Last updated: 10 September 2026
The short version
- Signerva reads your mailbox so it can show you your email, summarise threads, and tell you who is still waiting on a reply.
- We never use your email content to train AI models — not ours, and not our providers'.
- We never sell your data, and we never use it for advertising.
- Signerva does not send email on your behalf unless you approve it, or unless you deliberately turn on an automation that says otherwise.
- Disconnect a mailbox and we delete its contents from our systems within 30 days.
The rest of this page is the detail behind those five statements.
1. Who we are
Signerva is operated by ANTYPAS WEB SOFTWARE DESIGN SERVICES - FZCO, trading as Signerva, of IFZA Business Park, Building A2, Dubai Silicon Oasis, Dubai, UAE. We are the data controller for the information described here.
For anything in this policy, write to privacy@signerva.com.
2. What we collect
2.1 Account information
Your name, email address, authentication credentials, workspace and team membership, role, and preferences. If you subscribe to a paid plan, our payment processor collects your billing details — we store a customer reference and subscription status, not your card number.
2.2 Mailbox data from Google
When you connect a Google account, we access and store the contents of that mailbox: message headers, message bodies, thread structure, participants, labels, and metadata about attachments (filename, type and size). Signerva stores this so that your inbox loads quickly and so that follow-up detection can look across your history rather than only at what arrived today.
We store your Google refresh token so we can keep your mailbox in sync without asking you to sign in repeatedly. It is encrypted, held only on our servers, and never sent to your browser.
2.3 Usage and diagnostic data
Which features you use, when you signed in, error reports, and performance data. We configure our diagnostic tooling to exclude message bodies, subjects and participant addresses. If a bug report would require us to look at the contents of a specific message, we ask you first.
3. How we use Google user data
Signerva requests the narrowest set of permissions that lets the product work. Here is every scope we ask for and what it is for:
| Permission | Tier | Why Signerva needs it |
|---|---|---|
openid | Basic | Establish that the sign-in belongs to you. |
https://www.googleapis.com/auth/userinfo.email | Basic | Identify which mailbox address has been connected, so it can be labelled correctly in your workspace. |
https://www.googleapis.com/auth/gmail.modify | Restricted | Read your messages and threads to build your inbox, summaries and follow-up detection; apply labels, archive and mark as read when you ask; and create and send drafts that you have approved. It does not permit permanently deleting your mail. |
We deliberately do not request full-account access (https://mail.google.com/), because that would let Signerva permanently delete your mail. Nothing in the product needs that, so we do not ask for it.
4. AI processing
Summaries, action items, priority suggestions and draft replies are produced by sending parts of your email to an AI model provider that processes it on our behalf. This is worth being precise about, because it is the part people most want to understand.
- We minimise what is sent. Quoted reply history, signature blocks, legal disclaimers and tracking markup are stripped before transmission. We send the part of the conversation needed to answer the question at hand, not your whole mailbox.
- We cache results. Analysis is keyed to the content it was derived from, so unchanged conversations are not sent repeatedly.
- Your content is not used for training. Our agreement with the provider prohibits using your data to train or improve their models, and we will not enter an agreement that permits it.
- You can see what it costs and turn it off. AI usage is reported in your workspace, and AI features can be disabled per workspace.
5. Who else processes your data
We use a small number of sub-processors, each contractually bound to protect your data and to process it only on our instructions. The current list, with what each one receives, is published at Sub-processors. We will update that page before adding a new one.
We do not sell your personal data. We do not share it with advertisers. We may disclose data if legally compelled to, and where we are permitted to tell you, we will.
6. Where your data is stored
Customer data is stored in the European Union (Supabase, eu-central-1). Some sub-processors operate globally, so data may be processed outside that region in transit; those transfers are covered by the contractual protections described above.
7. How long we keep it
| Data | Retained for |
|---|---|
| Mailbox content (messages, threads, attachment metadata) | While the mailbox is connected, then deleted within 30 days of disconnection or account closure |
| OAuth tokens | Revoked and deleted immediately on disconnection |
| AI analysis and cached summaries | Deleted with the content they were derived from |
| Encrypted backups | Rolling 35 days |
| Audit logs (who did what, and when) | 12 months, retained for security and accountability |
| Billing records | As required by applicable tax and accounting law |
8. Deleting your data
You can remove your data at any time, without contacting us:
- Disconnect a mailbox in your workspace settings. This revokes our access token with Google and queues that mailbox's content for deletion.
- Delete your account in your personal settings. This removes your profile, mailboxes and their contents.
- Revoke access from Google directly at your Google account permissions page. Signerva detects the revocation, stops syncing, and deletes the stored content on the same schedule.
Deletion is a hard delete, not a hidden flag. Copies persist only in encrypted backups until those age out, and in audit logs, which record that an action occurred without retaining the message content it acted on.
9. How we protect it
Our security practices are described in detail on the Security page. In summary: data is encrypted in transit and at rest; OAuth tokens are encrypted with a key held outside the database; access is isolated per workspace and enforced by the database itself as well as the application; and every consequential action is written to an append-only audit log.
No system is perfect. If we discover a breach affecting your data, we will notify you and the relevant authorities as required by law, and tell you what happened and what we did about it.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, to object to certain processing, and to complain to a supervisory authority. Signerva provides self-service access, export and deletion in the product; for anything else, write to privacy@signerva.com and we will respond within 30 days.
11. Children
Signerva is a business product and is not directed at anyone under 16. We do not knowingly collect their data.
12. Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will tell you in the product and by email before the change takes effect. Past versions are tracked in our public changelog.
13. Contact
Privacy: privacy@signerva.com
Security: security@signerva.com
Support: support@signerva.com
ANTYPAS WEB SOFTWARE DESIGN SERVICES - FZCO
IFZA Business Park, Building A2, Dubai Silicon Oasis, Dubai, UAE