Legal
Privacy policy
Last updated 29 September 2026
This policy explains what CoreSign does with personal information. It covers both people who send documents for signature and people who are asked to sign them — their situations differ, and the differences are called out where they matter.
To delete your account, see Deleting your account — you do not need to write to us.
Who we are
CoreSign is operated by Core Legacy Studios (“we”, “us”). You can reach us about anything in this policy at coresign.support@corelegacystudios.com.
Two different roles, and why it matters to you
When a sender uploads a document and chooses who should sign it, they decide what that document contains and who receives it. We handle it on their instructions. In data-protection terms they are the controller and we are the processor.
For our own account records — who holds a CoreSign account, billing, and the security logs that keep the service running — we decide, and we are the controller.
If you are a signer and you want a document changed, withdrawn or deleted, start with the sender. They chose to send it and they control it. We will help you reach them and will act on their instruction, but we will not unilaterally alter or destroy the record of an agreement that another party relies on.
What we collect
If you send documents
- Your email address, and a securely hashed password.
- Which version of our terms of service you accepted, and when.
- If you turn on two-step sign-in with an authenticator app: the secret it shares with us, stored encrypted.
- If you add a passkey: its public key and credential ID; the kind of authenticator, where your device reports one; whether it is synced across your devices; how it connects; a use counter; the name you give it; and when it was added, last used and, if you remove it, removed. Your private key, fingerprint, face and PIN stay on your device — we never receive them.
- With the first second step of either kind: recovery codes, each kept only as a one-way fingerprint.
- While you add a passkey or sign in with one: a single-use challenge, kept only as a one-way fingerprint and valid for five minutes.
- If you create API keys: a one-way fingerprint of each key and its first few characters, so you can tell your keys apart. The key itself is shown to you once and is not kept.
- The documents and templates you upload, and the fields and questions you place on them.
- The names and email addresses of the people you ask to sign, which you supply.
- If you buy a paid plan: your billing country, state and ZIP code, and the name on your card. The card number, expiry date and security code go into the payment processor’s own secure field and never reach our systems.
- A record of each payment: the amount, any tax, the currency, where it was taxed and the billing country, state and ZIP code it was taxed by, its status and any refund.
If you are asked to sign
- Your name and email address, as given to us by the sender.
- The signature, any initials or dates you enter, and any answers you give to the sender’s questions.
- A record of the signing: when the request was sent, when you opened it, when you read the document and which of its pages were shown to you, when you consented to sign electronically, and when you signed — together with the network address and browser identification recorded at those moments.
That last item exists because it is the evidence the agreement rests on. An electronic signature is only worth as much as the record of the circumstances in which it was given, and it is written into the certificate of completion and sealed. It is therefore not something we can later edit or selectively remove — doing so would destroy the integrity of the very record it documents.
This website
The site you are reading now sets no cookies, runs no analytics, and loads no scripts, fonts or images from anyone else. Visiting these pages does not tell us who you are. Standard server logs are kept briefly for security and reliability.
Why we process it
- To carry out the signing — delivering the request, showing you the document, recording your consent and signature, producing the completed file. This is performance of the service you or the sender asked for.
- To produce and preserve the record — the certificate of completion and the seal. This is our legitimate interest, and the sender’s, in holding evidence of an agreement.
- To keep the service secure — detecting abuse and unauthorised access.
- To meet legal obligations, where they apply.
We do not sell personal information. We do not share it with advertisers. We do not use the contents of documents sent through CoreSign to market anything to anyone, and we do not use them to train machine-learning models.
Who else sees it
We share personal information only with service providers who need it to deliver the service, and only for that purpose:
- An email delivery provider, to send signing requests, notices that it is your turn to sign or that a document was withdrawn, completion notices and emails about your account, such as a notice that a payment has failed.
- A payment processor, for paid plans. We send it your account’s email address, the name on your card and your billing country, state and ZIP code; it keeps your card on file to take renewal payments. It sends us back the records of each payment and of your subscription.
- Hosting and infrastructure providers, who store the data on our behalf under contract.
We may also disclose information where we are legally required to, or where it is necessary to establish or defend a legal claim — including producing a sealed record when its authenticity is in dispute, which is much of the reason the record exists.
