Privacy

Paired-device media and signing documents work differently. Live tool media is exchanged between devices; Sign uploads and stores PDFs, recipient details, signatures and audit evidence.

Effective 30 September 2026 · applies to usemyphone.com

Who to contact

For privacy questions, access, corrections or erasure requests, contact the operator of Use My Phone at info@usemyphone.com or use our contact page. We may ask you to verify your account ownership before disclosing or deleting information.

Paired-device tools

In a paired session, camera, microphone, file-transfer, scanner and signature-pad media normally travels over an encrypted WebRTC connection between your devices. A configured relay can forward that encrypted connection where a direct connection is unavailable. The application does not intentionally save that paired media. Our server handles pairing and control messages. Some tools, including audience questions and photo-booth guest uploads, pass content through server memory to deliver it to the host.

Accounts and operational data

We store your email address, optional display name, verification and sign-in details, plan, Stripe customer/subscription references, usage counts, saved-device labels and relevant session history. Browser sign-in sessions last up to 30 days. Pairing metadata can be stored to restore connections after a server restart; it is not a recording of the media.

Contact messages and bug reports are kept for up to a year. First-party analytics record aggregate activity; per-tab visitor hashes used for counting are kept for 90 days. Anonymous performance samples measure page loading, responsiveness and visual stability by page category and broad device type, without identifiers or document contents. Technical diagnostic and performance records are bounded and kept for up to 14 days; secure links, credentials and private-link tokens are excluded or redacted. Where AWS CloudWatch delivery is enabled, sanitised operational logs also have a 14-day retention period. Administrator security events retain a named identity, time and hashed network address for up to 12 months.

Use My Phone Sign — private testing

Sign uploads PDFs and stores original and completed documents, signature images, field values, sender/recipient details, status and audit evidence. These are not peer-to-peer-only tools. Private document storage uses AWS S3 with KMS encryption. Automated PDF validation and security checks process files for technical safety, not their legal meaning. Authorised operators can access infrastructure for support and security; the dedicated audited document-viewing interface is not yet released.

Inactive drafts are scheduled for deletion after 30 days. Document content for completed, voided, declined or expired envelopes is scheduled for deletion after 90 days. Scheduled deletion runs periodically, not at an exact second. The erasure process removes stored object versions and identifying envelope metadata, retaining only minimal hashes and an erasure receipt until 12 months after the terminal event. Download and save completed documents you need before the retention period ends.

Reusable templates persist separately until removed or an account-erasure request is processed. Request permanent deletion from your account page and confirm using the one-time email link, or contact support. Confirmation immediately revokes account and signing access. A tracked process cancels Use My Phone subscriptions, deletes all versions of files you own and removes identifying account, recipient, template and team records. Provider failures are retried; completion is not claimed until primary cleanup succeeds. Other senders' documents and Stripe's legally retained financial records are not erased by deleting your account. Minimal random-ID hashes and erasure receipts are retained for 12 months.

Database backups expire on a rolling 30-day schedule, so deleted data may remain in a restricted backup for up to 30 additional days. Off-box erasure receipts are checked before the application serves a restored database, keeping previously deleted accounts inaccessible while cleanup is reapplied.

Why we use this data

We use account, pairing and signing data to provide the service you request; security and limited operational measurements help prevent abuse and maintain reliability. Optional advertising choices use consent where required. Some billing or legal records may need to be retained to meet legal obligations. We do not classify uploaded documents or determine whether their execution is legally appropriate.

Cookies and advertising

Essential cookies include pl_session (account sign-in), pl_oauth (a ten-minute sign-in security check), pl_trial (trial usage), pl_admin (administrator sign-in) and pl_admin_setup (ten-minute restricted enrollment). They support requested functions, not advertising.

Google AdSense may appear on eligible public content pages for anonymous and Free visitors. Pro and Studio accounts are ad-free when signed in. Sign, account, checkout, administration and document pages do not load advertising. Google and its partners may use cookies or similar identifiers subject to applicable consent requirements. When advertising consent controls are available, use “Privacy and cookie settings” on an ad-supported page to review choices. See Google’s partner-sites policy. Contact us if a consent control is missing or not working.

Providers and location

AWS hosts the application and private storage in the Stockholm region. IONOS handles transactional email, including private sign-in and recipient links. Google provides optional account sign-in and public-page advertising. Stripe handles subscriptions and card details on its own systems. These providers have their own privacy terms; some processing or support may involve other countries. We do not receive your full card number.

Your choices and rights

Use your account page to review available profile, device and subscription controls. Depending on applicable law, you can request access, correction, erasure, restriction, portability or object to processing, and withdraw optional consent without affecting earlier lawful processing. You may also complain to your data-protection authority, including the UK Information Commissioner. Contact us for requests not covered by the interface.

Changes

We update this notice as the service changes. The date above identifies this version. Our service terms explain the limits of electronic-signature functionality.

Optional AI assistance

AI assistance is off by default. Where enabled, you choose which captured or PDF text to share, review and edit it locally, and approve each request. Only that approved text is sent through our server to Amazon Bedrock in the disclosed AWS region. This does not silently upload phone photos, peer-to-peer transfers, historical documents or completed signed PDFs. The current Stockholm configuration uses a region-local model.

Suggestions can be wrong or incomplete. They are not legal or financial advice, and never sign, send invitations or alter original documents automatically. The app keeps AI results only in your current browser view, not in its database, storage or operational logs. We retain your account consent until changed or your account is erased, and attempt/token counts for up to 14 days. You can disable future processing in Account; already-started provider requests cannot be recalled. See Amazon Bedrock data protection for provider processing information.