SignLeaf

Privacy policy

Effective date: 10 September 2026

This policy covers the SignLeaf iPhone app and this website. The SignLeaf developer is responsible for the information we handle. Contact us about privacy or your data at arshpreet@billionweb.co.

Your documents and signatures

SignLeaf scans paper documents and cleans up photographed handwriting on your iPhone. Scanned pages, signature photos, cleaned signatures and initials, document names, text and dates you add, editable drafts and completed files are stored locally. SignLeaf does not upload this content to our servers, Firebase, RevenueCat or a third-party AI service. You do not need a SignLeaf account, and we do not provide cloud document storage or sync.

Camera access is requested when you use a camera feature. You can change it in iPhone Settings → Privacy & Security → Camera. For signature photos, the system photo picker shares only the images you select; SignLeaf does not request access to your entire photo library. If you share an output or save it to Files, the app or storage provider you choose receives that file and handles it under its own privacy terms.

Usage analytics

Usage analytics and crash reporting are enabled by default in the App Store app, including before a purchase. The current app has no in-app analytics or diagnostics switch. An earlier disabled preference, if already stored, is respected.

We use Google Firebase Analytics to understand app use, improve scanning and saving, and compare subscription offers. Information includes screens viewed, onboarding selections, preferred export format, camera-permission outcomes, editing actions, scan and save outcomes, page counts, processing times, sharing actions, purchase and restore outcomes, subscription status, and interactions with rating prompts. These are categories and measurements, not the contents of your documents or your written App Store review.

Firebase also processes app-instance identifiers, app and operating-system versions, device and language information, sessions and other automatically collected usage events. Google Analytics processes the connection's IP address to derive approximate location, such as country or city, and to operate its service. IP handling varies by region and service settings. SignLeaf does not request GPS or precise location access.

A randomly generated SignLeaf installation identifier is used to associate analytics with subscription records and offer assignment. Firebase's app-instance identifier is also shared with RevenueCat for this connection. These identifiers do not contain your name or email address, but they allow records about the same installation to be linked; they are not a promise of fully anonymous data.

Crash reports and reliability

Firebase Crashlytics processes crash traces, failure categories, app and operating-system versions, device state, installation and session identifiers, and diagnostic information to help us investigate failures. Pending reports can be sent when you next launch the app. Our custom reports use fixed error categories and exclude document contents, signature images, entered text, filenames, file paths and raw app error messages. This does not mean that no technical data leaves the device.

Read Firebase's privacy and security information and Google's explanations of IP handling in the EU, Switzerland and UK and outside those regions for more about these services.

Purchases and Apple Ads measurement

Apple processes App Store payments. RevenueCat processes purchase and transaction records, product identifiers, subscription and renewal status, trial eligibility, the SignLeaf installation identifier, storefront and currency information, device and operating-system information, last app activity, and the assigned subscription offer and assignment time. This supports purchase validation, subscription access, restores and subscription performance reporting. Neither SignLeaf nor RevenueCat receives your full payment-card details from an App Store purchase.

To measure whether Apple Ads brought an installation to SignLeaf, the app enables Apple's AdServices attribution through RevenueCat on launch. RevenueCat receives an attribution token and the attribution Apple makes available, which can include campaign, ad group and keyword information. This collection is separate from Firebase usage analytics and does not require you to buy a subscription.

SignLeaf does not collect the advertising identifier (IDFA), display third-party ads or use its app data to track you across other companies' apps and websites for targeted advertising. Firebase advertising storage, advertising user-data sharing and ad-personalization signals are disabled. Subscription and attribution services still process the information described above. See RevenueCat's privacy policy and Apple's privacy policy.

Storage, retention and deletion

Deleting local content or the app does not delete information already received by service providers, erase Apple's purchase history or cancel a subscription. Contact us to request deletion of information we can associate with you. We will explain any information we must retain and why.

Your privacy requests

Depending on applicable law, you may have rights to access, correct, receive a copy of or delete personal information, restrict or object to processing, withdraw consent where processing relies on it, or complain to your local data-protection authority. Email arshpreet@billionweb.co with the subject “SignLeaf privacy request” and describe your request.

We may need limited information to locate a subscription or installation record and verify your request. Because there is no SignLeaf login, your email alone may not identify app records. Do not send payment-card details, passwords, confidential documents or signature images. Sending a request does not itself change the app's collection setting. Stopping use of the app prevents new app usage events; information already collected remains subject to the retention and deletion rules above.

Support messages and this website

If you email us, we receive your email address, message and any attachments you choose to send. We and our email provider use them to respond and resolve your request. Prefer a description of the issue or a redacted example over an actual private document.

GitHub Pages hosts this website. We add no analytics scripts, advertising pixels, cookies, external fonts or third-party scripts to these pages. GitHub can process IP addresses and request information to serve and secure the website, as explained in the GitHub Privacy Statement.

Service providers and protection

We use the providers described in this policy to operate subscriptions, measure app use, investigate errors, host these pages and answer support requests. Providers processing information for us are required to protect it consistently with this policy and applicable privacy requirements, and to use it for permitted service purposes under their terms. Apple and services you choose when sharing also have their own relationship with you.

SignLeaf uses iOS app storage and data-protection mechanisms for local content. Apple, Google Firebase, RevenueCat, GitHub and our email provider may process service information outside your country; their privacy information describes their safeguards and international processing arrangements.

We process information to provide requested app and purchase services, operate and improve the app, respond to requests and meet legal obligations. The applicable legal basis depends on the information and your location, including performance of a requested service, legitimate interests where permitted, legal obligations, or consent where required. This policy does not treat your acceptance of the terms as consent to every form of processing.

Policy changes

We will update this page and its effective date when our practices change. Where required, we will provide additional notice or seek consent for a new use of personal information. You can reach this policy from Profile and the subscription screen in SignLeaf.