Privacy Policy
Last updated: 9 September 2026
Your signatures never leave your iPhone. Signelle has no account, no login and no signature library in the cloud. One thing does get sent: when you ask Signelle to design a signature, the name you typed goes to an AI service to draw it. Nothing else goes with it, we do not keep it, and it never reaches our analytics or crash reports.
Who we are
Signelle is developed by Tofesoft. This policy covers the Signelle iPhone app and this website. Contact: tofesoftware@gmail.com.
What stays on your device
All of the following is created, stored and processed on your iPhone, and is never sent to us:
- generated signature designs and their stroke data
- signatures you draw by hand
- photos you scan and the signatures extracted from them
- practice strokes
- PDFs you import, the signatures you place on them and the signed files you export
- the names of your saved signatures and of any document you sign
Scanning is done on device: the photo is held in memory for the length of the scan, converted to stroke data, and dropped. Imported PDFs are read from the system file picker and are never copied into the app's storage; a signed file is written to a temporary location and removed when you leave the screen.
Generating a signature with AI
When you tap Generate, Signelle sends the name or initials you typed, the style you chose and the technical settings for the request to an AI service, through our own secure gateway. The service draws signature designs; Signelle then works out, on your iPhone, how each one could actually be written by hand, and shows you the six it trusts.
- It happens only when you ask for it. There is no background or automatic sending.
- Only the text, the style and the request settings are sent — nothing from your saved signatures, your drawings, your scans, your practice or your documents.
- We do not store the text or the generated images on our servers.
- To apply the Pro allowance, our gateway keeps a small usage record against your RevenueCat app user identifier and the store’s identifier for your purchase: the times of your recent generations and a count of generations made during a free trial. It holds no text, no image and nothing that identifies you.
- The text never appears in our analytics, our crash reports or our logs.
- We send ourselves an operational notification when a purchase, a trial or a generation happens, so we notice problems quickly. It carries the event, the product and its price, your store country and eight characters of the identifier above — never your text, your signatures or anything that names you.
- Once you pick a signature it becomes stroke data on your iPhone. Using, editing, practising or exporting it later never sends anything again.
Everything after generation — the stroke recovery, the practice scoring, the editing, the export and PDF signing — runs on your iPhone and works offline.
What we do receive
Signelle uses Google Firebase for anonymous product analytics, crash reporting and remote configuration. None of it carries the content listed above.
- Analytics. Which features are used, from a fixed list of event names such as "signature saved" or "export completed", together with non-identifying properties such as the chosen style, the export format, or how close a practice attempt came as one of five broad bands — never the score itself, the strokes or any coordinate. Google also processes a randomly generated app instance identifier, your device model, iOS version, app version, language, and a coarse country derived from your IP address.
- Crash reports. Stack traces, device state at the time of a crash and a random installation identifier. For errors the app handles itself, we record only an error domain and a numeric code — never the message, because a message could contain a name or a filename.
- Remote configuration. The app asks Firebase for feature settings. This request carries the app instance identifier and app version and returns settings only.
Signelle shows no advertising, uses no advertising identifier and does not ask to track you across other companies' apps or websites.
Purchases
Signelle Pro is sold through the App Store. Apple processes the payment; we never see your payment details. We use RevenueCat to check whether a purchase or subscription is active, which involves the App Store transaction receipt and a randomly generated app user identifier — not your name or your Apple Account. Before an AI generation, our gateway asks RevenueCat about that same identifier to confirm Pro is active.
Permissions
- Camera — only when you scan a signature from paper, and only after you open that screen. The photo stays on your device.
- Photos — Signelle uses the system picker, so it receives only the single image you choose and has no access to your library.
- Face ID / Touch ID — only if you turn on App Lock. iOS performs the check; Signelle is told yes or no and never sees biometric data.
Keeping and deleting data
Your signatures live in Signelle's own storage on your device. Deleting a signature in the app removes it permanently — there is no recycle bin and no backup on our side. Deleting the app removes everything Signelle stored.
Google keeps analytics data according to the retention period configured for our project, and crash reports for 90 days. Because none of it identifies you, we cannot look up "your" records; uninstalling the app stops all collection and resets the identifiers described above.
Children
Signelle is not directed to children under 13 and we do not knowingly collect their data.
Service providers
- Google Firebase (Analytics, Crashlytics, Remote Config, the AI gateway, this website) — privacy information
- Google Gemini API (draws the signature designs, and reads them back to check the spelling — it receives the typed text and nothing else; under the paid API terms Google does not use prompts or outputs to improve its products, keeps them for a limited period only to detect abuse, and may process them in any country where it has facilities) — API terms
- RevenueCat (subscription status) — privacy policy
- Telegram (delivers the operational notification described above — it carries the event, the product and its price, your store country and eight characters of your RevenueCat identifier, and never your text or your signatures) — privacy policy
- Apple (App Store purchases) — privacy policy
Your rights
Depending on where you live you may have rights to access, correct or delete personal data held about you. Signature content is under your control on your device. For anything else, write to tofesoftware@gmail.com and we will help.
Changes
If this policy changes, the date at the top changes with it and the current version is always published here.