Data Removal
PDF Signature Maker keeps the documents you sign yourself on your device only. Two things are held on our server: a small subscription record for web subscribers, and — if you use it — the encrypted contents of a signature request. Both are described below.
What lives where
- Documents and signatures you sign yourself: only on your device. Delete them in the App (signature screen → ×), by uninstalling the App, or by clearing site data in your browser.
- App preferences: only on your device; removed on uninstall or when you clear site data.
- Configuration requests: our server receives a random device identifier (not linked to your identity) with app version, language, and platform. These records are used in aggregate and are not tied to any account or person.
Signature requests (web)
If you asked someone else to sign a document, our server holds the encrypted document, the encrypted signed copy once it comes back, and an audit trail (creation, opening and signing times with the IP address and browser user-agent of each event). The document is encrypted in your browser before upload and the key stays inside the link you share, so we cannot read it.
To delete it now: open sign.bnj.app in the same browser you created the request from, go to "Have someone else sign it" → My requests, open the request and press Delete the request. That removes the encrypted files and the audit trail from the server immediately, with no backup.
Otherwise it deletes itself: everything stored for a request is erased automatically 30 days after the request was created.
If you no longer have the browser you created it from, email [email protected] with the request link (or the identifier in it) and we will delete it for you.
Web subscription record
If you subscribed on sign.bnj.app, our server holds one small record: your licence code, your Stripe customer identifier, and the email address you entered at Stripe checkout. It exists only to tell the App whether your subscription is active.
To have it deleted:
- Cancel the subscription first — from the billing portal in the App, or by replying to any Stripe receipt.
- Email [email protected] with your licence code (
SIGN-…) or the email address used at checkout, and ask for removal.
We delete the record within 30 days. Note that Stripe keeps its own payment and invoice records independently, as it is required to for accounting and anti-fraud purposes; see Stripe's Privacy Policy. Deleting our record does not cancel a subscription — cancel first, or you will keep being billed with no way for us to look you up.
Requesting removal of device identifiers
If you would like the random device identifier associated with your installs removed from our aggregate logs, email [email protected] from any address and include the approximate install date. Since the identifier is not linked to your identity, we cannot look it up by name or email — but we will purge matching records where feasible.
Android subscriptions
Purchase records for the Android app are held by Google Play, not by us. To manage those, see your Google Play account.