Skip to content
TapSign

Privacy

What we hold, which is very little

Most of TapSign never touches us at all: you sign on your device, and signing does not upload the file. Everything below describes the parts that are optional, what each one puts on our server, and what your rights over it are.

Last updated 1 September 2026.

Who is responsible

The controller of the personal data described on this page is BILOUD SRL, a company registered in Romania, VAT number RO34723223, trade register number J2015002244239. TapSign is our own product; no other company operates it on our behalf.

We have not appointed a data protection officer. One is required of an organisation whose core activity is monitoring people on a large scale or handling special categories of data, and we do neither: the product is built so that we hold as little as possible and see none of the documents. If that ever stops being true, this page will say so and a name will appear here.

No email address is printed anywhere on this site, because an address in a public page is an address in a spam list within the week. Wherever this page says to write to us, it means the contact form, which reaches the same mailbox a printed address would.

Signing does not involve our servers

When you sign a document, nothing about it reaches us. The file stays on your device, the app computes a hash of it, the hash goes to your token or ID card, and the signature comes back from the chip. There is no upload step, no queue and no server that opens your file. We could not produce a list of what you have signed, because no such list has ever existed here.

Your PIN is passed to the chip over the local connection. It is not stored, not cached and not written to any log.

You can use TapSign this way indefinitely. Everything else on this page describes something you have to switch on first.

If you create an account

An account is optional, and signing works fully without one. It carries your settings from one of your devices to another, and if you turn on the vault it can also hold documents you choose to store. The list below is the account itself. The vault is described in the next section.

  • Your email address. It is the account, and it is how you sign in.
  • Your first name and last name, if you fill them in. Both optional, and used only to show you your own name.
  • Your phone number, if you enter one. Optional. We do not call and we do not send messages.
  • The devices signed in to the account: the name each one reports, its platform, its app version, and when it was last seen.
  • Your app settings: the signature style, the reason and place you sign with, the suffix a signed file is saved under, and whether your devices share one set of settings or each keep their own.

An account holds no certificates and no private keys. Documents reach us only if you turn on the vault, and then only as ciphertext we cannot read. Removing a device from the account signs it out and deletes the settings it was keeping for itself.

How you sign in

There is no password on a TapSign account, so there is no password of yours for us to lose. Three ways in exist and you can use whichever suits you.

  • A one-time code sent to your address. We store a keyed hash of the code, the moment it expires and how many times it has been tried. The code itself is not kept, and the row is useless a few minutes after it is written.
  • A passkey. We hold its public key, its credential identifier, the name you gave it and when it was last used. The private half never leaves your device or your password manager.
  • Sign in with Apple. Apple gives us an identifier for you and, if you allow it, your email address. If you choose Apple's private relay, what we receive is a forwarding address and we never see the real one. Apple offers your name once, on the first authorisation, and we use it only to fill a name field you left empty.

If you turn on the vault

The vault is optional encrypted storage for documents you want on all your devices. It does not exist until you enable it in the app, and it is the only part of TapSign that puts a document on our server.

What arrives is ciphertext. Each file is encrypted on your device with a key of its own, that key lives inside a manifest which is itself encrypted with your master key, and your master key reaches us only sealed under a secret we do not hold. We cannot read the contents of a file, its name, its type, or which folder it sits in. There is no column anywhere in our database that could hold a file name.

What we can see is the number of objects on an account, the size in bytes of each stored object, when each one arrived, when the tree last changed, and how many ways into the vault the account has and of what kind. That is the complete list, and it is the shape of the tables rather than a policy we could quietly change.

If you lose every way in, the documents are gone. No copy of your master key exists on our side, so there is nothing for us to recover from and nothing for us to hand to anybody who asks, including a court.

Read the published vault format

If you send a diagnostic report

A diagnostic report is a log of the technical exchange between the app and your token or card. It is off unless you turn it on, we only ask for it while chasing a specific fault, and nothing is sent until you press send.

The app strips file names and file paths before the report leaves your device. What arrives is the log, the device name, its platform and operating system version, the app version, build, channel and language, and, if you add them, a message and a screenshot. If you were signed in when you sent it, the report also carries your account identifier, email address and name, so that we can write back about it.

Reports are deleted ninety days after they arrive. A scheduled job reads the expiry date written into each report and removes it, so the deletion does not depend on anybody remembering.

The monthly usage summary

The app can send one summary a month: for each file extension, how many files and how many bytes. It is counted on your device, sent at a random moment well after the month it describes, and it carries no account, no device identifier and no token. The endpoint that receives it does not even accept one.

The row we store has a month, an extension, a count and a total. Nothing in it can be tied to you, or to another row, or to anything you uploaded. It is not personal data and it is not analytics: it exists so we can size the thing we are building, and it is designed so that reading it tells us nothing about anybody.

If you write to us

The contact form asks for your name, your email address, a subject and a message. The message is delivered to our mailbox and kept as ordinary correspondence. We use it to answer you and for nothing else: nothing is shared and nobody is added to a mailing list.

The form is protected by Cloudflare Turnstile, a check that the sender is a person rather than a script. Turnstile receives your IP address and a token from your browser. It sets no advertising cookie and does not follow you to other sites, but it is a third party, it is the only one on this website, and it appears on the contact page alone.

Cookies, addresses and counters

This site sets a session cookie and a request forgery token. Both are needed for the site to work: a form that cannot tell one visitor from another cannot be protected from a forged submission. There is no analytics cookie, because there is no analytics.

