Privacy Policy
Last updated: August 25, 2026
PDF Signature Maker ("the App") is developed by Hugo Software Ltd. ("we", "us"). It is available as an Android app and as a web app at sign.bnj.app. This policy explains what data the App handles and how.
The short version
When you sign a document yourself, it never leaves your device. The App opens, displays, signs, and exports PDF files entirely on your device — in the browser on the web, on the phone on Android. We do not upload, store, or see those documents or your signatures.
There is one exception, and it is the signature request. On the web you can ask someone else to sign a document. That document has to reach the other person, so it is stored on our server — but it is encrypted in your browser before it is uploaded, and the decryption key travels only inside the link you share. The key never reaches our server, so we cannot open the document. See "Signature requests" below for exactly what we do hold.
Data we do NOT collect
- We do not create user accounts, and there is no sign-up or password.
- We do not upload the PDF files or signatures you sign yourself. (Signature requests are the one exception, described below, and they are end-to-end encrypted.)
- We use no advertising SDKs, no analytics SDKs, and no crash-reporting SDKs.
- We do not access your camera, microphone, location, or contacts.
Data stored on your device
- Saved signatures (up to 6) are stored only in local storage on your device so you can reuse them. You can delete them in the App at any time; uninstalling the App or clearing site data removes them.
- App preferences (such as whether you have seen the tutorial) are stored locally.
- On the web, a licence code and the last known subscription status are stored locally if you subscribe.
- On the web, your signature requests — their identifiers, the decryption keys, the file names and notes you typed — are stored locally in your browser. The keys exist only here and inside the links you share; if you clear your browser data, we cannot recover them and the encrypted documents become permanently unreadable.
Signature requests (web only)
When you create a signature request, your browser encrypts the document with a key it generates locally (AES-GCM, 256-bit) and uploads only the encrypted result. The file name, the note to the signer, your name, and the signer's name are encrypted in the same way. The signer's browser decrypts everything using the key in the link, and encrypts the signed document again before sending it back.
On our server, for each request, we hold:
- the encrypted document and, once signed, the encrypted signed document — neither of which we can read;
- a random request identifier and a random access token;
- a random identifier for the browser that created the request, used only to count how many open requests a free user has;
- an audit trail: when the request was created, when the document was opened, when it was signed, and for each of those events the IP address and browser user-agent string of the device involved. This trail exists because it is the point of the feature — it is what tells you the document really was opened and signed — and it is shown to whoever created the request.
Retention: the encrypted files and the audit trail are deleted automatically 30 days after the request is created. You can delete a request — and everything stored for it — at any time from the "My requests" list. There is no backup copy afterwards.
Anyone holding the link can open and sign that document, so share it only with the person who should sign it.
Data sent over the network
On launch, the App makes a single request to our configuration server to fetch remote settings (feature limits, announcements, maintenance mode). This request contains only:
- a randomly generated device identifier (not linked to your identity),
- the App version, your language code, and the platform ("android" or "web").
We use this to operate the App and to count active installs in aggregate. It is not used for advertising and is not sold or shared with third parties.
The web app also uses Umami, a privacy-focused analytics tool we host ourselves, to count page views in aggregate. It sets no cookies and does not profile individuals.
Purchases
Android
The optional Premium subscription is processed entirely by Google Play Billing. We never receive your card number or payment credentials. Google's handling of your payment data is governed by Google's Privacy Policy.
Web
The optional Premium subscription is processed entirely by Stripe. Payment details are entered on Stripe's own checkout page — we never see or receive your card number. Stripe's handling of your data is governed by Stripe's Privacy Policy.
If you subscribe on the web, our server stores a small record so we can tell whether your subscription is active:
- a randomly generated licence code (e.g.
SIGN-XXXXXXXX), - your Stripe customer identifier,
- the email address you entered at Stripe checkout, used to identify your subscription for support and refunds.
This record is not used for marketing, and we do not send promotional email. Your subscription status itself is read from Stripe when the App asks.
To have this record deleted, cancel your subscription and email us — see the data removal page.
Legal note about signatures
The App places a visual image of your drawn signature on the PDF. It does not create a qualified or certified electronic signature and performs no identity verification. The audit trail records the technical facts we can observe (times, IP addresses, the name the signer typed); it does not prove who that person is.
Children
The App is not directed at children under 13.
Changes
We may update this policy; the current version is always available at this page. Material changes will be reflected in the "Last updated" date above.
Contact
Questions? Email us at [email protected].