Privacy
Privacy Policy
Signata is a product about evidence, so this page tries to be evidence rather than assurance. Every claim below is checkable against what the app actually does.
Effective 7 August 2026 · StacknScope Inc.
The whole thing, in eight lines
- There is no Signata account, and no server that receives anything you record.
- No analytics, no telemetry, no crash reporting, no tracking.
- Signata has no location code and never asks for location permission.
- Your event history stays in Signata's container on your Mac unless you export it yourself; evidence always stays in the container.
- Nothing leaves your Mac unless you configure an alert channel — and then only an event kind, a local timestamp, a summary, and this Mac's name.
- Evidence files are never attached to alerts. Ever.
- Signata asks signata.app whether a newer version exists. It sends nothing about you, and you can switch it off.
- Buying it leaves your email address and the license issued to it in one small table, so the license can be sent to you again. Licensing itself makes no network request at all.
What Signata records
While armed, Signata records physical events on the Mac it runs on: wake and sleep, screen lock and unlock, USB attach and detach, volume mount and unmount, display changes, and audio output changes. Each entry carries a timestamp, an event kind, a summary, and local context such as the machine name, the user name, and where available the battery level, the network name, and the reason the Mac woke.
With Evidence Mode enabled — off by default — Signata may also create a camera snapshot or a desktop screenshot after a configured event. Screenshots can contain whatever was on your display.
What never leaves your Mac
Stated affirmatively, because "we do not sell your data" is a low bar:
| Event history | Stays in the app container unless you export it yourself. Exports go where you choose and are never transmitted. |
|---|---|
| Evidence files | Stay in the app container. Never transmitted, never attached to an alert. |
| Location | Not collected. No location code exists in the app. |
| Usage and analytics | Not collected. There is nothing to collect it with. |
| Credentials | Stored in the macOS Keychain, never in preferences or logs. |
What your events can leave in
If — and only if — you enable an alert channel and supply your own credentials, Signata sends an event kind, a local timestamp, a summary, and this Mac's name to that channel. The machine name is there so that someone running Signata on more than one Mac can tell which machine an alert came from. Two channels are supported:
- Telegram, through a bot you create, to a chat you choose.
- An HTTPS webhook, to any endpoint you nominate.
Both are third-party services chosen and configured by you. Whatever you send them is subject to their terms, not ours, and StacknScope Inc. has no visibility into either. Alerts go straight from your Mac to the service you named; they are never proxied through anything we operate.
Checking for updates
Signata asks signata.app whether a newer version exists.
This is the only request the app makes on its own, and you can turn it
off in Settings ▸ General.
The request carries nothing about you, your Mac, or anything Signata has recorded — it fetches a public file listing the current version. Like any web request it reveals your IP address and the version you are running, and that is the entirety of what we could learn from it. There is no identifier, and nothing is stored against you.
Updates are signed with an Ed25519 key. Signata refuses to install one whose signature does not verify, so an intercepted or altered download is rejected rather than applied.
Where your data lives
Inside Signata's sandbox container on your Mac:
~/Library/Containers/com.stacknscope.Signata/Data/Library/Application Support/Signata/
You can read it with any text editor — the event log is JSON Lines, and the format is published. Evidence files are ordinary images in a dated folder.
Retention and deletion
You control it. Evidence has a keep-days window and a total storage cap, both configurable, applied automatically. Nothing has a server-side copy, so deleting a file deletes it — there is no second copy to also delete.
Uninstalling Signata and removing its container removes the event log, the evidence, and the settings. What survives that is worth knowing, and it is everything Signata put in the macOS Keychain — there are three things, and this is all of them: your alert credentials, your license once you activate one, and the date your trial started. The last one sits there rather than in the app's own data so that reinstalling Signata does not silently hand someone a second trial. All three belong to the Keychain rather than to the container and outlive both. Remove them in Keychain Access, or leave them; nothing reads them once Signata is gone.
Because there is no account, there is nothing to close. The two records this project does hold about a person live on our side, not yours, and each has its own section below: a purchase, and an address on the notification list.
The camera and the screen
Evidence Mode is off by default, each capture type has its own opt-in, and each requires the corresponding macOS permission. Beyond that, Signata operates under constraints it will not relax:
- Capture is never triggered remotely — only by an event on the machine while you have armed it.
- Hidden operation and capture are mutually exclusive. Signata will not offer a concealed mode that also photographs.
- The macOS camera indicator is never suppressed or worked around.
Denying either permission is a supported state. Events keep recording and the app degrades quietly rather than nagging.
Purchases
Buying Signata is the only transaction this site handles, and two parties hold anything afterwards: Stripe, and one narrow table in the same database the notification list lives in.
What Stripe gets
Checkout is Stripe's own hosted page, not ours. Your card number, its expiry and its security code are entered there and never touch signata.app — we could not see them if we wanted to. Stripe also collects a billing address, because it calculates sales tax and VAT from it. What Stripe does with all of that is governed by Stripe's privacy policy. Stripe keeps its own record of the payment for as long as its accounting and tax obligations require, and that record is not ours to delete.
