Last updated · July 12, 2026

Privacy Policy

Signum is operated by Axiom Tech Lab, registered in Bengaluru, Karnataka, India (“Signum”, “we”, “us”). This policy explains what data we collect, how we use it, who we share it with, how long we keep it, and what choices you and the people you send to have.

It applies to: signum.email (this marketing site), app.signum.email(the dashboard), the Signum Chrome extension, the Signum Gmail add-on, and the Signum API.

Where the law uses a specific term (data controller, lawful basis, data subject right), we use that term too — always with a plain-English explanation right beside it.

1. Plain-English summary

  • You sign in with Google. We get your name, email, and a refresh token. We use the token only to do what you asked us to do.
  • Tracking events on emails YOU send are stored. Subjects and recipient addresses are encrypted with a key unique to your workspace.
  • We never store the BODY of your emails by default.
  • We do not sell data. We do not run ads. We do not train AI on your email content.
  • Recipients can opt out of tracking globally. Senders can export or delete everything.
  • Subprocessor list is published below. So is data residency. So is retention.
  • India DPDP grievance officer: Krishna · [email protected]

2. Who is the data controller?

For sender data(your account, your billing, your config, your usage logs): Signum is the data controller. We decide what’s collected and how it’s used.

For recipient data(the email addresses, subjects, and engagement events of the people you send to): you are the data controller. We are your processor — we hold and process that data on your instructions, under the terms of your acceptance of the Terms of Service. A signed Data Processing Agreement (DPA) is available for paid plans on request from [email protected].

3. What we collect from senders

From Google OAuth:

  • Your Google account name, email address, and account ID.
  • A Google OAuth refresh token, encrypted with your workspace key before storage.
  • Your browser-resolved timezone.

From your use of Signum:

  • Workspace name, plan tier, and billing details (handled by Stripe / Razorpay — we never see your card number).
  • Configuration: Watcher rules, Followup sequences, Remind patterns, contacts, templates, cohort definitions.
  • Audit log of state-changing actions (settings changes, rule edits, role changes, OAuth grants and revokes).
  • Server access logs: IP class (not full address by default), user agent, request path, HTTP status, response time. Retained 30 days for security monitoring.
  • Webhook delivery logs (which event, which URL, response code). 30 days.

From the Chrome extension / Gmail add-on:

  • The Gmail thread and message metadata required to run Watcher rules, attach reminders, and surface engagement on the right thread.
  • Local browser storage (in the extension): your auth token, recently-rendered floater rows, draft buffers. This is stored on YOUR device, not on our servers.

4. Google user data and Limited Use

Signum works inside Gmail, so some of what we process is Google user data. We request the narrowest OAuth scopes that make the product work, and nothing more:

  • openid · email · profile — to sign you in and identify your account.
  • gmail.send — to send the tracked emails and follow-ups you configure, on your behalf.
  • gmail.modify — to read your own threads for reply detection (so a sequence stops when someone replies), to apply and remove Signum’s own labels, to create drafts, and to insert reminder notes.

We do not request the https://mail.google.com/ full-access scope, and Signum cannot permanently delete your mail. References to mail.google.com elsewhere are links that open a thread in the Gmail web interface, not access we hold.

Signum’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features described in this policy.
  • We do not sell Google user data.
  • We do not use Google user data for advertising.
  • We do not use Google user data to train generalised or foundation AI/ML models.
  • We do not allow humans to read your Google user data, except: with your explicit consent; to fix a specific problem you report; for security; or where required by law.
  • We transfer Google user data to others only as needed to provide or improve the service, to comply with law, or as part of a merger or acquisition under equivalent protections.

Message bodies are not stored.When reply or out-of-office detection needs to read a message, it is read transiently and discarded — we do not persist the contents of your emails. Addresses and subjects are encrypted at rest (see § Encryption and security).

5. What we collect from recipients

When you send a tracked email through Signum, we may collect, for each recipient:

  • Recipient email address (encrypted at rest with your workspace key).
  • Subject line of the email (encrypted at rest).
  • Send timestamp, Gmail message ID, thread ID.
  • Tracking events: pixel loads (opens), link clicks, honeypot interactions, and attachment/document opens.
  • For each event: timestamp, IP-derived country (not full address), user-agent class, bot-detection verdict (HUMAN / BOT / MPP_PROXY / GMAIL_PROXY / PIXEL_PROXY).

We do NOT store the BODY of your emailsby default. The body is sent through the Gmail API and immediately discarded. The only exception is if YOU explicitly save a body as a template or as a Followup step body — that’s your authored content, kept encrypted, and only used to send future emails on your behalf.

6. Lawful basis (GDPR / DPDP)

For sender data: contract. You signed up, we need this data to provide the service you contracted for.

For recipient tracking data: usually legitimate interest (your interest, as the sender, in understanding whether your business email got read), occasionally consent(when you maintain a list with explicit opt-in). You are responsible for ensuring the right basis applies to YOUR recipients. The controls in §9 below help you do that.

For analytics on signum.email and app.signum.email: we use only essential, first-party data (auth session cookies). No third-party analytics. No advertising trackers. No behavioral cookies.

