Signa by BlueCouchWorks

Privacy Policy

Effective date: 17 May 2026. Last updated: 17 May 2026.

This Privacy Policy explains how Signa (the “App”), an iOS application developed and operated by BlueCouchWorks (“we”, “us”, “our”), handles information when you use it. Signa is an end-to-end encrypted messenger designed so that you retain ownership of your messages, photos, and account. We do not see plaintext message content, we do not commercialize your data, and we do not operate a server that holds it.

By installing or using the App, you acknowledge that you have read and understood this Policy. If you do not agree, please do not install or use the App.

Short version

  • You own your data. Messages are end-to-end encrypted on your device. Photo attachments are uploaded to your Google Drive or Yandex Disk, not to anything we control.
  • We do not see plaintext message or call content. Cryptographic keys live on your device and never leave it in a readable form.
  • Message envelopes are stored briefly, encrypted, on Apple’s secure cloud infrastructure so peers can pick them up when offline. They are deleted after a short retention window. We treat that infrastructure as untrusted and place only ciphertext on it.
  • Photo uploads stay in your Drive. Signa uses Google’s per-file drive.file scope (or Yandex’s equivalent app-folder scope), so it sees only the files it creates and cannot read the rest of your storage.
  • We run no analytics, tracking, advertising, or behavioral profiling. There are no third-party SDKs for those purposes in the App.
  • We cannot recover your account, messages, or groups if you lose access to your device. That is a consequence of not storing your data in a form we can read.

Who we are

Signa is an independent application made by BlueCouchWorks. For privacy or data questions, contact privacy@bluecouchworks.com.

Information the App does not collect

The App does not collect, and we do not receive, any of the following:

The App’s privacy manifest declares NSPrivacyTracking = false; Signa does not perform tracking as defined by Apple’s App Tracking Transparency framework.

Information handled locally on your device

The following information is stored on your device and processed only on your device. It is not transmitted to us in a form we can read. It may be transmitted, in encrypted form, to other devices you authorize through an invite:

Information transmitted through Apple’s cloud infrastructure

To let two devices exchange messages without a dedicated server we operate, Signa places encrypted message envelopes and encrypted signaling records on the secure cloud infrastructure that Apple already operates for your Apple ID. That infrastructure is governed by Apple’s Privacy Policy. We treat it as untrusted: everything Signa places there is either a public cryptographic key, or is encrypted with a key held only by the group members.

Each record has a short time-to-live: encrypted envelopes are removed after a bounded retention window so they cannot accumulate. Specifically, Signa may place there:

We do not operate or administer this infrastructure. We cannot decrypt records whose keys we never held; we also cannot prevent the operator (Apple), from retaining or disclosing ciphertext and associated metadata in accordance with its own policies and with lawful process addressed to it.

Information stored in your Google Drive or Yandex Disk

When you send a photo attachment, Signa uploads the file directly to a cloud-storage provider that you sign in to — currently Google Drive or Yandex Disk. The file lives in your storage account, against your quota, under your ownership. We never receive or hold a copy.

Your use of these providers is also governed by Google’s and Yandex’s own terms and privacy policies. We are not responsible for their handling of your data.

Information exchanged peer-to-peer

For voice and video calls, once two devices discover each other through the encrypted signaling channel described above, call media flows directly between them over a WebRTC connection. The audio/video stream itself never passes through any server we operate. STUN servers (see Third-party services, below) are contacted only to discover each device’s public network endpoint; no call content passes through them.

Third-party services

Signa embeds no advertising, attribution, analytics, or crash-reporting SDKs from any third party. Diagnostic signals we do receive come from Apple’s on-device MetricKit framework and consist of aggregated, non-identifying crash and performance headers; they contain no message content, no stack frames, no binary UUIDs, and no user content.

Data retention

Security

Signa uses Apple’s CryptoKit to perform cryptographic operations: AES-256-GCM for message encryption, Curve25519 for key agreement, Ed25519 for signatures, HKDF-SHA256 for key derivation, and PBKDF2-SHA256 for passphrase-based invite keys. Private keys are stored in the iOS Keychain with device-only access attributes and, where available, are protected by the Secure Enclave. Group keys rotate automatically when a member is removed, so revoked members cannot read messages sent after their removal.

No security is absolute. No system of electronic storage or transmission can be guaranteed to be 100% secure, and we cannot warrant the security of information that leaves your device. You are responsible for keeping your device, your Apple ID, your storage-provider accounts, and any invite passphrases you share safe from unauthorized access.

Children

Signa is not directed to children under the age of 13, and we do not knowingly handle personal information from any such user. Users in the European Economic Area and the United Kingdom must be at least 16 years old (or the minimum age at which consent to online services is valid under local law) to use the App without parental consent. If you believe a child has used the App improperly, please contact us and we will take appropriate action with respect to any information we can identify.

Your rights

Depending on where you live, you may have rights under the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA), or similar laws, including the right to access, correct, delete, or port your personal information, and the right to object to certain processing.

Because Signa’s design means that we do not hold your personal information, most such rights are exercised locally on your device or with the providers that do hold your data:

If you would like confirmation of the above, or if you believe we have information about you and would like it deleted, contact us at privacy@bluecouchworks.com and we will respond within the timeframes required by applicable law. For data held by Apple, Google, or Yandex, please contact those providers directly.

If you are in the EU/UK/EEA, you have the right to lodge a complaint with your local data protection authority.

Do-not-sell / do-not-share (CCPA). We do not sell or share personal information, as those terms are defined by the CCPA/CPRA. There is therefore nothing to opt out of.

International users and cross-border transfers

Signa is offered from the United States. If you are located outside the United States, you understand that your use of the App may involve transfer of encrypted records through infrastructure operated by Apple, Google, or Yandex in jurisdictions that may offer different levels of legal protection than your country. By using the App, you consent to such transfers to the extent permitted by applicable law.

Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected in a new “Last updated” date at the top of this page and, where appropriate, announced inside the App. Continued use after the effective date of a revised Policy means you accept it.

Contact

Questions about this Policy: privacy@bluecouchworks.com.