Privacy Policy
Last updated: 22 July 2026
Sigil personalises email signatures from your organisation's Microsoft 365 directory. This policy explains what data the service processes, why, and what it deliberately never touches.
Who we are
Sigil is provided by Tophhie Cloud (“we”, “us”). When you use Sigil, your organisation is the data controller for its directory data and we act as a data processor on your behalf. For our own account and billing records we act as a controller. You can reach us at privacy@usesigil.app.
What Sigil processes
Directory attributes (to build signatures)
To render a personalised signature, Sigil reads user attributes from your Microsoft 365 directory through the Microsoft Graph API, using permissions your administrator grants at onboarding. These include name, job title, department, company, email address, phone numbers, office and address, manager details, and any on-premises extension attributes your organisation uses. Sigil only ever reads the directory — it never writes to it. These attributes are already visible to colleagues in the address book.
Templates and images you create
Signature templates, compliance footers, campaign banners and the images you upload are stored so the service can render and manage them.
Usage telemetry (to show the service is working)
Sigil records metadata about signature activity so administrators can see whether signatures are reaching users: which mailbox requested a signature, which template version was served, the compose type, and whether the add-in applied it. It also counts clicks on tracked links in signatures and banners. This telemetry contains no IP addresses, no recipient identities, and no message content or rendered signature HTML — counts and metadata only.
Account and billing data
We store your organisation's tenant record and subscription details. Payment card handling is performed by our payment processor; we do not store card numbers.
What Sigil never does
- It does not read, store or transmit the content of your emails.
- It does not track individual recipients or log who received what.
- It does not sell or share personal data for advertising.
Sub-processors
Sigil relies on the following providers to deliver the service:
| Provider | Purpose |
|---|---|
| Microsoft | Identity (Microsoft Entra ID) and directory data (Microsoft Graph) |
| Cloudflare | Application hosting, storage and caching |
| Stripe | Subscription billing and payment card processing |
Retention and deletion
Directory data is read on demand to render signatures and cached only transiently. Templates, images and account records are kept for as long as your organisation uses Sigil. Activity telemetry (metadata only) is retained to provide historical adoption reporting. When an organisation is deprovisioned, its templates, images, cached signatures and tenant data are deleted.
Your rights
Depending on your location, you may have rights to access, correct or delete personal data, or to restrict or object to its processing. Because your organisation controls its directory data, please direct such requests to your organisation's administrator; we will assist them as processor. For data we control, contact privacy@usesigil.app.
Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected in the “last updated” date above.