Privacy
Subsigno runs in your browser: the signature is built on your device and copied to your clipboard from there. Eight things can reach a server, each named below — the optional opt-in, the logo finder, the anonymous signature counter, the analytics on the production site, the icons a signature you send may carry, the “Save my contact” link in its last line, any image or banner link we host for you, and signing in to a Team account. Everything else stays with you.
What stays in your browser
Everything you type is kept as a draft in your browser's local storage, under a single key (subsigno.draft.v1) holding the signature details, the look you chose and which mail app you said you use. A second key (theme) remembers light or dark. A third, in session storage rather than local storage, is a single flag (subsigno.counted.v1) recording that this editor session has already been counted once — it holds nothing but that fact and it goes when you close the tab. A fourth key (subsigno.team.v1) exists only for someone signed in to a Team account: it remembers which Team they last opened in the editor, or that they chose the free editor. Those four keys are everything the editor stores in your browser; the editor itself sets no cookies. One cookie exists sitewide, named next, and signing in to a Team account sets another, described under “Team accounts” below.
A cookie, sbsgn_lang, holds the site's own language code — nothing about you. It is set only when you pick a language in the header's language switcher, never simply by visiting a page, lasts one year, and “Clear my data” removes it too.
The “Clear my data” button in the Extras panel deletes all three and resets the editor on the spot.
A team setup link travels in the part of the URL after the # symbol, which browsers never send to any server, including ours. Creating or opening one stores nothing anywhere.
A signature made with the “Made with Subsigno” line on carries a “Save my contact” link. That link contains the details you typed into your signature — encoded in the link itself, as a vCard the server assembles on the spot when someone taps it. Nothing is stored on our side, we keep no record of who taps it, and it works without any account. Anyone who receives your mail can read those details in the link, exactly as they can read them in the signature. Turn the line off and the link goes with it.
What your browser requests while you edit
The preview loads the images you point it at — your photo, logo or banner — directly from wherever they are hosted, as soon as you type the address. That request goes to your host, not to us.
The logo finder, only when you use it, sends the website address you typed to our server. The server looks the name up through Cloudflare's public DNS-over-HTTPS resolver, fetches that one page, and returns the addresses of images found on it. We keep only the address you pick — never the page, never the image. Nothing about the search is stored; an abuse limit works on a salted hash of your network address, held in the server's memory for at most an hour.
Nothing else is requested: fonts, styles and scripts are served from subsigno.com, and with the opt-in box unticked the export buttons send nothing about you — only the counter below.
When you copy or export a signature, your browser adds one to an anonymous counter on our server: no identifier, no network address, no user agent, no cookie, and nothing about you or about your signature — only the day and the number one. It is not analytics and it does not know who you are, which is why it is not switched off by Do Not Track or Global Privacy Control: those signals are an instruction not to track a person, and there is no person in this request to track. The total, rounded down, is public — it is the number shown on the home page.
Icons in the mail you send
Social and contact-line icons are off by default. Switched on, your signature references icon images on subsigno.com, and each recipient's mail client fetches them when the message is opened. We never log, sample or analyse those requests: the automatic request logging on our infrastructure is switched off, and the routes write nothing. Cloudflare, as the host, sees the connection in passing to deliver the file — as any host would.
Leave icons off and your signature requests nothing from us, ever.
Images we host for you
If Subsigno hosts the images in your signature — a logo, a photo, a banner — the files live on img.subsigno.com, in a Cloudflare R2 bucket in the European Union. Your Team’s Owners upload the Team’s logo and banners, and each person their own photo, from their account page; Subsigno support can also do it on your behalf. Each image gets a permanent address that does not change when the image behind it does.
That address is public by design, exactly as any image in any email is. Anyone who receives your signature can open it, and we do not know who does: those requests are served by Cloudflare's edge, the automatic request logging on our infrastructure is off, and nothing ties a request to a person. There is no tracking pixel, no click counting and no address unique to one recipient.
What we record beside the file is bookkeeping and nothing else — which team and which member a slot belongs to, the image's type, its size, and when it last changed — and how many images the Team, and each person in it, uploaded this month, to apply the monthly limits. No name, no email address, and nothing at all about whoever looks at it.
