Privacy Policy
Last updated: May 06, 2026
This Privacy Policy describes how Liviu Stoica (“we”, “us”, “our”) collects, uses, and protects information when you use the XignAll website at xignall.io (“Website”) and the XignAll desktop application (“Application”).
1. Data Controller
Liviu Stoica
Str. Dinu Lipatti, Bl. 34, Sc. B-C, Parter
Târgoviște, Dâmbovița, România
Email: contact@xignall.io
2. What Data We Collect
2.1 Website (xignall.io)
Analytics data (Google Analytics):
We use Google Analytics 4 to understand how visitors use the Website. Google Analytics collects:
- IP address (anonymized)
- Browser type and version
- Pages visited and time spent
- Referring website
- Device type (desktop/mobile)
Google Analytics sets the following cookies: _ga, _gid, _ga_*. These cookies persist for up to 2 years. Data is processed by Google LLC under their Privacy Policy (policies.google.com/privacy). We have enabled IP anonymization.
Aria chat widget (xignall.io):
When you use the Aria chat assistant on the website, a UUID is stored in your browser cookie to enforce a rate limit of 10 questions per day. This UUID is anonymous — it does not identify you personally. It is not linked to any account or purchase.
Theme preference:
The website stores your dark/light mode preference in localStorage.theme. This is a local browser value and is never transmitted to our servers.
Contact form:
If you submit a contact form, we collect your name and email address solely to reply to your inquiry.
2.2 Desktop Application (XignAll)
The Application processes documents locally. Your PDF files, signing certificates, and PIN codes never leave your computer and are never transmitted to our servers.
License activation:
When you activate a license key, the Application sends to our servers:
- Your license key
- A hardware hash (an anonymized fingerprint of your device — not personally identifiable)
We do not collect your name, email, or any document content during activation. The hardware hash is used solely to enforce the per-device license limit (up to 3 simultaneous activations on Pro plan).
Update check:
At startup, the Application queries the GitHub Releases API (api.github.com) to check for newer versions. No personal data is transmitted in this request.
Aria in-app chat:
If you use the Aria assistant inside the Application, your questions are sent to our backend at api.xignall.io. Questions are processed to generate an answer and are not stored permanently.
3. Legal Basis (GDPR)
We process data under the following legal bases:
| Purpose | Legal basis |
|---|---|
| Google Analytics | Legitimate interest (Art. 6(1)(f) GDPR) — understanding website usage to improve the service |
| License activation | Performance of a contract (Art. 6(1)(b) GDPR) |
| Contact form | Legitimate interest (Art. 6(1)(f) GDPR) — replying to your inquiry |
| Aria rate limiting (cookie UUID) | Legitimate interest (Art. 6(1)(f) GDPR) — preventing abuse |
4. Data Retention
| Data | Retention |
|---|---|
| Google Analytics data | 14 months (Google’s default retention setting) |
| License keys and hardware hashes | Duration of active license + 1 year after expiry |
| Contact form messages | Until the inquiry is resolved, then deleted |
| Aria cookie UUID | Session or up to 1 year (browser cookie expiry) |
5. Data Sharing
We do not sell your personal data. We share data only with:
- Google LLC — analytics processing (Google Analytics). Google may transfer data outside the EU under Standard Contractual Clauses.
- Hetzner Online GmbH — our backend server (
api.xignall.io) is hosted at Hetzner, Germany. Data remains within the EU. - Lemon Squeezy LLC — payment processor for license purchases. Lemon Squeezy handles payment data under their own Privacy Policy. We do not store your payment card data.
6. Your Rights (GDPR)
As a resident of the EU/EEA, you have the right to:
- Access — request a copy of your personal data we hold
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data (“right to be forgotten”)
- Restriction — request that we limit processing of your data
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent
To exercise any of these rights, contact us at contact@xignall.io. We will respond within 30 days.
You also have the right to lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
www.dataprotection.ro
7. Cookies Summary
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
_ga | Google Analytics | Distinguish users | 2 years |
_gid | Google Analytics | Distinguish users | 24 hours |
_ga_* | Google Analytics | Session state | 2 years |
aria_uuid | XignAll | Aria rate limiting | 1 year |
localStorage.theme | XignAll | Dark/light mode preference | Until cleared |
You can disable cookies via your browser settings. Disabling Google Analytics cookies does not affect the functionality of the Website or Application.
8. Security
We implement appropriate technical measures to protect data in transit (HTTPS/TLS) and at rest. License keys and hardware hashes stored on our servers are not accessible to unauthorized parties.
9. Children
The Website and Application are not directed at children under 16. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this Privacy Policy. When we do, we update the “Last updated” date at the top. For significant changes, we will post a notice on the Website.
11. Contact
For any privacy-related questions:
Email: contact@xignall.io
Postal address: Str. Dinu Lipatti, Bl. 34, Sc. B-C, Parter, Târgoviște, Dâmbovița, România