What we keep
One row per purchase, in the same Cloudflare D1 database in the United States that the notification list uses, described below — still the only database this project has. The row is:
| Email address | The address you gave Stripe, lowercased. Where the license was sent, and what recovery looks up. |
|---|---|
| The signed license | The exact token that was emailed. Stored rather than regenerated, so a recovered copy is byte-for-byte the one you already have. |
| Amount and currency | What was actually charged. For reconciling against Stripe and for honoring a refund. |
| Date issued | When the license was signed. |
| Date emailed | When the license email actually went out, or empty until it has. This is what stops one payment from producing two emails, and what lets a send that failed be tried again. |
| Date last recovered | When a copy of the license was last re-sent, or empty if it never has been. It bounds how often that can happen, so typing an address into the recovery form over and over cannot be used to bury its owner in mail. |
| Stripe's session id | Stripe's reference for the payment, and this row's key. What a support question about one specific charge is looked up by. |
No name, no address, no card details — not even the last four digits — and no IP address. Alongside it we record every Stripe event we have already processed — an identifier, an event type, and the time it arrived, with nothing personal among the three. That record exists so that a redelivered webhook is visible as one, and so there is something to reconcile against Stripe when a support question needs it. What actually stops you receiving a second license is the date-emailed field above: one payment can produce more than one Stripe event — a slow payment method sends a second one when the money finally lands — and counting events would have counted that as a second purchase.
Why keep any of it: so that someone who loses the email can have the license sent again. That is the entire purpose of the table. License recovery takes an address, looks for a purchase, and emails the license to that same address if it finds one. It answers identically either way — so it cannot be used to find out whether an address is a customer — and the only thing it writes is the date above, on a row that already existed. It records nothing about who asked: no address that is not already a customer's, no IP address, and no note that a request was made at all when no purchase matches it.
The app sends nothing
Licensing is entirely offline. Activating a license verifies an Ed25519 signature on your Mac, and so does every launch after that. There is no activation call, no seat check, no periodic revalidation, and no server that could be asked what you are running or how often. The 14-day trial works the same way: it starts and ends on your Mac, with nothing to sign up for. The transaction happens on this website; the app has no part in it, and the update check described above is still the only request Signata makes on its own.
How long we keep it, and how to have it removed
The purchase row is kept while Signata is sold and supported, because recovery has to keep working. Write to support@stacknscope.com and we will delete it — and here is the cost of that, said plainly: with the row gone, recovery can no longer send you the license, so keep your own copy of the email first. Stripe's record of the payment remains either way; we cannot delete it, and we are required to keep a record of sales for tax.
This website
signata.app is static files. No cookies, no analytics, no tracking pixels, no embedded third-party scripts, no fonts fetched from anyone else's server. Our host records standard request logs for delivery and abuse prevention; we do not build profiles from them.
The tamper-evidence demo on the home page runs entirely in your browser. Nothing it computes is sent anywhere.
Release notifications
The home page has one form, and it is the only place this site asks you for anything. If you enter an address there, here is everything that happens to it.
We store the address, the time you submitted it, the time you confirmed it, the time the confirmation was last sent to it, and a random token. That is the whole of the stored record — the fourth field is there so that typing an address into this form over and over cannot be used to bury its owner in mail. (Sending that email makes one more copy of the addresses, on our side; it has its own paragraph below.) We do not store your IP address, your browser, or the page you came from. It lives in a Cloudflare D1 database in the United States, the same one a purchase writes to, and it is the only database this project has.
Nothing is sent to an address that has not been confirmed. Submitting the form gets you one message asking you to confirm, and if you never open that link, you never hear from us again. That is deliberate: it means someone else typing your address into this form cannot sign you up for anything.
A confirmed address receives one email, when there is a release worth announcing. There is no newsletter and no second message, and no date by which it must go out — if nothing warrants an email, none is sent.
To be taken off the list, write to support@stacknscope.com, or just reply to any email we send you — every one of them carries a reply-to address a person reads. Either way the record is deleted, not marked inactive: the row goes, and the token and the timestamps go with it. We do it without asking why, and we write back to say it is done. That works before that email and after it.
Sending that email makes a second copy of the list, and it is exactly the copy a privacy policy is tempted not to mention. The tool that sends it appends each address to a file the moment that address has been mailed successfully, so that a failure halfway through cannot end up mailing anyone twice. The file holds addresses and nothing else. It exists only on the machine the send is run from, it is never committed to the repository and never published, and it is deleted in the same act as the rows — the commitment below covers both copies, because a promise to delete a list that leaves a copy of the list behind is not a promise.
Once that email has gone out, the list has done the only job it was collected for, and we delete it: the rows, and that file. Being exact about how, because this is the kind of promise worth being exact about — nothing deletes it automatically. No code in this project removes a row except the one that acts on an individual request to be removed. Deletion is a manual step, deliberately held until a send has finished with zero failures, because deleting earlier would drop people from the list whose message had not actually reached them. We commit to taking it within 30 days of that email going out. Until then the database record is the five fields listed above, the file is addresses, and the removal address above works the whole time.
Delivery is handled by Resend, who process the address on our behalf in order to send the message. They are the only third party that sees it. We do not sell, rent, share or otherwise hand your address to anyone. A purchase you later make lands in the same database, keyed by the same address, so being straight about the shape of it: the two are separable but not unlinkable, and we do not join them. Nothing in this project reads one to learn anything about the other, and being on this list is not treated as knowing anything about you as a customer.
Writing to support@stacknscope.com will also tell you what we hold for your address, whether that is a place on this list, a purchase, or — as it is for most people — nothing at all.
Children
Signata is a utility for Mac owners and is not directed at children. The app collects nothing from anyone. A purchase and the release notification list are the only places this project holds a personal detail at all — an email address, in both cases — and we do not knowingly accept one from a child.
Changes
Material changes will be published here with a new effective date before they take effect, and the in-app policy will match. If a future version of Signata ever collects something this page says it doesn't, that page changes first.
Contact
support@stacknscope.com — StacknScope Inc., publisher of Signata.