Privacy Policy
Last Updated: July 24, 2026
1. Introduction
Kychee, Inc. ("Kychee," "we," "us," "our") operates the kysigned service (kysigned.com). This Privacy Policy explains how we collect, use, store, and protect your personal information.
2. Information We Collect
2.1 Senders (Document Creators)
- Email address (used for passkey or magic-link sign-in and notifications)
- An optional display name you choose
- Payment for credit purchases — handled by Stripe, our payment processor. You pay by card on Stripe's pages; kysigned never receives or stores your card details.
2.2 Signers
- Email address and name (as provided by the sender)
- The signing-request email that the signer forwards back. This email — which their own provider has DKIM-signed — is the signature. It is embedded, complete, inside the signing record delivered to every party, and is held by our email infrastructure only as long as needed to assemble that signing record.
- The timestamp of the signing event, which we anchor with independent timestamp authorities (RFC 3161 and OpenTimestamps)
2.3 Documents
- PDF documents uploaded for signing (the working copy is retained for a limited period, then deleted — see Section 5)
- The SHA-256 hash of the document (retained as metadata)
2.4 Automatically Collected
- Server logs (IP address, request timestamps, user agent)
- Analytics data via Google Analytics 4 (see Section 7)
3. How We Use Your Information
- To provide the e-signature service (creating signing requests, sending notifications, assembling and delivering signing records)
- To authenticate your sign-in (passkey or magic link)
- To send transactional emails (signing requests, reminders, confirmations, completion notices)
- To comply with legal obligations
- To improve our service
We do NOT sell your personal information. We do NOT use your documents to train AI models. We do NOT share your information with third parties for marketing purposes.
4. The Signing Record
When all signers have signed, we assemble an signing record — a single PDF containing the document, a signature page, each signer's original signed email, independent timestamp proofs, and the relevant public keys — and email it to every party. The signing record is the permanent record of the signing, and it contains each party's name and email address. Because it is delivered to each party's own mailbox, a signing record once sent cannot be recalled by us, as with any email.
For your convenience, kysigned also keeps a database of the documents you send: document names, document hashes, signer names and emails, signing timestamps, and statuses. When you delete your account (see Section 8), that record is permanently deleted, and any unused credits are forfeited and not refunded.
5. Data Retention
| Data Type | Retention Period |
|---|---|
| PDF working copy | Deleted shortly after the signing record is delivered to all parties (typically hours). Up to 7 extra days if a completion email bounces. Hard maximum 30 days from completion, regardless of state. |
| Unsent document held for sign-in | When you prepare a document and ask us to email you a sign-in link, we hold that document and its recipient list so the link works from any device, including your phone. Only you can open it: either by signing in with the address you gave, or from the secure link in the email we sent to that same address. It is never sent to anyone until you complete sign-in, and it is deleted the moment it is sent or after 7 days, whichever comes first. |
| Signed emails (during signing) | Held by our email infrastructure only until the signing record is assembled; the permanent copy lives inside the delivered signing record. |
| Document/signing metadata | Retained until you request account deletion |
| Server logs | 90 days |
| Payment records | As required by law (typically 7 years) |
6. Data Sharing
We share data with:
- run402 — the platform providing our compute, database, email delivery, and storage
- Stripe — our payment processor. We share the purchase amount and your email; your card details are entered on Stripe's pages and never reach kysigned.
- Public timestamp authorities (RFC 3161 / OpenTimestamps) — they receive only the cryptographic hash of a signed email, never its contents or your identity
- Public DKIM-key archives — used to make signatures independently verifiable; they receive only provider domain and key-selector information, never your data
- Google Analytics 4 — aggregate site usage (anonymized, never linked to your account)
- Advertising platforms (Google Ads, Meta Ads, and similar) — only when running paid campaigns, and only aggregate conversion events (e.g., "a visitor completed signup") tied to the referring campaign, NOT your account details, document contents, or signer data. We do not upload customer lists or build retargeting audiences.