Your IP address is used to limit how often sign-in codes can be requested, how often a code can be tried and how often the contact form can be submitted. Those counters live in a cache, expire on their own within the hour, and are counters rather than a record of who did what.

Our web server keeps ordinary request logs, which include IP addresses, for security and for working out what broke. They rotate daily and the last five days are kept, after which they are gone. They are not joined to accounts and nothing is built from them. Backups of the database are taken and stay in the same Romanian data centre as the server, so a deleted account disappears from a backup as those backups age out rather than the instant you press the button.

Who else is involved

Two companies, in two limited contexts, and only if you go there.

  • Cloudflare, for the Turnstile check on the contact page, as described above.
  • Apple, if you choose Sign in with Apple. Apple knows that you signed in; we receive an identifier and, at your choice, an address.
  • Nobody else. No analytics, no tracking pixels, no advertising networks, no third-party fonts and no third-party scripts on any other page of this site. We do not sell data, share it for anyone else's purposes, or hold anything worth buying.

Where it is kept

On our own infrastructure in Romania, reachable only over TLS. BILOUD SRL owns the data centre, the servers, the racks, the switches and the routers, and is itself the internet provider: nothing about this is rented from a cloud. Sign-in codes and replies leave our own mail server, also in Romania. Your data is not copied to a provider in another country.

The one exception is the Turnstile check on the contact page, where Cloudflare may process your IP address outside the European Union. That transfer relies on the European Commission's standard contractual clauses.

Why we are allowed to hold it

Under the General Data Protection Regulation every use of personal data needs a lawful basis. Ours are these.

  • Your account, your devices, your settings and your vault: performance of a contract, Article 6(1)(b). You asked for an account, and what we agreed to do with it is carry your settings and, if you turn the vault on, hold the ciphertext you put there.
  • Sign-in codes, passkeys and the limits around them: performance of the same contract for the signing in itself, and legitimate interests, Article 6(1)(f), for keeping other people out of your account.
  • Diagnostic reports: your consent, Article 6(1)(a), given by switching diagnostics on and pressing send. You can withdraw it whenever you like, and withdrawing it does not make what came before unlawful.
  • Messages sent through the contact form, and the anti-spam check on it: legitimate interests, Article 6(1)(f), in answering correspondence and in not being buried by scripted submissions.
  • The monthly usage summary: it identifies nobody, so it is not personal data and needs no basis. If it ever could identify somebody, it would not be sent.

How long we keep it

Nothing is kept because it might be useful one day.

  • Your account and everything hanging off it: for as long as the account exists. Close it and all of it goes, including your devices, your settings, your passkeys and every encrypted object in your vault.
  • Sign-in codes: minutes. They expire on their own and the row is worthless afterwards.
  • Diagnostic reports: ninety days from the day they arrive, then deleted automatically.
  • Messages from the contact form: kept as correspondence while the matter is live and for a reasonable time after, so that a conversation can be picked up where it stopped. Ask and yours is deleted.
  • Rate limit counters: an hour at the most.
  • The monthly usage summary: kept indefinitely, because there is nobody in it to forget.

We do not send marketing

There is no newsletter, no product announcement and no offer, so there is no opt-out to find and nothing to unsubscribe from. The only email we send is about your own account: a sign-in code, a confirmation you asked for, a reply to a message you sent us.

This is not a promise we might revisit quietly. If that ever changed we would ask first, and it would be a thing you switch on rather than one you have to switch off.

Your rights, and how to use them

The Regulation gives you rights over your own data. None of them costs anything and none of them needs a reason.

  • Access: a copy of what we hold about you and an account of what it is for.
  • Rectification: anything wrong put right. Your name and phone number you can change yourself on the account page.
  • Erasure: your account and everything on it deleted. This one you do yourself, from the button at the bottom of the account page, and it happens as you press it.
  • Portability: what you gave us, handed back in a machine-readable file, or sent directly to another provider where that is technically possible.
  • Objection: you can object to anything we do on the basis of legitimate interests, and we stop unless we can show grounds that override yours.
  • Restriction: you can require us to hold data without using it while a disagreement about it is being settled.
  • Withdrawing consent: for diagnostics, at any moment.
Ask through the contact form

The one request we cannot fill

We cannot give you your vault in readable form, because we have no key to it. What we can hand over is exactly what we hold, which is ciphertext, its sizes and its timestamps. Only you can turn that back into documents.

This is the same reason we cannot open a vault for a court, a police force or anyone claiming to be you. It is not a policy we could be persuaded out of. There is no key here to be compelled to use.

If you want to complain

Tell us first, through the contact form, and we will look at it properly. If that gets you nowhere, you have the right to complain to the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul General Gheorghe Magheru 28-30, Sector 1, cod 010336, Bucharest, dataprotection.ro. You can also go to court, and complaining to the authority does not stop you doing that.

What we do not do

No profiling and no automated decision-making. Nothing in TapSign decides anything about you.

No selling, renting or sharing your data for anybody else's purposes, and no advertising anywhere in the product or on this site.

TapSign is not aimed at children, and a qualified certificate is not something a child holds. We do not knowingly hold data about anyone under sixteen. If you believe we have, tell us and it will be deleted.

When this page changes

The date at the top changes with it. If a change matters to you rather than only to a lawyer, we will say so on the site, and by email to anyone with an account, before it takes effect.

This page describes what the product does today. If you find a place where the page and the software disagree, the software is the bug, and we would like to hear about it.

Questions about any of this

Write to us through the contact form and say which part you mean. Requests about your own data go the same way. There is no separate address to hunt for: the form reaches the mailbox a printed address would, without printing one for the scrapers.

Contact