7. How we use it

  • Run the agents. Watcher reads inbound Gmail to match rules; Followup sends scheduled steps; Remind tracks reply state; Track scores engagement.
  • Serve the dashboard. Your own data rendered back to you with appropriate filtering and aggregation.
  • Send emails on your behalf (when you tell us to: Followup steps, untracked-thread follow-ups via dashboard, AI Auto-Respond when enabled).
  • Prevent abuse. Bot detection on tracking events. Rate limiting on the API. Anti-spam guards on bulk send.
  • Improve the product. Aggregate, anonymized usage analytics — never tied back to individual recipients or message content.
  • Bill you. Communicate about your account, plan, usage, and renewals.
  • Comply with the law. Respond to lawful requests, enforce our terms, protect rights and safety.

We do NOT:

  • Sell your data, or your recipients’ data, to anyone.
  • Run advertising or third-party trackers on our website or in the product.
  • Use your email content to train models (general or our own).
  • Build identity graphs across workspaces.
  • Share recipient data with any sender other than the one who sent them the email.

8. Subprocessors

Subprocessors are third-party services we use to operate Signum. Each is contractually bound to the same privacy standards we hold ourselves to. Current list:

Google Cloud Platform(Mountain View, US) — API runtime (Cloud Run), secret management (Secret Manager), workload identity. Regions: us-central1, asia-south1.

Neon(US) — primary PostgreSQL database. Region: US-East. TLS required.

Cloudflare(global) — pixel-worker edge (Workers), CDN, DNS, DDoS protection.

Google Workspace (Gmail API)— to send and read emails on your behalf, scoped to the OAuth permissions you granted.

Stripe(US, IE) — USD billing. PCI-DSS Level 1 certified.

Razorpay(India) — INR billing. RBI-registered payment aggregator.

Anthropic(US) — Premium-tier AI Auto-Respond features only, when shipped, with your explicit opt-in. If you use this feature, the email content you choose to draft over is sent to Anthropic’s API.

We notify subscribers by email at least 14 days before adding a new subprocessor that processes recipient data. You can object and cancel without penalty during that window.

9. Data residency and international transfers

Primary database: US-East (Neon). Pixel-worker: global Cloudflare edge. API services: us-central1 and asia-south1 (Google Cloud).

For EU customers: data may be transferred to and processed in the United States. We rely on:

  • EU–US Data Privacy Framework: Google Cloud, Cloudflare, and Stripe are all current participants.
  • Standard Contractual Clauses (SCCs): for any gaps not covered by the DPF.
  • Encryption at rest and in transit: data is unreadable to third parties along the path.

For Indian customers under DPDP: cross-border transfer to the US is currently permitted (US is not on India’s restricted-transfer list). If India later restricts transfers in a way affecting Signum, we will give 90 days’ notice and offer a data-residency option.

10. Recipient rights and opt-out

Every tracked email Signum sends includes:

  • A List-Unsubscribe header (RFC 8058 one-click) for bulk sends.
  • A footer-less opt-out link the sender configures (no Signum branding ever forced).

When a recipient opts out via either mechanism:

  • Future tracking pixels and link wraps from that sender to that recipient stop firing.
  • Any active Followup sequence to that recipient cancels immediately.
  • The recipient is added to that workspace’s suppression list.

Recipients can also reach us directly at [email protected] for:

  • Right of access — a copy of the data we hold about them.
  • Right of rectification — correction of inaccurate data.
  • Right of erasure / right to be forgotten — deletion from our systems.
  • Right of transparency — the list of workspaces that have tracked them.
  • Right to object — global suppression across all current and future workspaces.
  • Right to portability — export of their tracking data as JSON.
  • Right not to be subject to automated decision-making — the engagement score is an aid to the sender’s decision, not a binding automated decision.

We respond to these requests within 30 days. If the data is held under a sender’s direction (you, the data controller), we forward the request to you and assist with compliance — that’s our role as processor.

11. Sender rights

As a sender (account holder), you can:

  • Export all your data as a signed JSON archive from Settings → Export Workspace Data.
  • Delete your account from Settings → Account. We delete sender data within 30 days; recipient tracking data is anonymized (PII removed) for billing reconciliation.
  • Revoke Google access at myaccount.google.com/permissions. We lose Gmail send/read the moment you do.
  • Move to another provider. The exported archive is in open JSON, not proprietary.
  • Audit access. Every workspace-membership change and OAuth grant is in your audit log.

12. Cookies and tracking on signum.email

signum.email (marketing site):no cookies. No analytics. No fingerprinting. No advertising trackers. Pages are statically generated and served via Cloudflare. If we add privacy-preserving analytics later (Plausible, no cookies), we’ll disclose it here.

app.signum.email (dashboard):

  • One essential cookie: signum_session (your JWT auth token). HttpOnly, Secure, SameSite=Lax, scoped to .signum.email.
  • Two short-lived cookies during OAuth: signum_oauth_state, signum_oauth_verifier. Both expire after 10 minutes.
  • localStorage on your device: UI preferences (dark/light, density), recent-action cache. Never sent to our server.

