Security & compliance

Everything your infosec team will ask for — on one page.

Plain English, no fine print. Forward this URL to whoever signs off on your tools.

We cannot read your email — and here is the proof.

Our Google integration asks for exactly one permission: gmail.settings.basic. It manages send-as settings — your email signature — and nothing else. Your admin sees it on the consent screen and can revoke it in one action.

Not a pledge. A permission boundary.

The exact scope of gmail.settings.basic

This is the only Gmail permission we request, and it is the narrowest one that can set a signature.

What it lets us doWhat it cannot do
Read and update send-as settings (your signature)Read your email
Manage basic Gmail settingsSend email on your behalf
Search your inbox
Read your contacts
Read your calendar
Read your drafts or attachments

Everything we store is business-card data

Names, titles, phone numbers, photos — the details you already broadcast at the foot of every message.

What we storeWhat we never touch
Name, email, job title, phoneEmail content
Profile photo and company logoInbox and sent items
Your signature template and tagsContacts
Provider connection settingsCalendar
Drafts and attachments

🇪🇺 EU-only residency

Your data is processed and stored in the EU. It is not routed through US data centers, and it is never sold or shared with third parties.

🔒 Encrypted in transit and at rest

All traffic is HTTPS, and stored data is encrypted at rest on Cloudflare's infrastructure.

Pen-tested. DPA-ready.

The two documents procurement asks for — available up front.

🛡️

Independent penetration test

We commission an independent penetration test and share the executive summary with customers under NDA.

📄

Signable Data Processing Agreement

A ready-to-sign DPA covering our role as a data processor under the GDPR. Ask sales for a copy.

Frequently asked questions

Can teamsig read my email?

No. We only request gmail.settings.basic, which manages send-as settings and nothing else. It cannot read, send, or search email.

What permission does teamsig request?

One: gmail.settings.basic. Your admin sees it on the Google consent screen and can verify it at any time.

Where is my data stored?

In the EU. We do not route data through US data centers.

Do you sell or share my data?

No. We are not a data broker. The only data we hold is the business-card data you give us, and we use it solely to render your signatures.

How do I revoke access?

In the Google Admin console: Security → API controls → Domain-wide delegation, and remove our client ID. Access stops immediately.

Do you have a DPA?

Yes. A signable Data Processing Agreement is available on request from sales@teamsig.org.

Talk to us about security