1. Introduction
At BrillSign, we believe that privacy is a fundamental human right. Our platform is designed from the ground up to protect your most sensitive documents through advanced cryptography and zero-knowledge principles. This Privacy Policy explains how we handle information when you use our website, platform, and services.
By using BrillSign, you agree to the practices described in this policy. If you do not agree, please do not access or use our services.
2. Data We Collect
We collect information in two main categories:
- Account Information: Name, work email, and organizational affiliation when you sign up for a trial or waitlist.
- Usage Data: Anonymous metadata about how you interact with our platform (e.g., page views, feature usage) to improve our service.
- Cryptographic Proofs: We store hashes of your documents and signatures, which are mathematically unique but do not contain the document content itself.
3. Zero-Knowledge Architecture
Unlike traditional e-signature providers, BrillSign utilizes a Zero-Knowledge Architecture. This means:
- Documents are encrypted on your device before being transmitted.
- We do not hold the decryption keys to your files.
- Our employees and systems are architecturally incapable of reading your document contents.
4. How We Use Data
We use the collected data for the following purposes:
- To provide and maintain the BrillSign platform.
- To verify signer identities through cryptographic methods.
- To communicate with you regarding security updates and service changes.
- To comply with legal obligations and prevent fraudulent activity.
5. Data Sharing & Disclosure
We do not sell your personal data to third parties. We only share information with trusted service providers (e.g., cloud hosting, email delivery) that are necessary to operate our platform, and they are contractually bound to protect your data.
We may disclose information if required by law or in response to valid requests by public authorities (e.g., a court or a government agency). However, due to our encryption, we cannot provide readable document contents even if legally compelled.
6. Security Measures
BrillSign employs industry-leading security measures, including AES-256 encryption at rest, TLS 1.3 in transit, and multi-factor authentication (MFA) support. Our systems are regularly audited for compliance with SOC 2 Type II and ISO 27001 standards.
7. Your Rights
Depending on your location (such as the EU or California), you may have rights regarding your personal data, including:
- The right to access and receive a copy of your data.
- The right to rectify inaccurate information.
- The right to request erasure ("the right to be forgotten").
- The right to object to processing.
8. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer:
Email: privacy@brillsign.com
Address: BrillSign Security Team, Silicon Valley, CA.