Privacy Policy
Themoonknows operates SignFlow eSignature, an add-on that lets a document owner collect an electronic signature from another person.
Google account access
SignFlow requests six OAuth scopes: openid and userinfo.email authenticate the sender; documents.currentonly accesses only the open document; drive.file accesses files opened or created with SignFlow; script.external_request calls our backend; and script.scriptapp schedules delivery checks. We never request Gmail or broad Drive access.
Data we process
| Data | Purpose | Storage |
|---|---|---|
| Sender and signer email addresses, document title | Ownership, status, one-time codes, and reminders | Cloudflare D1 |
| Source and executed PDFs | Field placement, signing, and delivery | Cloudflare R2 |
| Field positions and submitted signature/date/text values | Stamp the executed PDF | D1 and the executed PDF |
| Event times, IP address, and user agent | Security and signature audit certificate | D1 |
| Hashed signing tokens and one-time codes | Authenticate without storing usable credentials | D1 |
Retention
Source PDFs are permanently deleted seven days after a request is signed, cancelled, or expires. Signing requests expire after 30 days and email codes after 10 minutes. Executed PDFs and audit records remain available as the sender's signature record while the account is active. You may request deletion at any time.
Processors
Cloudflare provides Workers, D1, and R2 infrastructure. Resend delivers transactional email. Dodo Payments acts as merchant of record for paid subscriptions. We do not receive full card or bank details, sell personal data, or use document data to train models.
Your choices
Revoke Google access at Google Account permissions. To request access, correction, export, or deletion, email hello@themoonknows.com.
Contact
Themoonknows
Sinhgad Road, Pune, Maharashtra 411030, India
hello@themoonknows.com