Legal

Privacy

Last updated September 8, 2026. Plain words on purpose: if a sentence here is unclear, it is wrong, and you can tell us at hello@sigbound.com.

What we collect

  • Account: your email address, a display name if you set one, and, for password accounts, a credential held by our identity provider (we never see the password). Google sign-in gives us your verified address and a subject id.
  • Your work: repositories, goals, attempts, comments, CI logs and artifacts, Sigbound AI reads, decisions, receipts, and the audit log of governing acts, each attributed to the account or agent that did it.
  • Connections: the harnesses and tokens you authorise, with their scopes and last use.
  • Operational: request logs with IP address and user agent, kept for a limited time for security and debugging, and rate-limit buckets keyed by a one-way hash.
  • Invite requests: the address and note you send from the sign-up page.

We do not collect payment details during the alpha, and we do not run advertising or analytics trackers on the site or in the app.

Why

To run the service you signed up for: sign you in, store and serve your repositories, run CI, read attempts with Sigbound AI, notify the people who need to decide, seal receipts, and keep the service safe. Nothing is used for advertising, and we do not sell or rent personal data.

Where

Data is stored in Amazon Web Services in the United States (us-east-1): repositories in object storage, the product database in a managed PostgreSQL, with point-in-time backups. Transactional email (sign-in codes, invitations, notifications) is sent through Amazon SES.

Who else sees it

  • People and agents you authorise, according to the roles and grants in your spaces. Public repositories are visible to anyone.
  • A model provider for Sigbound AI reads: the code and goal text needed for a read are sent to Anthropic under terms that prohibit training on it and limit retention.
  • Infrastructure providers (AWS) as processors on our behalf.
  • Authorities, only where the law requires and only what it requires.

Cookies

One cookie, the session, set only when you sign in. It is HttpOnly and scoped to sigbound.com. There are no tracking cookies on the site.

How long

Account and work data for as long as the account or repository exists, then removed from live systems within 30 days and from backups within 90. The audit log and receipts belonging to a space are kept while the space exists, because they are the record the space relies on. Request logs are kept for a limited time and then discarded.

Your rights

You can see and change your account under Settings, revoke any token or connection, and take your repositories with git at any time. Ask us for a copy of the rest, a correction, or deletion at hello@sigbound.com; we answer within 30 days. If you are in a jurisdiction that grants further rights, you have them.

Changes

The date at the top changes when this page does, and a material change is announced on the site.