Privacy Policy
Last updated July 29, 2026
Penstead is a document preparation and electronic signature service: you fix a document and then send it out to be signed. Preparing it happens in your browser rather than on our servers. This policy explains exactly what happens to your files, what data we collect, and the choices you have. Plain language, no dark patterns.
What happens entirely in your browser
The following never upload your document — they run on your own device and the file never touches our servers:
- Viewing, reading, and searching PDFs
- Editing text, annotating, signing yourself, and adding watermarks
- Organizing, cropping, rotating, numbering, compressing, and redacting
- Filling PDF forms
- Text recognition (OCR)
- Converting images and plain text to PDF
A ZIP file is unpacked in your browser too, but every file inside it is then handled by its own rule: images, plain text, and PDFs stay local, while any Word, Excel, PowerPoint or OpenDocument file inside the ZIP goes to our conversion service exactly as a loose one would. So a ZIP is only fully local if everything in it is.
Features that use a server
Two things send your document off your device:
- Converting Office files (Word, Excel, PowerPoint, OpenDocument, RTF, HWP), including ones found inside a ZIP. The file is sent to our conversion service, rendered to a PDF, and then deleted — held only for the moments the conversion takes. A file whose conversion is abandoned is swept within the hour. Images, plain text and PDFs are converted in your browser and do not leave your device.
- Request signatures.When you send a document out for others to sign, the document, the recipients’ names and email addresses, everything they type into the fields, and an audit trail are stored so the signing process can complete and so the signed copy can be produced later. We email each recipient their signing link, and when everyone has signed we email you and them a confirmation with the signed document attached, so nobody depends on us to keep their copy. Those emails leave our systems permanently — we cannot recall or delete a message once it has been delivered, or the copy it carried.
We never sell your documents, never use them to train models, and never access their contents except as required to perform the action you asked for.
Accounts
You do not need an account. Every tool works signed out, and signing in does not unlock any tool — it raises the limits on the few things our servers do for you, and gives you one place to find documents you have sent.
If you do sign in, we store:
- Your email address. There are no passwords. We email you a single-use link that expires in 15 minutes, and that link is stored only as a one-way hash — we cannot read it back out.
- A session.A cookie holding a random token, stored on our side as a one-way hash, alongside your browser’s user-agent string and a salted hash of your IP address, so you can see and revoke where you are signed in. We do not store the address itself.
- Rate-limit counters keyed to your account, so limits follow you rather than your network.
If you subscribe, Stripe handles the payment. Your card details go to Stripe and never reach our servers; we keep the Stripe customer and subscription identifiers, your plan, and when the current period ends. If you email us or we email you, we keep a record of what was sent and whether it arrived — see below.
What we log
Signing is the one place where we record data about people other than you, so it is worth stating plainly. Each time a signature request is viewed, signed, downloaded, or declined, we store an audit entry with the time, the action, and the IP address and browser user-agent of whoever performed it. That trail is what makes an e-signature defensible, so it is also printed onto the Certificate of Completion pageattached to the finished PDF — meaning every signer’s IP address and browser are visible to everyone who receives the signed document, and to the sender in their management view.
If you send someone a signature request, please tell them this. Under GDPR an IP address is personal data, and they are agreeing to it through you rather than through us. If you send us a message through the contact form, we store your message, the email address you optionally give us, and your IP address, to handle abuse reports and rate-limit the form.
Analytics and cookies
We use Google Analytics to count visits and understand which tools get used. Analytics records standard usage data — pages viewed, approximate region, device and browser type — and sets its own cookies. It never receives the contents of your files, and never your email address. Google is an advertising company, so while we run no ads, sell no data and embed no ad-network pixel, we cannot claim this data is untouched by advertising infrastructure.
Any content blocker or “do not track” setting will stop it. Everything on the site works identically either way.
Separately from Analytics, we keep our own count of a few product events so we can tell whether the free plan is the right size. Those are described under Data retention below, they are first-party, and they never contain file names or contents.
Attribution cookie.When a link carries a campaign tag — the ?utm_source=you can see in the address bar — we store that tag, and only that tag, in a cookie for 90 days, so that if you later create an account we know which post or message brought you here. It holds up to three short words such as reddit|social|landlord. It contains no identifier for you, is never sent to anyone else, and is not set at all if you reach us by search, by typing the address, or by any untagged link.
Data retention
How long each thing lasts, and why:
- Files edited locally: never stored by us at all.
- Files sent for conversion: held only for the moments the conversion takes, then deleted. A file whose conversion is abandoned is swept within the hour.
- Signature requests: retained indefinitely. Voiding a request stops anyone opening the link, but it does not erase the document, the recipients, the field values, or the audit trail — the record has to survive so a completed signature can be proven later, and the other signatories rely on that as much as you do. If you want one erased outright, ask us.
- Sign-in links: unusable after 15 minutes or one use, and the rows are deleted within a day.
- Sessions: expire after 30 days, sooner if you sign out, and are removed a week later.
- Email records:which messages we sent you and whether they were delivered, kept as long as the account, because “did they get it?” is the question a signature request most often turns on. Addresses that hard-bounce or report us as spam are kept on a suppression list so we never mail them again.
- Rate-limit counters: hours to a day.
- Product measurement: 12 months. We record when someone signs up, first uses a server-side feature, hits a plan limit, or subscribes — so we can tell whether the free allowance is the right size. These records carry the event, your account if you have one, and a salted hash of your network address if you do not. They never contain file names or file contents.
- Account records: until you close the account. Payment records are kept by Stripe for as long as tax and accounting rules require, independently of us.
Closing your account does not delete documents you have already sent for signature. Signature requests keep working, because other people hold those links and have a legal record that depends on them. If you want a signature request removed, ask us.
Sub-processors
These are every third party that can touch your data, and what each one is for. We do not sell data to any of them, and none of them receives your documents except where noted.
- Vercel — hosting. Sees requests to the site.
- Supabase — database and private file storage. Holds signature requests, accounts and sessions.
- Google Cloud Run — the document-conversion service. Office files pass through it and are not retained.
- Stripe — payments. Receives your card details directly and your email address; we never see the card.
- Resend — email delivery. Receives the recipient address and the message we send, and — when a signature request is completed — a copy of the signed document, which is attached to the confirmation email so both parties keep one.
- Google Analytics — usage measurement. Never receives your files or your email address.
Your rights
Depending on where you live (for example the EU/UK under GDPR, or California under CCPA), you may have the right to access, correct, export, or delete your data, or to object to processing. You do not have to ask us for most of it:
- Export. “Download my data” on your account page returns everything we hold about you as one JSON file, including what we deliberately leave out and why.
- Deletion.“Close my account” on the same page removes your account and signs you out everywhere. Read the note on retention above first: documents you have already sent are not removed by it.
For anything else — a signature request erased outright, or a request from someone who signed a document rather than sent it — contact us and we will handle it.
Children
Penstead is not directed to children under 13 and we do not knowingly collect their data.
Changes
We may update this policy as the product evolves. Material changes will be reflected by the “last updated” date above.
Contact
Questions, data requests, or abuse reports: get in touch or email hello@penstead.com.