Privacy Policy

Last updated: August 29, 2026

This policy explains what CrossRoads Digital Media LLC ("we", "us") collects when you use Signoff, why, and the choices you have. It applies to the website at sign-off.cloud, the application, and the MCP endpoints.

1. What we collect

Account data. When you sign in through Clerk, we receive your name, email address, profile image, and organization membership details (organization id, role) from Clerk.

Service data. The content you create in the Service: boards, test runs, checklist items, verdicts, notes, findings, evidence you upload (screenshots, logs), and exact task requests submitted by an agent for private task compilation.

Usage data. Records of actions in the Service (for example, seat counts, API and MCP usage events) used for billing, limits, and abuse prevention.

Technical data. Standard server and edge logs (IP address, user agent, request metadata) retained briefly for security and debugging.

2. How we use it

We use collected data to operate the Service: authenticate you, run your boards, compile exact task requests into structured work, enforce plan limits, bill you, secure the Service, and improve reliability. We do not sell your data, and we do not use your content to train general-purpose machine learning models.

3. Processors

We run on a small set of subprocessors, each under its own terms: Clerk (authentication, organizations, billing orchestration), Stripe (payment processing), and Cloudflare (hosting, storage, delivery, and hosted task compilation through Cloudflare Workers AI). These parties process data only to provide their part of the Service to us.

When hosted task compilation is enabled, the exact task request is processed by Cloudflare Workers AI. When a customer enables local BYOK compilation, the local runner sends the request directly to the model provider selected under that customer's account; Signoff does not receive that provider credential.

4. Retention and deletion

Customer content remains in active systems while it is needed to provide the Service and according to the configured retention for the applicable feature. Exact task requests and derived private contracts remain available to the originating API-key agent while the task is active, then may be scrubbed after completion or a valid deletion request while the human-visible QA projection and privacy-safe aggregate measurements remain.

When content or an organization is deleted, we remove or scrub its active copies within a reasonable period. Backups, security logs, and records required by law may persist until their normal expiry or legal retention period.

5. Your choices and rights

You can export your run data from the Service at any time. You can correct your profile through Clerk and request deletion of content or your organization. Where privacy law gives you rights of access, correction, deletion, or portability, contact us and we will honor them subject to lawful retention duties.

6. Security

Within the product, raw task sources, temporal decomposition, model provenance, and free-form agent feedback are available only to the originating API-key agent, not ordinary organization members or browser and REST surfaces. Everyone holding the same API key is the same agent principal and can access that key's task history.

Infrastructure operators, subprocessors, and legal process may still access retained data when required to operate, secure, support, or comply with law. Product-level privacy must not be understood as legal privilege, zero-knowledge storage, or protection from lawful discovery.

Access is authenticated, credentials are hashed or held by our processors, and data is encrypted in transit. No system is perfectly secure, but we design for least-privilege access and review our controls as the Service grows.

7. Children and jurisdictions

The Service is for business use and is not directed at children. Data is processed in the regions where our processors operate, which may include the United States; by using the Service you consent to that processing.

8. Changes and contact

We may update this policy with notice posted on the site. Questions and requests: privacy@sign-off.cloud.