Privacy Policy
Effective date: October 9, 2026.
1. About this policy
This Privacy Policy describes how AgreeProof processes personal information when people use its web-based service to create, review, confirm, and retain records of person-to-person agreements.
AgreeProof is operated by an individual. For privacy or service questions, contact anton@agreeproof.com.
2. Information we process
Depending on the feature used, AgreeProof may process names or display names; U.S. phone numbers; agreement descriptions, facts, rendered documents, and versions; document and evidence hashes; signing acknowledgements; confirmation timestamps; audit records; evidence files and their metadata; and an email address entered to request an executed-PDF copy.
We may also process security and operational information, including session-token hashes, OTP timing and attempt information, masked or hashed phone references, provider acceptance identifiers, rate-limit information, and server-derived records of OTP requests. Canonical phone numbers are retained in some operational records, including user, participant, and OTP-challenge records; other records use masked or hashed references.
3. How information is provided and used
Information may be provided directly by a person using AgreeProof, by an authenticated participant, or by Party A when Party A supplies information about Party B for a proposed agreement. Party A is responsible for having an appropriate basis to provide Party B's personal information. AgreeProof does not independently verify Party A's authority or Party B's identity.
We use information to create and maintain versioned agreement records; enforce participant-only access; provide requested phone verification and signing confirmation; create authenticated sessions; generate authorized PDFs; store and retrieve authorized evidence; deliver a requested executed-PDF email copy; prevent abuse; rate-limit requests; and maintain security and audit records.
4. Phone numbers and SMS
A person may request an authentication code to access an account or a fresh signing code while confirming an agreement version. These messages are transactional and user-requested, not marketing messages. Message frequency varies, and carrier message and data rates may apply.
A successful OTP confirms control of a phone number for the relevant product action at that time. It does not independently verify real-world identity, legal capacity, authority, or continuing ownership of the number.
If a supported SMS opt-out process is used, AgreeProof may be unable to send a requested authentication or signing OTP until an approved restoration process is available. AgreeProof does not currently promise automated HELP responses or automatic restoration after START or UNSTOP. Party B invitation SMS will be used only when its consent and provider workflow have been approved and enabled.
5. Service providers and sharing
AgreeProof may use service providers to operate requested functions, including Telnyx for transactional SMS when configured, Resend for requested executed-PDF email delivery when configured, Vercel Blob for private evidence storage when configured, Neon/PostgreSQL for application persistence, and Vercel or related infrastructure for hosting when configured.
For example, an SMS provider may receive a destination phone number and OTP needed to deliver a requested message. An email provider may receive a recipient email address and PDF attachment needed to deliver a requested copy. AgreeProof does not sell or share mobile information with third parties for their promotional or marketing purposes.
6. Cookies, local storage, and analytics
AgreeProof uses an HTTP-only cookie to maintain an authenticated session. The invitation handoff may use a short-lived encrypted and signed HTTP-only cookie. The browser may use local storage to retain an in-progress agreement draft on the device.
AgreeProof does not currently use Google Analytics, Google Tag Manager, Microsoft Clarity, or similar analytics in this application. If analytics, advertising technology, or additional cookies are introduced, we will review and update this policy and any applicable preference controls.
7. Retention, access, and requests
Agreement versions, confirmations, audit records, and retained evidence are designed to preserve the history of an agreement. OTP challenges and sessions have expiry and revocation controls. AgreeProof does not promise automatic deletion, a particular retention period, or a self-service deletion workflow.
For privacy questions or requests, contact anton@agreeproof.com. Before publication, the operator must establish the applicable request-verification, retention, backup, legal-hold, and response procedures.
8. Security, children, and scope
AgreeProof uses participant-specific authorization and private, server-authorized evidence storage to reduce risk. No security measure can guarantee that unauthorized access, loss, or misuse will never occur.
The intended initial market is Texas, United States. The operator will establish any age and geographic eligibility rules before publication.
9. Changes and contact details
We may update this policy as the service changes. AgreeProof does not state a business registration, business address, or legal entity that has not been established. If a legal notice or postal-contact detail becomes applicable, we will add it to this policy.