Privacy Policy
Last updated: 23 September 2026
1. What we collect
Account and workspace data: your name, email, hashed password or connected sign-in account, workspace membership, subscription state, documents, templates, comments, tags, brand assets, contacts, and company information you choose to store. Company information may include addresses, tax details, bank details, and other facts you place in a brand kit or document.
Signing and delivery data: recipient name and email, assigned fields, verification status, typed signature, consent version, timestamps, IP address, browser identifier, document hash, signing events, and email-provider delivery events. The requesting workspace can see the resulting record and audit certificate.
Service and feedback data: sign-in sessions, security and usage logs, device and request information, errors, plan usage, and feedback you submit. Feedback includes the relevant product path and identifiers you can see before sending; it does not include the document body.
2. How we use it
We use this data to provide and secure Triplewave: authenticate people, operate workspaces, draft and render documents, apply your brand, import and export files, route reviews and signatures, send transactional email, enforce plan limits, process subscriptions, prevent abuse, investigate errors, and respond to feedback.
We do not sell personal data or share it with advertisers. We do not use your document content to train AI models. When you ask Triplewave to draft or revise, the relevant document content, document facts, brand voice, and company information are sent to our AI provider, Anthropic, to generate the requested result. Anthropic states that commercial API inputs and outputs are not used to train its models by default.
3. Providers and international processing
Triplewave uses service providers to host the application and database, generate AI output, deliver email, process payments, monitor errors, and receive product-feedback notifications. Current core providers include Vercel for hosting and page analytics, Neon for the database, Anthropic for AI, AutoSend for transactional email, Dodo Payments for subscriptions, Sentry for error monitoring, Google Analytics for visit measurement, and Slack for team feedback notifications. These providers may process data in countries other than yours under their own security and data-protection commitments.
Payment information is collected by Dodo Payments; Triplewave does not store full card details. Information you place in a document, including bank or tax details, is visible to people with whom you share or send that document.
4. Cookies and local storage
Session cookies keep you signed in. When you visit a public page, such as the home page, pricing, templates or the blog, Triplewave sets three first-party analytics cookies. tw_first_touch and tw_last_touch hold the campaign source, the referring site’s domain and the page you landed on, for 90 days. tw_analytics_id holds a random identifier for up to a year. None of them holds document content, and none records anything on signing, share, print or account-recovery pages.
Google Analytics measures visits to our public pages, such as the home page, pricing, templates and the blog, and sets its own cookies, named _ga, to do so. It never runs inside a workspace or on sign-in, signing, share, print or account-recovery pages. Vercel Web Analytics counts page views without cookies and sees workspace pages only as generic routes, never your workspace or document names. Your browser’s local storage keeps interface preferences such as your theme. We use no advertising or cross-site tracking cookies.
5. Retention and deletion
Workspace data is kept while the workspace is active. A workspace owner can schedule closure from account settings. Public document and signing links are revoked immediately, the workspace becomes read-only, and owners have 30 days to export data or cancel closure before the workspace is purged. Some security, fraud-prevention, billing, or legal records may be kept longer when necessary.
Unsigned documents are removed when an authorized member deletes them. Signed documents receive a 30-day private export period: public links are revoked immediately, then the document, signer data, and audit certificate are purged unless deletion is cancelled or retention is required by law.
You can request account deletion from account settings and verify the request by email. Documents in shared workspaces remain with the workspace; personal authorship and activity references may be transferred or anonymized. A sole workspace owner must first transfer or close that workspace. Backups may retain deleted data for a limited period before routine expiry.
6. Security
We use technical and organizational safeguards designed to protect Triplewave data, including encrypted transport, hashed credentials, email verification, scoped workspace access, short-lived or revocable public links, rate limits, and monitored application errors. No service can guarantee absolute security. Keep your account credentials and signing links private and contact us promptly if you believe they have been compromised.
7. Your choices and contact
You can update your account, workspace, brand kit, contacts, and document information in the product. You can also ask for access, correction, deletion, or help with a privacy concern by emailing hello@droidsize.com. We may need to verify your identity and may retain data where the law or another person’s rights require it.
Triplewave is operated by DROIDSIZE TECHNOLOGIES PVT. LTD. ("Droidsize"), based in India. We will update this policy as the product and applicable requirements evolve and will post the revision date here.