ChitSeal

Privacy Policy

Last updated: July 28, 2026

What we collect, and why

Account: your phone number and name — the phone number anchors your identity on every agreement. If you sign in with Apple or Google, we store the account identifier they issue (never your password).

Agreements: the loans you record — amounts, parties, dates, terms, payment records, and any attachments you add.

Signing context: when you e-sign we record the device model, app version, network address, and time of signing — and, only if you opt in, an approximate (~1 km) location. This is sealed into the record so that it can show more completely what the circumstances of signing were.

Identity verification (optional / higher-value agreements): verification is performed by our partner Didit, who checks your government ID and a selfie (biometric matching). We never see or store your document images or biometrics — we store only the verified legal name, encrypted (AES-256). It is disclosed to the other party in one case only: your agreement is overdue and they request it — exactly as stated before you verify.

We never collect bank credentials — ChitSeal does not move money.

Who processes it for us

We use a small set of service providers, each bound to use your data only to provide their service: Railway (hosting, United States), Twilio (SMS — both the one-time codes that anchor a signature and, where you have opted in, the payment reminders about your loan; a reminder text names the other party and the amount, because otherwise the person receiving it cannot tell what it is about), Backblaze (encrypted off-host backups of the database and your attachments, Canada), Didit (identity verification), Apple / Google (optional sign-in), OpenAI (optional AI drafting of terms — the draft inputs, never your account data), and one or more time-stamping authorities (RFC-3161).

More than one timestamp authority may receive the hash — but normally only one does. Where we have configured a backup as well as a primary — so that one authority being unreachable cannot leave a record untimestamped — the hash goes to the primary first, and to it alone. The next authority is asked only if the primary has not answered within a few seconds, or has already failed: we do not ask every authority we have configured at the same time. So in ordinary operation exactly one authority ever sees a given record's hash, and a second sees it only when the first is slow or unreachable. Each receives only a one-way hash of your record — never its contents, amounts or names. The token we keep is the one from the first authority in our configured order that answers, not simply the quickest to reply. We record, for every authority we have configured, whether it was asked and what it answered — and one that was never asked is recorded as not asked, never as one that failed. We do not name the authorities on this page, because which ones we use changes as we contract with them; the evidence pack for a record names the authority whose token that record carries.

Cross-border: our servers are currently hosted in the United States, so your data is processed there under contractual safeguards. Wherever you are, this policy governs how it is handled, and Canadian law (PIPEDA) applies to us as a Canadian company. Rights your own country gives you are in addition to that, not replaced by it.

What we share

Nothing, with anyone, except: the other party to your agreement sees that agreement; your verified identity is disclosed to the other party only after a default, as described above; and we disclose data if a court of competent jurisdiction orders it.

What a push notification carries. If you turn notifications on, alerts travel through Apple's notification service to reach your phone, and Apple can see their contents. Some carry the other party's name, the amount, or the agreement reference — a reminder has to say what it is about or it is not a reminder. Turn notifications off in iOS Settings and nothing is sent this way.

What is published publicly. Each sealed record is added to an append-only log, and a signed summary of that whole log is published to a public repository hosted by GitHub, so that a third party can hold a copy we cannot alter afterwards. That summary contains cryptographic hashes and nothing else — no names, no amounts, no terms, no phone numbers, and nothing from which any of those can be recovered. Your agreement itself is never published.

The landing page. If you join the waitlist we keep the email address you give us, which section of the page you submitted from, and a one-way hash of your IP address (to stop the same person submitting a thousand times). It is used to tell you when the app is available, and for nothing else. Ask us at the address below and we will delete it.

How long we keep it

An agreement nobody signed is deleted. If the signing window closes and the other party never signed, the record lapses and is deleted 30 days later — including their name and phone number. Nothing was agreed, so there is nothing to keep, and they never consented to us holding it. A sealed agreement is the opposite and is never removed this way: it is evidence, and the other party is entitled to it.

Sealed agreements are evidence, so we keep them while your account is active. Delete your account any time — the deletion runs immediately, in one step: there is no grace period, nothing to cancel, and nothing left waiting to be swept up later. Two things deliberately outlive it. A sealed agreement — or one the other party had already signed — is detached from your account but keeps your name on it, because it is their evidence of what you both agreed, and a record of an agreement with one of the two parties removed proves nothing. And the ledger line recording that an App Store purchase was already used stays, with your account removed from it, so that one purchase cannot be redeemed again and again. Everything else — your account, your phone number, your unsigned drafts and anything attached to them — goes with the deletion.

Identity checks happen at our provider, not here. When you verify your identity, the photo of your document and the photo of your face go to Didit and are processed there; we receive the RESULT — whether it matched, and the name and document type — never the images and never the biometric template. Deleting your ChitSeal account removes what we hold. Didit keeps and deletes what it holds on its own schedule, under its own policy, and we cannot delete it for you: write to the address below and we will pass the request on.

One honest qualification about backups. We keep encrypted off-host backups so that a hardware failure cannot destroy evidence people are relying on. Those backups are deliberately immutable: every snapshot is locked for at least 30 days, and within that window nobody — including us — can alter or delete it. That is what makes them trustworthy as evidence, and it is also the reason a deleted account persists inside them. To be exact about the direction that lock runs: 30 days is a floor, not an expiry. It stops a backup being destroyed early; it does not delete anything afterwards, and we do not currently expire old snapshots automatically. So a deleted account can remain in backups indefinitely, until those snapshots are removed. Backups are never used to answer anything — only to rebuild the service after a disaster — and if that ever happened we would re-apply your deletion.

What a verification text leaves behind. We never store the code itself, only a one-way hash of it, and the code stops working five minutes after it is sent. The challenge record is a different thing: it holds the phone number, what the code was for, and when it was sent and used. Those records are deleted 30 days after they are created — including for numbers that never became accounts. One exception, and it is deliberate: the challenge that underwrites a signature — a code sent to a signer for one specific agreement, on an agreement somebody actually signed — is kept for as long as that agreement is kept. It is the record that the code went to that number at that minute and came back, it is what the evidence pack relies on to say so, and deleting it would quietly weaken a signature the other party is entitled to rely on. If the agreement itself is deleted — nobody signed, it lapsed — the challenge goes with it.

Your rights

Ask us for a copy of everything we hold on you and we will send it within 30 days — email the address below. Correct your name in Profile. Delete your account any time. Questions, complaints, or access requests: contact@vanillapha.com — we respond within 30 days. If we ever suffer a breach creating a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as required by law. PIPEDA applies; you may complain to the OPC at any time.

Where you live adds to this; it does not replace it. For users in the United States we honour the same rights, and e-signature records are kept in accordance with the ESIGN Act and applicable state UETA laws. For users in the United Kingdom, UK GDPR gives you rights of access, rectification, erasure, restriction, objection and portability, and you may complain to the Information Commissioner's Office. For users in Taiwan, 個人資料保護法 §3 gives you the rights to enquire and review, to obtain a copy, to supplement or correct, and to require that we stop collecting, processing or using your data and delete it. Use the same address for any of these.

ChitSeal (“Chit”) is a product of Vanillapha Inc., an Ontario corporation. Contact: contact@vanillapha.com — registered office: 952 Guildwood Blvd, London, Ontario N6H 4G3, Canada