Sigbot complies with applicable privacy laws, including: UK GDPR & Data Protection Act 2018, EU GDPR, and Canada PIPEDA.
Where Sigbot processes personal data as a Processor, the terms of our Data Processing Addendum apply.
Account Data: Name, email address, login credentials, subscription status.
Contact Data (Customer-provided): Names, email addresses, phone numbers, job titles, company names, and other details extracted from email signature blocks in connected inboxes.
Sigbot does not read, store, or index the substantive body content of emails — only signature-block information is extracted.
Signature-block text is processed using third-party artificial-intelligence models to identify and structure contact details. Specifically, signature-block text is sent server-side to Anthropic PBC's Claude API for parsing, and images captured with the business-card scanner are sent to Google Cloud Vision for optical character recognition. These providers process the data solely to provide the extraction service to us, under data protection agreements, and are listed as subprocessors in our Data Processing Addendum. Sigbot's agreements with these providers do not permit them to use your data to train their models.
Sigbot uses secure cloud infrastructure (including Google Cloud Platform and Firebase) to provide device synchronisation, backups, team collaboration, and real-time database features. Data may be cached locally and stored in the cloud.
Sigbot uses only strictly necessary cookies and browser storage — we do not use advertising or cross-site tracking cookies.
Because these are strictly necessary for the Services to function, they cannot be disabled while using Sigbot. You can clear them at any time through your browser settings, which will sign you out.
We rely on contractual necessity (to provide the Services), legitimate interests (security and service improvement), legal obligations, and consent where required by law.
We do not sell personal data. We may share data with subprocessors providing cloud hosting, authentication, and payment processing. All processors operate under data protection agreements. A current list of subprocessors is set out in our Data Processing Addendum.
Data may be transferred outside the UK/EU/Canada. We rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions, as detailed in our Data Processing Addendum.
We implement encryption in transit (TLS), encryption at rest, access controls, OAuth-based authentication where supported, and monitoring systems. Full details are available on our Security Overview page.
Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. To exercise these rights, contact legal@sigbot.co.
Sigbot is not intended for individuals under 18. We do not knowingly collect personal data from children.
You may lodge a complaint with a supervisory authority: UK ICO, an EU Data Protection Authority, or the Office of the Privacy Commissioner of Canada, depending on your location.
We may update this Privacy Policy periodically. We will post the updated version with a new "Last updated" date and provide notice of material changes.
Privacy questions: legal@sigbot.co. General enquiries: support@sigbot.co.