Privacy Policy

What we collect, why, and how to get rid of it.

Last updated: 10 September 2026

The short version

  • Signerva reads your mailbox so it can show you your email, summarise threads, and tell you who is still waiting on a reply.
  • We never use your email content to train AI models — not ours, and not our providers'.
  • We never sell your data, and we never use it for advertising.
  • Signerva does not send email on your behalf unless you approve it, or unless you deliberately turn on an automation that says otherwise.
  • Disconnect a mailbox and we delete its contents from our systems within 30 days.

The rest of this page is the detail behind those five statements.

1. Who we are

Signerva is operated by ANTYPAS WEB SOFTWARE DESIGN SERVICES - FZCO, trading as Signerva, of IFZA Business Park, Building A2, Dubai Silicon Oasis, Dubai, UAE. We are the data controller for the information described here.

For anything in this policy, write to privacy@signerva.com.

2. What we collect

2.1 Account information

Your name, email address, authentication credentials, workspace and team membership, role, and preferences. If you subscribe to a paid plan, our payment processor collects your billing details — we store a customer reference and subscription status, not your card number.

2.2 Mailbox data from Google

When you connect a Google account, we access and store the contents of that mailbox: message headers, message bodies, thread structure, participants, labels, and metadata about attachments (filename, type and size). Signerva stores this so that your inbox loads quickly and so that follow-up detection can look across your history rather than only at what arrived today.

We store your Google refresh token so we can keep your mailbox in sync without asking you to sign in repeatedly. It is encrypted, held only on our servers, and never sent to your browser.

2.3 Usage and diagnostic data

Which features you use, when you signed in, error reports, and performance data. We configure our diagnostic tooling to exclude message bodies, subjects and participant addresses. If a bug report would require us to look at the contents of a specific message, we ask you first.

3. How we use Google user data

Signerva requests the narrowest set of permissions that lets the product work. Here is every scope we ask for and what it is for:

PermissionTierWhy Signerva needs it
openidBasicEstablish that the sign-in belongs to you.
https://www.googleapis.com/auth/userinfo.emailBasicIdentify which mailbox address has been connected, so it can be labelled correctly in your workspace.
https://www.googleapis.com/auth/gmail.modifyRestrictedRead your messages and threads to build your inbox, summaries and follow-up detection; apply labels, archive and mark as read when you ask; and create and send drafts that you have approved. It does not permit permanently deleting your mail.

We deliberately do not request full-account access (https://mail.google.com/), because that would let Signerva permanently delete your mail. Nothing in the product needs that, so we do not ask for it.

4. AI processing

Summaries, action items, priority suggestions and draft replies are produced by sending parts of your email to an AI model provider that processes it on our behalf. This is worth being precise about, because it is the part people most want to understand.

  • We minimise what is sent. Quoted reply history, signature blocks, legal disclaimers and tracking markup are stripped before transmission. We send the part of the conversation needed to answer the question at hand, not your whole mailbox.
  • We cache results. Analysis is keyed to the content it was derived from, so unchanged conversations are not sent repeatedly.
  • Your content is not used for training. Our agreement with the provider prohibits using your data to train or improve their models, and we will not enter an agreement that permits it.
  • You can see what it costs and turn it off. AI usage is reported in your workspace, and AI features can be disabled per workspace.

5. Who else processes your data

We use a small number of sub-processors, each contractually bound to protect your data and to process it only on our instructions. The current list, with what each one receives, is published at Sub-processors. We will update that page before adding a new one.

We do not sell your personal data. We do not share it with advertisers. We may disclose data if legally compelled to, and where we are permitted to tell you, we will.

6. Where your data is stored

Customer data is stored in the European Union (Supabase, eu-central-1). Some sub-processors operate globally, so data may be processed outside that region in transit; those transfers are covered by the contractual protections described above.

7. How long we keep it

DataRetained for
Mailbox content (messages, threads, attachment metadata)While the mailbox is connected, then deleted within 30 days of disconnection or account closure
OAuth tokensRevoked and deleted immediately on disconnection
AI analysis and cached summariesDeleted with the content they were derived from
Encrypted backupsRolling 35 days
Audit logs (who did what, and when)12 months, retained for security and accountability
Billing recordsAs required by applicable tax and accounting law

8. Deleting your data

You can remove your data at any time, without contacting us:

  • Disconnect a mailbox in your workspace settings. This revokes our access token with Google and queues that mailbox's content for deletion.
  • Delete your account in your personal settings. This removes your profile, mailboxes and their contents.
  • Revoke access from Google directly at your Google account permissions page. Signerva detects the revocation, stops syncing, and deletes the stored content on the same schedule.

Deletion is a hard delete, not a hidden flag. Copies persist only in encrypted backups until those age out, and in audit logs, which record that an action occurred without retaining the message content it acted on.

9. How we protect it

Our security practices are described in detail on the Security page. In summary: data is encrypted in transit and at rest; OAuth tokens are encrypted with a key held outside the database; access is isolated per workspace and enforced by the database itself as well as the application; and every consequential action is written to an append-only audit log.

No system is perfect. If we discover a breach affecting your data, we will notify you and the relevant authorities as required by law, and tell you what happened and what we did about it.

10. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, to object to certain processing, and to complain to a supervisory authority. Signerva provides self-service access, export and deletion in the product; for anything else, write to privacy@signerva.com and we will respond within 30 days.

11. Children

Signerva is a business product and is not directed at anyone under 16. We do not knowingly collect their data.

12. Changes to this policy

If we change this policy in a way that materially affects how we handle your data, we will tell you in the product and by email before the change takes effect. Past versions are tracked in our public changelog.

13. Contact

Privacy: privacy@signerva.com
Security: security@signerva.com
Support: support@signerva.com

ANTYPAS WEB SOFTWARE DESIGN SERVICES - FZCO
IFZA Business Park, Building A2, Dubai Silicon Oasis, Dubai, UAE