- Law enforcement — only when required by valid legal process
7. Cookies, Analytics, and Marketing Attribution
We use:
- An essential session cookie — an HttpOnly cookie set on passkey or magic-link sign-in to keep you authenticated. It carries no personal data, only an opaque session identifier.
- Browser storage — for non-secret preferences such as your cookie-consent choice.
- Google Analytics 4 (GA4) — for aggregate usage analytics, loaded only after consent where consent is required. GA4 sets
_gaand_ga_*cookies (2 years) to assign anonymous client IDs. We do not link GA4 data to your kysigned account. - Marketing attribution storage — when you arrive via a paid advertising campaign, we capture URL parameters such as
gclid,utm_source,utm_medium,utm_campaign,utm_term, andutm_contentin your browser'slocalStorage. Ad platforms may also set their own cookies (_gcl_aufor Google Ads,_fbp/_fbcfor Meta). We use these to measure which campaigns deliver actual users — not to build cross-site profiles or to retarget you. If you sign up after clicking one of our Google ads, we keep that click's identifier with your account and report the resulting conversion events (sign-up, first document sent, credit purchase and its amount) to Google Ads against that identifier — never your name, email address, or documents. Where the consent banner applies, your recorded choice accompanies these reports. - First-party page and click counting — we count page and click activity on our public pages without identifiers: these counts contain no account, cookie, device, or network identifier of any kind, cannot be linked to you, and work identically whatever you choose in the consent banner. If the link you arrived on carries a campaign tag (such as
utm_campaign), we include that tag — a label of our own advertising campaign, shared by everyone the campaign brings and never unique to you — in these counts.
We do NOT:
- Sell your data to advertisers
- Build cross-site behavioral profiles
- Retarget you across the web after you leave the site
- Share your kysigned account data with advertising platforms
You may manage non-essential cookies via the "Cookie settings" link in our footer, or disable cookies in your browser settings. See our Cookie Notice for full details.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data
- Correct inaccurate personal data
- Delete the data we hold about you (a signing record already delivered to recipients cannot be recalled — see Section 4)
- Export your data in a portable format
- Opt out of non-essential analytics tracking
To exercise these rights, contact legal@kychee.com.
To delete your kysigned account, email legal@kychee.com — from the email address your account uses — with "DELETE MY KYSIGNED ACCOUNT" in the subject line. We delete the kysigned account belonging to the sending email address. All data we hold about you is then permanently deleted; any unused credits are forfeited and are not refunded (see the Terms of Service), and signing records already delivered to recipients cannot be recalled (see Section 4).
9. Legal Basis for Processing (EU/EEA Users)
If you are located in the EU or EEA, we process your personal data on the following legal bases under GDPR:
- Contract performance (Article 6(1)(b)) — processing necessary to provide the e-signature service you requested (document sending, signing, notifications, signing record delivery, verification)
- Legitimate interest (Article 6(1)(f)) — server logs, service improvement, fraud prevention, and aggregate analytics
- Consent (Article 6(1)(a)) — marketing cookies and non-essential analytics (collected via the consent banner; withdrawable at any time via the "Cookie settings" link)
- Legal obligation (Article 6(1)(c)) — retention of payment records as required by tax and financial regulations
We do not hold any formal GDPR certification (such as a code of conduct or GDPR seal). We comply with GDPR requirements through the technical and organizational measures described in this policy, including data minimization (working copies are ephemeral; signed emails are retained only inside the signing record delivered to the parties), purpose limitation, and the rights described in Section 8.
10. Children's Privacy
kysigned is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.
11. International Transfers
Our service is operated from the United States. If you access the service from outside the US, your data may be transferred to and processed in the US. For transfers from the EU/EEA, we rely on Standard Contractual Clauses (SCCs).
12. Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, and access controls. We hold no signing keys of any kind — neither for users nor for sealing documents — so there is no signing key for an attacker to steal. However, no system is perfectly secure. You are responsible for securing your sign-in method (your passkey device or email account).
13. Changes to This Policy
We may update this policy. Material changes will be communicated via email and/or website notice at least 30 days before taking effect.
14. Contact
Kychee, Inc. Email: legal@kychee.com Data protection inquiries: legal@kychee.com