How long we keep it
- Completed documents, certificates and seals are kept while the sender’s account is active, because they are the evidence of an agreement. If the sender deletes their account, they are deleted fourteen days after the sender confirms, and every signer is sent their own copy first.
- Account records are kept while the account exists. When it is deleted, they go at the end of those fourteen days, except the payment records and the record of the deletion described under Deleting your account.
- Payment records are kept for as long as tax and accounting law requires, even after the account they belong to is deleted — from then on they are kept without any link to it.
- Sign-in security records are kept for 90 days, and are deleted with the account.
- Documents never sent can be deleted by the sender at any time.
Download your completed documents and keep your own copy. This is the single most useful thing you can do, whichever side of a signature you are on. The signed file, its certificate and its sealed record can be checked on their own merits and do not depend on you still having an account with us.
Deleting your account
You can ask to delete your account in two ways: in the app, from your Profile page (“Delete your account”), or on the web at sign.coresignapp.com/delete-account, with no app and no sign-in. Either way we email a link to the account’s address, valid for 60 minutes. Nothing happens until you open it and confirm by typing DELETE. If your account uses two-step sign-in, you also need to be signed in when you confirm. A plan that still renews has to be cancelled first, on your Profile page.
When you confirm
- Signing in stops at once, and your API keys are revoked.
- Documents still out for signature are withdrawn, and their signers are emailed that they were withdrawn.
- Everyone who signed a completed document is emailed their own link to download it, and the date it will be deleted.
- You are emailed a link that cancels the deletion.
Fourteen days later
Your account is deleted for good: the account and its sign-in details, every document — signed, in progress and drafts — with its files, and your templates, API keys and webhooks. Our payment processor is asked to delete your customer record, after every card stored with it has been disabled. We email you when it is done. The deletion runs early each morning, UTC, so it happens within a day of the date we give you.
Until then, the link in our email cancels the deletion. Cancelling restores sign-in; your API keys stay revoked, and withdrawn documents stay withdrawn.
What is kept, and why
- Payment records, because tax law requires them: each payment’s amount, any tax, where it was taxed, and the billing country, state and ZIP code it was taxed by — with no name, no email and no link to your account.
- A record that an account was deleted, and when, holding no name and no email, so that “was it deleted?” has an answer.
- For each completed document, a fingerprint of its seal in CoreSign’s permanent log, with no names or addresses. The log is only ever added to, never edited.
- Our encrypted off-site backups. Deleted data stays in them until they are cleared, and how long backups are kept has not been set yet.
Your rights
Depending on where you live, you may have the right to ask for a copy of the personal information we hold about you, to have inaccurate information corrected, to ask us to delete it, to object to or restrict certain processing, and to receive it in a portable form. Residents of the European Economic Area and the United Kingdom have these rights under the GDPR; residents of California have comparable rights under the CCPA, including the right not to be discriminated against for exercising them.
To delete your account you do not need to write to us: see Deleting your account. For everything else, write to coresign.support@corelegacystudios.com and we will respond. Two honest limits:
- Where a sender is the controller of a document, we will pass your request to them and act on their instruction rather than deciding for them.
- We will not alter or delete a completed sealed record in a way that would misrepresent a transaction another party relies on. Where we cannot delete something, we will tell you why.
Where your information is held
CoreSign is operated from the United States and information is processed there. If you are outside the United States, using the service involves transferring your information to it.
Children
CoreSign is not intended for children, and we do not knowingly collect information from anyone under 13. If you believe a child has provided us with personal information, write to us and we will remove it.
Security
Passwords are stored hashed, never in a recoverable form. Access to a document under signature requires an authorisation issued for that one person and that one document. Completed documents are sealed cryptographically, so alteration after the fact is detectable. How the seal works sets this out in full, including what we do not claim.
No service can promise perfect security, and we are not going to be the ones who do.
Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects how we handle personal information, we will make a reasonable effort to tell affected account holders directly rather than relying on you to re-read the page.
Contact
coresign.support@corelegacystudios.com reaches a person. Please say whether you are writing as a sender or as someone who was asked to sign — it lets us give you a useful answer first time.