Every photograph and logo we store is decoded and written out again as a PNG before it is stored. That removes whatever was inside the file you sent, including metadata a camera or a design tool left in it — the place a photograph was taken, most of all. Animated GIFs cannot be written out again without stopping the animation, so their frames are kept exactly as sent; everything else is taken out — every comment and every embedded block of data, XMP metadata included, except the one instruction that tells the animation to loop.
A hosted banner can link through a permanent address of ours, subsigno.com/go/…, so that where it leads can change without the signature being edited. A reader who clicks it is sent on to the address you chose; your Team’s Owners set that address, or we do on your behalf, and nothing else can ever be a destination. We record nothing about the click — no network address, no time, no count — and the automatic request logging on our infrastructure is off for it too.
A Team's owner controls its members' images and can delete any of them at any time — today, before self-serve accounts exist, that owner is us, acting for you. Deleting a member removes their photo and banner immediately; deleting the whole Team removes everything it has.
When an image is deleted, a copy can remain in our encrypted backups for up to six months, until they expire.
The opt-in, and what is stored then
The opt-in checkbox appears in the Share panel and again in the dialog after an export. It is one choice — ticking either box ticks both — and it is unticked by default. If you tick it, and only then, we store: your name, job title, company, email address, phone number, the language you were using, which version of this consent text you agreed to, and the date and time. Opting in gets you 10% off your first Solvetus service.
The record is stored in a Cloudflare D1 database, together with a salted one-way hash of your network address that exists only to limit automated submissions — it is pseudonymous and it is not your address. One record per email address per day; repeat submissions fold into it.
We keep the record until you withdraw your consent or until we stop contacting people altogether. If you leave the box unticked, nothing is sent and nothing is stored.
Once deleted, a record can remain in the encrypted backups for up to six months, until they expire. If a backup is ever restored, we delete it again.
Why, and on what basis
The purpose is to contact you about IT services and practical tips, as described next to the checkbox. The legal basis is your consent, under Article 6(1)(a) of the GDPR.
Your details are never sold, rented, or shared for anyone else's marketing.
Withdrawing consent and your rights
You can withdraw your consent at any time, and you do not have to give a reason: write to info(at)subsigno.com and your record will be deleted.
You also have the right to ask what we hold about you, to have it corrected, to receive a copy, and to complain to your national data protection authority — in Portugal, the CNPD.
Team accounts
Members of a Team can sign in at subsigno.com/account. The editor needs no account and never asks for one. Signing in is not open to everyone: an account exists only because a Team's owner — today, us on the Team's behalf — gave a seat to that person's e-mail address.
There is no password. We e-mail a link and a 6-digit code, each valid once for 15 minutes. For an account we store the e-mail address, when the account was created, the last sign-in, and when the address last changed. Which Teams it belongs to comes from the Teams' own seats.
Signing in sets one cookie, __Host-sbsgn, holding a random value that identifies the session; asking for a code sets a second, __Host-sbsgn-p, for 15 minutes, so that the code works only in the browser that asked for it. Both are strictly necessary to sign you in, so no consent is asked for them. No network address and no device details are stored with a session. A session ends after 30 days without use, 90 days after signing in, or when you sign out.
To stop codes being guessed and inboxes being flooded, sign-in attempts are counted under a keyed one-way hash of the e-mail address and of the network address — never the addresses themselves — and those counts are deleted within a day.
Sign-in e-mails are delivered by Microsoft, through the Microsoft 365 mail service Solvetus uses, from noreply@subsigno.com. Microsoft processes the recipient's address and the message in order to deliver it; nothing else about you is sent to Microsoft.
In the editor, a signed-in member can save their Team signature, so it opens again without retyping. What they typed into it — name, title, contact details, social links, disclaimer and the look they chose — is then stored on our servers, one signature per member per Team, visible only to that member when signed in; the Team’s logo, the member’s photo and the banner are not copied into it, only which of them it uses. A saved signature is deleted when its member or its Team is deleted, or when the seat is given to someone else; like everything else, it can remain in the encrypted backups for up to six months. The legal basis is the same as for the account.
