Legal
Privacy Policy
This policy explains what personal data Cosignet processes, why, on what legal basis, who we share it with, and the rights you have. We keep it plain and honest.
Last updated: 18 June 2026.
Who we are
Cosignet (“we”, “us”) provides a hosted service that pauses high-risk actions and requires an explicit, payload-bound passkey approval. For any privacy matter, contact privacy@cosignet.com.
For account, security, billing, support, and service-administration data, Cosignet acts as controller. For approval payloads, approver metadata, and workflow data submitted by a customer for its own processes, Cosignet generally acts as processor under the customer's instructions, subject to the applicable Data Processing Agreement. The customer remains responsible for deciding what payload data is submitted to Cosignet and for ensuring it has a lawful basis to do so.
What we collect
- Account & contact data — the email address you submit to the waitlist or that is linked to your customer account; optional name/company/use-case from the waitlist form.
- Approval data — the action label and the payload you send for each confirmation. We store the payload because the approver must see exactly what they are signing and we hash it to bind the signature. Keep secrets out of payloads — pass references (IDs) instead of raw sensitive data.
- Public reveal (opt-in, off by default) — if you flag an individual confirmation for public reveal, its action, payload, and a PBKDF2 hash of the account's designated verified email are published permanently and irreversibly to our public transparency log, where anyone can read them. We do this only on your explicit instruction per request; an account owner or admin chooses this accountable-party address from a member email already verified by magic-link sign-in. It is not the individual signer's identity. Do not enable public reveal for confirmations containing personal or sensitive data.
- Authentication data — WebAuthn/passkey public credentials and the raw assertion produced on approval (our audit trail). The passkey private key is generated and protected by your authenticator; on many platforms this uses secure device hardware. We never receive or store it.
- Optional notification identifiers — a Telegram chat ID, only if you link Telegram notifications.
- API keys — stored only as a SHA-256 hash plus a short prefix; the full key is shown once at creation and never again.
- Technical/security data — your IP address and a bot-protection token are processed by Cloudflare Turnstile on our public forms (waitlist, registration) to prevent abuse. We do not run cookie-based analytics, advertising, or cross-site tracking. We use Cloudflare Web Analytics for aggregate, cookieless site metrics.
Why we use it & legal bases
- Provide the service (create and display approvals, authenticate you, keep an audit trail) — performance of a contract.
- Security & abuse prevention (Turnstile, rate limiting, fail-closed logging) — our legitimate interest in protecting the service and users.
- Service communication (invites, magic links, approval and usage notifications you enable) — performance of a contract / your request.
- Public reveal (publishing an approval's action, payload, and the account's designated verified-email hash when you opt in) — your explicit instruction/consent for that confirmation.
Sub-processors
We use a small set of providers to run the service:
- Cloudflare — hosting (Workers), database (D1), email routing, Turnstile bot protection, and cookieless Web Analytics (aggregate, no personal data).
- Resend — delivery of transactional email (invites, magic links, notifications).
- Telegram — only if you link Telegram notifications; the action label and approval link are sent to your linked chat.
Some providers may process data outside your country; where required we rely on appropriate safeguards (e.g. Standard Contractual Clauses).
Retention
During early access, confirmations (action, payload, hash, status, and the raw assertion once approved) are kept until you request removal. Avoid placing personal, secret, or sensitive data in payloads and pass references or IDs where possible. Ephemeral records (login/registration challenges, magic links, and short-lived sessions) expire automatically. Configurable automatic retention, aligned with the audit-history windows in our pricing (for example 7 days, 90 days, or 1 year by plan), is planned for paid and enterprise accounts; until it ships, confirmations persist until deletion is requested.
Public reveal is permanent. Once an approval is published to the public transparency log, its revealed action, payload, and account-designated email hash are part of an append-only, externally-anchored record and cannot be retracted, even if the underlying confirmation is later deleted. Only opt in when public, permanent disclosure is intended.
Your rights
Subject to applicable law (including the GDPR), you may request access, rectification, erasure, restriction, portability, or object to processing. To exercise any of these, or to ask about deletion, export, or data residency, contact privacy@cosignet.com. You also have the right to lodge a complaint with your local data-protection authority.
Cookies & security
We use only strictly-necessary cookies and run no tracking — details on the Cookie Policy. For how we secure data and bind approvals, see Security.
We may update this policy; material changes will be reflected by the “last updated” date above.