SignThix

SignThix · Effective September 14, 2026

Privacy Policy

How SignThix handles documents, account information and optional mailbox connections.

1. About SignThix

SignThix is a web application for preparing PDF documents, requesting signatures, following signing progress and producing signed documents with completion records. The service is operated from Israel and is available at signthix.com.

This policy covers the SignThix website and application, including optional mailbox connections. If someone sends you a document, that sender also determines which document and recipient details to provide and why to request your signature.

For privacy questions and access, correction or deletion requests, contact our shared Thix support address: support@notethix.com.

2. Information the service processes

These data support document preparation, delivery, signing, verification, completion records and the account features you use. The site uses browser storage for preferences and the application uses it for authentication state. OAuth connection-state cookies support the mailbox authorization flow.

3. Connecting Gmail

Connecting Gmail is optional and separate from signing in to SignThix. You begin in Settings and approve the requested permissions on Google's authorization screen. SignThix does not receive your Google password through this connection.

The integration requests openid, email, profile and https://www.googleapis.com/auth/gmail.send. It uses the returned email address to identify the connected mailbox. The current integration does not use your Google profile name or photo.

Gmail's sending permission allows SignThix to send signature invitations, reminders you request or configure, and completion notifications from the connected mailbox. Messages can contain recipient names and email addresses, document titles, signing or download links, and the branding or signature images selected for the workflow.

This connection does not read existing inbox messages, search mailbox history, import Google contacts or access Google Calendar or Google Drive.

4. Google connection storage

SignThix stores the connected mailbox email, Google access and refresh credentials, granted permissions, token expiry and connection timestamps in server-side storage hosted by Netlify. The server uses the refresh credential to renew an expired access credential when the connected-mailbox feature needs it.

The account connection screen shows the mailbox and connection information. It does not return the stored Google credentials to the browser. The saved connection remains until it is disconnected, replaced or removed after an invalid connection is detected.

5. Recipients and service providers

Google processes authorization and Gmail sending requests. The people selected in a document workflow receive the messages and document links that the workflow sends.

Data shared through these features depends on the selected workflow. Recipients and configured webhook destinations do not receive stored Gmail access or refresh credentials as part of the workflow payload. These services operate infrastructure in different countries; SignThix information is not represented as being held within a single region.

6. Google user data and Limited Use

SignThix's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, and the Google Workspace user data and developer policy.

Google user data will be used only for the connected-mailbox features disclosed here. It will not be sold, used for advertising or used to train general-purpose AI models. Transfers and human access will be limited to the circumstances permitted by those policies, including a user-authorized feature, necessary security work or legal requirements. These commitments apply to people and service providers working on SignThix's behalf.

7. Disconnecting a mailbox

You can disconnect Gmail in SignThix Settings. This removes the saved connection from active integration storage and stops later sends that depend on that connection. A send already in progress may finish.

Disconnecting does not delete previously sent emails, documents, signing records or your SignThix account. It also does not itself revoke the Google authorization grant. You can separately manage or revoke SignThix access through your Google Account connections. Revoking access cannot remove messages already received by someone else.

8. Retention and deletion

Account, document and audit records do not currently have a general age-based expiry in the application. They remain in application storage unless removed through the available controls or an administrative deletion process. Mailbox connection records follow the lifecycle described above.

The document controls let an account owner request deletion of a document. A document deletion does not guarantee deletion of every separate audit record, previously delivered copy or infrastructure backup. The application does not currently offer a self-service account-deletion control.

For account deletion or data that the available controls do not cover, email support@notethix.com. Identify the account and the request without sending passwords, authentication tokens or an unnecessary copy of the document. Identity or authority may need to be checked before a request is carried out.

9. Handling information

The public site and application use HTTPS. Account authentication and server-side access checks control application requests; optional mailbox authorization is handled through the provider's OAuth flow. This policy does not claim a security certification, application-level encryption of every stored field, or an absolute security guarantee.

Protect your sign-in credentials and document links. Report suspected unauthorized access through the contact below without including a password, token or signing link in an initial message.

10. Changes and contact

This page will identify the date of a published revision. Before Google data is used for a new purpose beyond the disclosure originally approved, SignThix will update its disclosure and obtain the consent required by Google's policies.

Service: SignThix, operated from Israel
Shared support and privacy contact: support@notethix.com
Website: signthix.com