Privacy Policy

Last updated: July 18, 2026

This policy explains what CrossRoads Digital Media LLC ("we", "us") collects when you use Signoff, why, and the choices you have. It applies to the website at sign-off.cloud, the application, and the MCP endpoints.

1. What we collect

Account data. When you sign in through Clerk, we receive your name, email address, profile image, and organization membership details (organization id, role) from Clerk.

Service data. The content you create in the Service: boards, test runs, checklist items, verdicts, notes, findings, and evidence you upload (screenshots, logs).

Usage data. Records of actions in the Service (for example, seat counts, API and MCP usage events) used for billing, limits, and abuse prevention.

Technical data. Standard server and edge logs (IP address, user agent, request metadata) retained briefly for security and debugging.

2. How we use it

We use collected data to operate the Service: authenticate you, run your boards, enforce plan limits, bill you, secure the Service, and improve reliability. We do not sell your data, and we do not use your content to train general-purpose machine learning models.

3. Processors

We run on a small set of subprocessors, each under its own terms: Clerk (authentication, organizations, billing orchestration), Stripe (payment processing), and Cloudflare (hosting, storage, and delivery). These parties process data only to provide their part of the Service to us.

4. Retention and deletion

Customer content stays in the Service until you delete it or delete your organization. When an organization is deleted, we remove its content from active systems within a reasonable period; encrypted backups and edge logs may persist briefly before expiring. Billing records are retained as required for tax and accounting law.

5. Your choices and rights

You can export your run data from the Service at any time. You can correct your profile through Clerk, and you can delete content or your whole organization. Where privacy law gives you rights of access, correction, deletion, or portability, contact us and we will honor them.

6. Security

Access is authenticated, credentials are hashed or held by our processors, and data is encrypted in transit. No system is perfectly secure, but we design for least-privilege access and review our controls as the Service grows.

7. Children and jurisdictions

The Service is for business use and is not directed at children. Data is processed in the regions where our processors operate, which may include the United States; by using the Service you consent to that processing.

8. Changes and contact

We may update this policy with notice posted on the site. Questions and requests: privacy@sign-off.cloud.