No third-party cookies. No tracking pixels other than the Signum pixel-worker, which only fires for emails YOU send.

13. Data retention

Default retention periods:

  • Account and configuration data: lifetime of account; deleted 30 days after account deletion.
  • Tracking events: 24 months. Configurable shorter from Settings → Data → Retention.
  • Audit logs: 18 months (security baseline).
  • Server access logs: 30 days.
  • Webhook delivery logs: 30 days.
  • Billing records: 7 years (regulatory requirement under Indian tax law).
  • Database backups: 7 days (Standard Neon plan) or 30 days (Pro). Deleted data persists in backups for the backup window before becoming irrecoverable.

On account deletion: sender data is deleted within 30 days. Recipient tracking data is anonymized (PII removed, aggregate counts kept) for billing reconciliation and abuse-detection history.

14. Encryption and security

The technical details live on the Security page. In brief:

  • In transit: TLS 1.2+ on every leg. HSTS site-wide.
  • At rest: AES-256-GCM. Per-workspace HKDF-derived keys. 79+ encrypt call sites across the API.
  • Pepper: held in Google Secret Manager, fetched via workload identity (no long-lived secrets).
  • Auth: JWT sessions with HS256 + revocation denylist enforced on every authed request.

What this is NOT:Signum is not a zero-knowledge product. The server holds the master pepper and can decrypt data to serve it back to you. We disclose this directly because “encrypted at rest” in our case means workspace-isolated with strong industry cryptography, not end-to-end-encrypted in the Signal sense.

15. Breach notification

If we discover a security breach that affects your data, we will notify you within 72 hours of confirming the breach (GDPR Art. 33 standard, applied globally). The notice will include:

  • What data was affected and approximate volume.
  • Likely consequences (best assessment at notification time).
  • Measures taken or proposed to address it.
  • Contact for further questions.

We will also notify supervisory authorities where legally required (DPA in the EU, MeitY in India under DPDP). You will be notified before public disclosure.

16. Children

Signum is for business communication. We do not knowingly collect data from anyone under 16. If we learn that we have, we delete it. If you believe a minor’s data is in Signum, write to [email protected].

17. Automated decision-making

Signum does not make automated decisions with legal or similarly significant effect on individuals (under GDPR Art. 22 or DPDP equivalent). Engagement scores, agent actions, and bot verdicts are advisory inputs to your decisions as the sender. Skip-on-engagement logic in Followup is a sequence behavior, not a determination about a person.

Premium-tier AI Auto-Respond, when shipped, drafts replies but never sends without your approval per send. The model is from Anthropic; we don’t use your data to train it.

18. Disclosures to law enforcement

We may disclose data when legally required (subpoena, court order, lawful regulatory request). Our approach:

  • We require a valid legal demand from a competent authority.
  • We narrow the disclosure to what’s legally required — we don’t volunteer more.
  • We notify the affected workspace owner before disclosure, unless legally prohibited (e.g. by gag order).
  • We push back on demands we believe are overly broad or invalid.
  • Annual transparency report (when meaningful volumes start arriving) will summarize counts received.

19. California (CCPA / CPRA)

If you’re a California resident: you have all the rights in §9 (access, deletion, correction, portability, opt-out). We do not sell or share personal information in the CCPA sense. You can also designate an authorized agent to exercise rights on your behalf.

Notice of right to opt out of “sale” or “sharing”: not applicable. We don’t do either.

20. India (DPDP Act 2023)

Signum’s parent entity is registered in India. Specific DPDP commitments:

  • Grievance officer: Krishna, reachable at [email protected].
  • Acknowledgment: grievances acknowledged within 72 hours.
  • Resolution: within 30 days.
  • Consent management: where consent is the basis (e.g. when an Indian sender uses Signum to send to Indian recipients), we provide consent-collection tooling and a recipient-facing dashboard for managing consents (planned by end-2026).
  • Data Protection Officer: not yet appointed (Signum’s revenue is below the threshold that mandates one); founder Krishna acts in that capacity.

21. EU / UK (GDPR / UK GDPR)

For EU and UK customers and recipients: rights in §9 apply in full under GDPR / UK GDPR. We are not currently required to appoint an EU representative; if you have a complaint, you can lodge it with your local supervisory authority. For UK: the ICO.

We rely on legitimate interest (Art. 6(1)(f)) for most recipient processing and contract (Art. 6(1)(b)) for sender processing. Specific bases are documented per processing activity in our internal ROPA (Record of Processing Activities), available to supervisory authorities on request.

22. Changes to this policy

When we make a material change, we notify all account holders by email and give 30 days’ notice before the change takes effect. Material includes: any change to what we collect, who we share with, retention periods, or your rights.

Non-material changes (typos, clarifications, restructuring, subprocessor swaps that don’t change data scope) take effect on update. The version history is on file and available on request.

23. Contact

Privacy questions: [email protected]

Security questions / breach reporting: [email protected]

India DPDP grievance officer: Krishna, [email protected]

Postal address:
Axiom Tech Lab
Attn: Grievance Officer
Bengaluru, Karnataka, India
(Full address available on request — please email first.)