An account is deleted when its last seat is deleted, or when you ask at info(at)subsigno.com; like everything else, it can remain in the encrypted backups for up to six months. The legal basis is the service your Team has taken out: the contract with the Team and, for its other members, the Team's legitimate interest in letting them sign in (Article 6(1)(b) and (f) of the GDPR).
A Team can register its own company domains, for example acme.com. To show it controls one, the Team publishes a small TXT record in that domain's DNS, and we look that record up through Cloudflare's public DNS resolver: when it is added, and then about once a week. We keep the domain name, the record's random token and the dates of those checks. Once a Team has a verified domain, every new sign-in e-mail address in that Team must be on it, and a Team without one has a single seat. If the record goes missing we e-mail the Team's owners a warning, a reminder and a final notice over two weeks, from noreply@subsigno.com through Microsoft, as for sign-in e-mails. Nothing that already exists is removed because of a domain: everybody who could sign in still can. Domains are deleted with the Team; like everything else they can remain in the encrypted backups for up to six months.
Owners of a Team sign in in two steps, and any member can choose to: after the e-mail, a passkey — a key kept on your own phone, computer or password manager. We store its public key (which cannot sign anybody in), its identifier, the name you gave it, when it was added and last used, a signature counter and whether it syncs between your devices; the private key never leaves your device, and your fingerprint or face never reaches us. We also store ten single-use backup codes, only as keyed one-way hashes. Between the e-mail and the passkey, a third cookie, __Host-sbsgn-2f, holds that step for 10 minutes; it is strictly necessary too. Passkeys and codes are deleted when you remove them, when your account is deleted, or when Subsigno support resets them at your request — a reset is recorded with who did it and when. The legal basis is the same as for the account.
Owners run their own Team from the account page: they can make another member an Owner or a member again, archive, restore or delete members’ seats, add, check or remove the Team’s domains, add languages, and show or hide the logo, the banner and members’ photos in the Team’s signatures. They can also add people and shared mailboxes, one at a time or from a CSV file: the name and e-mail address they enter are stored in the Team, and the person is sent one e-mail saying they were added. A CSV file is read but not kept: only the rows that become people are stored, with the title, department and phone numbers they list (used to pre-fill the person’s first signature). If you were added by mistake, ask the Team’s Owner to delete your seat. Each such change — by an Owner or by Subsigno support — is written to the Team’s history: what changed, when, and which account made it (support changes are recorded with who did it). The history is kept until the Team is deleted and, like everything else, can remain in the encrypted backups for up to six months after that. A person whose role changes, and the Team’s other Owners, are told by e-mail, from noreply@subsigno.com through Microsoft, as for sign-in e-mails.
Analytics
We count visits with Matomo, run by Solvetus on its own server in France, at analytics.solvetus.com. It is cookieless, and it records page views and clicks on outgoing links. It runs only on subsigno.com — previews and test deployments stay silent — and it honours your browser's Do Not Track and Global Privacy Control settings. Network addresses are shortened before storage, raw visit data is deleted after twelve months, no profile is built, and nothing follows you to other sites.
Hosting and processors
subsigno.com runs on Cloudflare (Workers, the D1 database and its cache). Cloudflare is a US company; as the host it processes connection data — your network address and request metadata — in passing, to deliver the site and defend it against abuse. We keep no visitor logs of our own.
Every night an encrypted copy of Subsigno's database and hosted images is made so the service can be restored after an accident. It is kept at OVH in France, and each copy is deleted after six months at most.
The other parties in the data path are Solvetus's own Matomo server (hosted at OVH in France) for the analytics above, OVH's object storage in France for the encrypted backups, Microsoft for the sign-in e-mails and domain notices of Team accounts, and Cloudflare's public DNS resolver for the logo finder's lookups and for checking a Team's domain records. There is no one else: no advertising network, no third-party scripts, no fonts or code from anyone's CDN.
Who is responsible
Subsigno is operated by Solvetus — a brand of Ruben José Dos Santos Marques (RJDSM), sole trader registered in Portugal; the legal notice carries the full identification. Questions about this page, or about anything stored, go to info(at)subsigno.com.
Contact
Last updated: · privacy-v3