Your document, handled carefully.
Plain answers to the questions people ask before uploading something that matters.
What we store
We store the reviewed and completed PDFs, field positions, designated email addresses, the name stated by the signer, signature method, retention choice, and a timeline of events. For new completions we also preserve the exact electronic-record disclosure and signing-intent text accepted, its version, and server timestamps. IP addresses and browser information provide context, not verified identity or proof that a document was read. There are no user accounts.
Both parties can download a private evidence ZIP with the PDFs, consent record where available, signing context, and checksums. It includes personal information and should be kept confidential. Older documents are labeled when historical consent wording was not captured.
Your browser tab temporarily saves unfinished field placement, email entries, or a signature/name draft so a refresh can restore your progress. Consent checkboxes are never remembered. These drafts use session storage and are separate from server retention; use a private device and close the tab when finished.
How it's protected
- Files are encrypted on disk (AES-256-GCM) with a key that is never stored beside them.
- Signing links contain a 256-bit random token. We store a hash for access checks and an encrypted copy so you can retrieve and share the same link. A database copy alone, without the separate encryption key, does not reveal working links.
- Everything travels over HTTPS.
- Documents are never shown to advertising or analytics systems. There are none on this site.
When it's deleted
- An uploaded document that is never sent is deleted after 24 hours.
- A signing link works for 14 days. If it isn't signed by then, the document is deleted a week later.
- Newly sent documents use one year (365 days) of storage after signing. A sender can instead explicitly choose 30 days; the signer sees that period before agreeing. Both people can download the PDF and evidence from their private links. Previously sent documents keep their earlier retention policy. Email delivery is not enabled, so save your link and download your copy.
- Declining or cancelling closes the signing link immediately. Unsigned files still follow their original expiry/deletion deadline.
Access ends at the deadline. Background cleanup removes the stored files, consent/evidence snapshot, and personal details in batches and retries temporary storage failures. File fingerprints, sizes and event types/timestamps remain for integrity history; mailbox copies and platform backups have separate retention policies. Hosting for 365 or 30 days does not replace your legal recordkeeping obligations. Keep your own copies when needed for a dispute or longer retention requirement.
What the signed PDF contains
The reviewed pages with the signature, name and date placed where you put the boxes, plus a signing record and, for new completions, the accepted consent wording. Reviewed PDFs may have been safety-sanitized after upload. Long records continue onto extra pages. Compare file fingerprints with a trustworthy saved reference to detect changes; fingerprints alone are not certificate-backed signatures or independent proof of identity.
A note on legal effect
Electronic signatures are widely accepted for everyday agreements, but whether a particular signature is enforceable depends on the document, the parties and the jurisdiction. We record what happened and keep the file intact; we don't give legal advice.
Read the permitted uses, New York/federal references, and electronic-record disclosure.