← talyana.ai

Privacy Notice

Last updated August 9, 2026

This notice explains what Talyana Sign collects, why, and what happens to it — written to be read, not skimmed past. The short version: we collect what an e-signature service needs to work and to produce trustworthy evidence, we send no marketing, we show no ads, and we never sell data.

Our two roles

For your account information, we decide how data is handled — we act as the data controller. For the contents of envelopes — the documents, fields, and signer information a sender puts into the Service — we process that data on the sender's behalf and instructions, as a processor. The sender is responsible for having the right to send those documents and for their signers' data; signers with questions about a document they were asked to sign should contact the sender first.

What we collect

Account information. Your name, email address, password (stored only as a secure hash), and your organization's name — which appears to signers as the sender of your documents.

Documents and envelope data. The documents you upload, the fields you place, the values signers enter, and the names and email addresses of the people you send documents to.

Signing evidence. E-signature laws favor good records, so when someone views, consents, signs, or declines, we record the action with a timestamp, IP address, and browser type in a tamper-evident audit trail. Signers may optionally share their device's precise location as additional evidence — this is opt-in at the moment of consent and never required to sign.

Operational basics. Standard server logs (IP addresses, requests, errors) kept for security and troubleshooting.

What we don't collect

No advertising trackers, no analytics beacons following you around the web, no selling or renting of personal information — signers especially are never marketed to, upsold, or asked to create an account. We don't use your documents to train anything or for any purpose other than providing the Service. Because we do no cross-site tracking at all, browser "Do Not Track" signals don't change anything — there is nothing to turn off.

Why we're allowed to process it

Where the law asks us to name a basis: we process account data to perform our contract with you; envelope data on the sender's instructions; signing evidence for our and our customers' legitimate interest in reliable, tamper-evident records (and the sender's compliance needs); optional geolocation only with the signer's consent; and anything else where a legal obligation requires it.

How we use information

To operate the Service: delivering signing requests and reminders, guiding signers through documents, stamping and sealing completed envelopes, producing certificates of completion and audit trails, verifying sealed documents, enforcing plan limits, preventing abuse, and providing support. Emails we send are transactional — signing requests, reminders, completions, verification, and password resets.

Who can see what

The sender of an envelope can see its signers' progress and completed values. Signers see the document sent to them and their own signing session. Our staff access customer content only when needed to provide support you've requested or to investigate abuse, and we treat everything in your envelopes as confidential.

Service providers and other disclosures

We use a small number of infrastructure providers to run the Service: DreamHost (hosting and database), MailChannels (email relay used by our hosting provider), Microsoft 365 (Word-to-PDF conversion, when you upload a Word document), and content-delivery networks for standard software libraries. Each receives only what's needed to perform its function. Beyond that, we disclose information only when we believe in good faith it's required by law or legal process, or necessary to protect the rights, safety, or integrity of the Service, our users, or the public. If Talyana Sign is ever involved in a merger, acquisition, or sale of assets, data may transfer as part of that transaction — under this notice's protections, with notice to account holders.

Where data lives

The Service is operated from the United States and data is stored and processed there. If you use the Service from elsewhere, you're sending your information to the U.S., where privacy laws may differ from your jurisdiction's.

Third-party sites and embeds

Documents can link anywhere, and customers can embed the signing experience in their own websites. Those sites are theirs, not ours — this notice covers only the Service itself, and we're not responsible for the privacy practices of sender websites, embedded contexts, or links inside documents.

Retention and deletion

Envelope documents are retained according to the sender's settings, and audit trails are kept for the life of the envelope record because they are the evidence that makes a sealed document trustworthy. Account information is kept while your account is active. To close your account or request deletion, email support@talyana.ai — we'll confirm what can be deleted and what must be retained, because deleting the evidence record of a document other parties have signed would defeat the purpose everyone signed it for, and some records must be kept where the law permits or requires it. Deleting certain data may make parts of the Service unusable for you.

Your rights

You can ask us to access, correct, export, or delete your personal information (subject to the retention realities above) by emailing support@talyana.ai. California residents: we don't sell or "share" personal information as the CCPA defines those terms, so there's nothing to opt out of; your access, deletion, and non-discrimination rights work through the same address. If you're a signer, requests about a document's contents go to its sender, who controls that envelope.

Security

Traffic is encrypted in transit (TLS). Passwords are stored as salted hashes. Completed documents are sealed with Ed25519 cryptographic signatures, and audit trails are hash-chained so tampering is detectable. Access codes for protected envelopes are stored hashed. No system is perfectly secure and we can't guarantee absolute security, but verifiability is the core of this product and we build accordingly.

Children

The Service is not directed to children and accounts may only be created by adults. Documents sent through the Service may lawfully involve minors (for example, a parental consent form), but the account holder is responsible for the appropriateness of those documents.

Changes and contact

If we make material changes to this notice, we'll tell account holders by email or in the console before the changes take effect. Questions, requests, or concerns: support@talyana.ai.