Legal
Privacy policy
Last updated 13 September 2026
Psygned is operated by Toarc United LLC, a Wyoming limited liability company ("Psygned", "we"). This policy explains what we collect, why, and what your rights are. It applies to people who create an account to send documents ("senders"), to people who are asked to sign them ("signers"), and to visitors of psygned.com. Questions go to [email protected].
Who is responsible for your data
For senders and visitors, Toarc United LLC is the controller of your account and website data. For signers, the sender who sent you the document is the controller of the document and of the details they entered about you (your name and email address); Toarc United LLC processes that data on the sender's behalf as a processor, under the terms of service. Where the law requires a controller for the evidence record itself (the times, addresses and identifiers that make a signature reliable), Toarc United LLC is a joint controller with the sender for that record only.
What we collect
- Senders: name, company name if given, email address, password (stored hashed by our authentication provider), the documents you upload, the names and email addresses of the signers you enter, your credit balance and purchase history, API keys (stored hashed) and the times they were used.
- Signers: the name and email address the sender entered, the values you type into fields, your typed or drawn signature, and the time you opened, agreed and signed.
- Evidence for both: the internet address (IP address) and browser identifier of the device used to create, send, open, agree and sign, and a unique identifier for each signature, because these form the record that makes an electronic signature reliable.
- Emails we send and whether they were delivered, through our email provider.
- Payments: when card payment is available, our payment provider collects your card details directly; we receive only a confirmation, the amount, the last 4 digits of the card and a billing country.
- Website: we set no advertising or analytics cookies. Session storage is used to keep senders logged in. Page views are counted with Cloudflare Web Analytics, which uses no cookies, no fingerprinting and stores no personal data; we see aggregate counts only.
Why we use it, and on what basis
- To run the signing service: deliver documents, collect signatures, and produce the signed copy and the Certificate of Completion (performance of the contract with the sender; for signers, the sender's legitimate interest and yours in completing the document you were sent).
- To create a reliable record of who signed what and when, which is the reason the service exists (legitimate interest of the sender and the signers in an enforceable record). This is why IP addresses and times are recorded and shared with every party to the document.
- To take payment and keep accounts (performance of the contract and legal obligations to keep financial records).
- To keep the service secure and to prevent abuse (legitimate interest).
- To answer your questions (legitimate interest).
We do not sell personal data, we do not use it for advertising, and we do not use documents or signatures to train any model.
Who we share it with
Only the providers needed to run the service, each under contract and only on our instructions:
- Supabase (database, file storage and authentication), hosted on Amazon Web Services in Ireland (EU).
- Resend (email delivery), United States.
- Cloudflare (website hosting, API edge and network), global network.
- Our card payment provider, when card payment is available; named on the pricing page and at checkout.
Every party to a completed document receives the signed copy and the certificate, which contain the signers' names, email addresses, signature images, signature identifiers and IP addresses. If a sender connects Psygned to their own software or an AI assistant, that software receives the same information about the sender's documents; the sender is responsible for it. We disclose data to authorities only when the law requires it.
How long we keep it
- Unsent drafts and their files: removed automatically 30 days after creation.
- Sent documents, signatures, certificates and the record of events: for as long as the sender's account exists. Senders and signers should keep their own copy of completed documents.
- Signing links: 14 days, after which a fresh one must be requested; used links stop working at once.
- Account data: until the account is closed, then removed within 30 days apart from purchase records we must keep for tax and accounting purposes (typically 7 years).
- Email delivery logs: as kept by our email provider, typically 30 days.
Your rights
Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, and to complain to a supervisory authority (for residents of the EEA, the authority in your country; for UK residents, the ICO). Signers should contact the sender first, since the sender controls the document. Either way you can write to [email protected] and we will answer within 30 days or pass the request to the sender. Note that the evidence record of a completed document generally cannot be altered or erased while the document is kept, because doing so would destroy the record the other parties rely on; where that applies we will explain it.
International transfers
Documents and account data are stored in the European Union. Email delivery and the website edge involve providers in the United States and on a global network. Where personal data leaves the EEA or the UK, the transfer relies on the provider's standard contractual clauses (EU Commission decision 2021/914 and the UK addendum) or on an adequacy decision, including the EU-US Data Privacy Framework where the provider is certified.
Security
Documents are stored in private storage and are only reachable through short lived signed links. Signing links are random, personal to one signer, expire, and are stored only as a hash, as are API keys and passwords. Once a document is sent, neither the sender nor Psygned staff can edit its evidence record through the application. Traffic is encrypted in transit and files are encrypted at rest by our storage provider. If a breach affects your data we will tell the affected senders without undue delay and, where required, the supervisory authority.
Children
Psygned is for adults. We do not knowingly collect data from anyone under 18 as a sender. Senders must not send documents for signature to children.
Changes
If this policy changes in a way that matters, we will show the new date here and, for senders, let you know by email.
Contact
Toarc United LLC, trading as Psygned, Wyoming, United States. [email protected].