it you can do on screen (deleting works, visibility, ranking, profile, unblocking). For account deletion or anything else, write to us at the address below.

For support, a staff member may open your journal read-only; your rate and estimates are not queried in that mode.

08

Children

Children under 14 may not use the service or post in the community without the consent of a legal guardian.

09

How we keep it safe

Sensitive tables are locked so that only the server can open them, never the browser directly. Certificates are linked by a hash chain, so a later substitution shows. Even so, we cannot promise perfect safety; if something goes wrong we will tell you.

10

Changes · contact

If this policy changes we will say so here, with the date it takes effect. For anything about your data, write to hello@sigan.app and we will reply as soon as we have read it.

Terms of Service