Signal Engine was built from day one with a simple rule: your customer data is yours. We don't sell it, we don't share it, and we give you full control over what's collected and how long it's kept.
Most SaaS platforms store your customer data on their servers. Signal Engine takes a different approach — AI processing happens directly from your browser to Anthropic's API. We never see your customer data.
Your customer data never touches Signal Engine's servers during AI analysis.
Every layer of Signal Engine is designed to protect your data and your customers' data.
Plain language. No legal jargon. Here's exactly what each regulation requires and how Signal Engine addresses it.
| Regulation | Requirement | How Signal Engine Complies | Status |
|---|---|---|---|
| GDPR | Lawful basis for processing personal data | Processing is based on contract performance and legitimate interest. Users are informed at signup. | ✓ Compliant |
| GDPR | Right to access personal data | Users can request a full export of their account data at any time via [email protected]. | ✓ Compliant |
| GDPR | Right to erasure ("right to be forgotten") | Account deletion removes all stored data within 30 days. Supabase row-level deletion is immediate. | ✓ Compliant |
| GDPR | Data breach notification within 72 hours | Incident response procedure in place. Affected users and supervisory authorities notified within 72 hours. | ✓ Compliant |
| CCPA | Right to know what data is collected | Full data inventory disclosed in our Privacy Policy. We collect: email, billing info, and usage analytics. | ✓ Compliant |
| CCPA | Right to opt out of data selling | We do not sell personal data. Ever. No "Do Not Sell" opt-out needed because there's nothing to opt out of. | ✓ Compliant |
| CCPA | Right to delete personal information | Account deletion available from Settings → Account → Delete Account. Data removed within 30 days. | ✓ Compliant |
| CAN-SPAM | Opt-out mechanism for marketing emails | Every marketing email includes a one-click unsubscribe. Opt-outs are honored within 10 business days. | ✓ Compliant |
| TCPA | Explicit consent for SMS marketing | SMS opt-in is explicit at signup. Users can text STOP at any time. Records of consent are maintained. | ✓ Compliant |
| SOC 2 Type II | Third-party security audit | Audit in progress. Expected completion Q3 2026. Supabase infrastructure is already SOC 2 Type II certified. | ⏳ In Progress |
These aren't buried in a 40-page privacy policy. These are your rights, plain and simple.
Questions about our data practices? Email [email protected] — we respond within 2 business days.