Last updated: September 25, 2026
Privacy Policy
This policy explains what eSign Me does with your data. It describes how the app actually works, not how we would like it to sound.
In short
- The app scans, signs and exports documents on your device. Nothing is sent to us for that.
- Your signature is never stored on our servers.
- We store a document only when you send it to someone for signing — and we delete it on the schedule below.
- No accounts, no advertising, no cross-site tracking. We do collect product analytics — see below.
Working on your device
Scanning a page with the camera, capturing a signature, placing it on a PDF and exporting the result all happen on your iPhone. There is no server in that path. If you never send a document to someone else for signing, we receive nothing at all.
Your signature stays on your device. We don't upload it, we don't keep a copy of it, and we can't see it.
When you request a signature from someone
Sending a document for signature is the only feature that uses our servers. When you use it, we receive and store:
| What | Why | |---|---| | The PDF you send | So the other party can open and sign it | | The signed copy | So you can download the result | | File name and page count | Shown to the recipient and used in the invitation email | | Your name, if you set one | Shown to the recipient, so they know who is asking | | The recipient's email address, if you enter one | To send them the link | | A random request identifier | Generated on your device. It tells our servers which app a request belongs to, so that only you can see its status and download the signed copy. It is not your Apple ID and carries nothing from your iPhone — but it is stored in the same record as your name and the recipient's address, so we treat it as data linked to you | | A push notification token | To tell you when the document is signed, and when the signing link is about to expire or has expired | | An App Attest key | Generated by iOS on your iPhone the first time you send a document. We store its identifier and its public key so our servers can tell a genuine copy of the app from a script; verifying it involves Apple. It says nothing about you or about who owns the iPhone, and we keep it for as long as the app stays installed | | The signing link's token, status and timestamps | To run the signing flow: opened, signed, downloaded |
The recipient's signature is not stored. When they sign in the browser, the image of their signature is sent to our server, used once to write it into the PDF, and discarded. It is never written to our storage or our database.
We do keep your document — and here is for how long
While a signing request is open, your document is stored on our servers. Anyone who has the signing link can open it, so treat the link as confidential.
- The signing link expires after 7 days.
- The original is deleted once the document is signed.
- If nobody signs it, the original is deleted when the link expires.
- The signed copy is deleted once you have downloaded it — at the earliest an hour after it was signed. If nobody ever downloads it, it is deleted after 90 days.
Deletion of expired files runs as a scheduled job once a day, so a file is removed at the first run after its deadline rather than at the exact minute.
Two honest caveats. First, deletion removes the files. Some records stay in our database — the link token, the status of the request, timestamps, the recipient's email address and your name — so we cannot say that everything about a request disappears. Second, we run this on ordinary cloud infrastructure and cannot promise that a deletion never fails; we can only tell you what the system does when it works as designed.
What we do not collect
- No accounts. There is no sign-up, and we hold no credentials for you.
- No IP address. We don't store it. We do record your browser, OS and device type — that's how we find out which browsers fail to open a document, so we can fix it.
- No advertising. No ad identifiers, no ad networks, no profiling, and we never sell or share data for advertising.
- No cookies for tracking.
Product analytics
We measure how the product is used, so we can see where it breaks and what to fix. We use PostHog, hosted in the European Union.
In the app, we record events such as: a document was added (and whether it came from the camera, your photos or Files), a signature was placed, a PDF was exported, a signature was requested, a signed document came back. These events are counted under a second random identifier, generated on your device for analytics only. It is deliberately separate from the request identifier above, and we do not link the two: your analytics history is not connected to your name, to the documents you send, or to who you send them to.
Every event from the app also carries what the analytics SDK attaches by default — your iPhone model, its iOS version, the app version, the screen size, and whether the build came from TestFlight — together with how the app was installed and the date you first opened it.
On the signing page, we record events such as: the page opened, the document failed to render, a signature was captured, the signature was submitted, a copy was downloaded. The signing page sets no cookies, builds no profile, and your IP address is not stored.
On our website (esignby.app), we count page views — the page, the site that sent you, the campaign in the link, and your browser and device type — and taps on the "Download on the App Store" button. The website sets no cookies and stores nothing in your browser. To tell visits apart, PostHog computes a one-way hash of your IP address and browser details on its servers, mixed with a random value that changes every day and is deleted once that day is processed — so the same visitor looks new the next day, and we do not store your IP address.
We never send the contents of your document, its file name, an email address, or the image of a signature as part of this. We do not record your screen, and we do not use this data for advertising or share it with advertisers.
Companies that process data for us
We use six service providers. They process data on our instructions, for the purposes described above:
- Railway — hosting for the website and the signing page.
- Vercel — standby hosting, used if the main host is unavailable.
- Supabase — database and file storage for documents in a signing request.
- Apple — push notifications to your device (APNs), and App Attest, which confirms that a request comes from a genuine copy of the app.
- Resend — sending the invitation email, when you provide a recipient's address.
- PostHog — product analytics, hosted in the European Union.
Your rights
You can ask us what we hold about you, ask for it to be deleted, or ask us to correct it. Write to support@esignby.app and we will do it.
Because there is no account, we usually need something to locate your data — for example the signing link, or the email address the invitation was sent to.
If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your local data protection authority.
Children
eSign Me is not intended for children. You must be at least 13 years old to use it, or at least 16 if you are in the European Economic Area or the United Kingdom.
Changes to this policy
If we change how we handle data, we will update this page and the date at the top. Where the change is significant, we will say so in the app.
Who we are
eSign Me is operated by Dmitrii Kholodov.
Questions about this policy, or about your data: support@esignby.app.