keysig
keysigLegal

Privacy Policy

Last updated September 1, 2026

THIS PRIVACY POLICY EXPLAINS HOW KEYSIG INC. ("KEYSIG," "WE," "US") COLLECTS, USES, SHARES, AND PROTECTS INFORMATION WHEN YOU USE KEYSIG.CO (THE "SERVICE"). KEYSIG IS A PLATFORM FOR DRAFTING, ELECTRONICALLY SIGNING, AND STORING MUSIC INDUSTRY AGREEMENTS, SO THE MOST SENSITIVE THING WE HANDLE IS THE CONTENT OF YOUR AGREEMENTS. THIS POLICY IS WRITTEN TO TELL YOU PLAINLY WHAT WE DO AND, JUST AS IMPORTANTLY, WHAT WE DO NOT DO.

KEYSIG IS NOT A LAW FIRM, DOES NOT PROVIDE LEGAL ADVICE, AND THIS POLICY IS NOT LEGAL ADVICE.

The short version: we collect what the Service needs to work, we share it only with the service providers that run the platform, we do not sell personal information, and you can delete your account and its data at any time. Inside the app, where your agreements live, there are no analytics or advertising trackers of any kind. On our public marketing pages we measure ad performance with a signup conversion signal, and only with your consent through our cookie notice (see Section 8); no names, emails, or agreement data are ever sent to an advertising service.

1. Who We Are and What This Policy Covers

The Service is operated by Keysig Inc., 107 Park Blvd, Malverne, NY 11565. This policy covers information handled through keysig.co, including our public pages, the authenticated app, the label portal, and the emails we send. It covers both keysig account holders and people who are not keysig users but whose information is processed because someone named them in an agreement (see Section 3).

2. Information We Collect

Account information. When you create an account: your name, stage or display name, email address, and, if you choose password sign-in, a password (stored by our authentication provider in hashed form; we never see or store your plain password). You can also sign up and sign in with a one-time link emailed to you, in which case there is no password to collect.

Profile information ("Legal Key"). Details you choose to add so agreements can be pre-filled: your legal name, artist or professional name, role (such as artist, producer, or manager), label, publisher, and manager status, deal preferences, company name, mailing address, phone number, your collective management organization (CMO) registrations (your performing rights organization (PRO), neighboring rights organization (NRO), and mechanical licensing collective (MLC) status), and IPI number. All profile fields are optional; you control what you add.

Agreement content and parties. The agreements you draft, upload, or execute, including all terms you enter, and the parties you name on them: names, email addresses, and, where you choose to add them, details such as splits, roles, PRO, NRO, and IPI information, and payment terms. Executed agreements are stored as signed PDF files in private storage. From your executed agreements we also derive structured ownership records per track (who owns what percentage of the composition and the master, with any identifiers the agreement documents), so you can see and export a clean picture of your catalog; these records are derived from your own agreements, not collected separately.

View-only copy recipients. If you add view-only recipients when sending an agreement, we collect their names and email addresses so the completed agreement can be emailed to them.

Tracks and collaborators. Information you add to organize your work: track titles and details, and the collaborators you keep on file (names, emails, and optional details such as legal name, address, phone, PRO, and IPI).

Catalog information. If you run a catalog audit, or look up a released track while adding one, we send the artist or track name you type to the music databases named in Section 5 and store what comes back against your account: track titles, ISRCs, release titles and dates, credits, and the internal identifiers those databases use. We also store the answers you give about each track, including the collaborator roles you record against it and whether you mark it as already covered by an agreement, so a later audit shows only what is new. You can delete an audit at any time.

Billing information. Your plan, subscription status, and a ledger of usage events (sends, unsigned-draft downloads, and refunds of credits). Payments are processed by Stripe; keysig never receives or stores your card number. We store Stripe customer and subscription identifiers so we can link your account to your subscription.

Marketing and early access consent records. If you give us your email address to hear from us, through the optional, unchecked-by-default box on our post-signing page or through an early access form on our marketing pages, we record the email address, the consent source, a timestamp, and your IP address, so we can prove the consent was real if we ever need to.

Referral information. If you share your referral link, we record your referral code and, when someone signs up through it, which account referred which, the referred email address, and whether the referral converted to a paid plan, so we can grant the reward exactly once.

Label template uploads. If a label uploads its own agreement template as a Word document, we store the uploaded file privately as a record of what the label provided, along with a timestamped record of which label administrator acknowledged the template content notice.

Technical information. Standard web server request logs kept by our hosting provider (such as IP address and requested pages) for operating and securing the Service. If an error occurs in the app, our error monitoring service receives a technical report that is scrubbed before it leaves your browser: email addresses and long identifier numbers are redacted, page addresses are stripped of query data, and the report identifies you at most by an opaque account id, never by name or email. Inside the authenticated app we do not run analytics scripts, advertising trackers, or session recording of any kind; our public marketing pages use the ad measurement described in Section 8.

3. If You Are Not a keysig User

keysig processes some personal information about people who never signed up, because a keysig user named them in an agreement. If someone named you as a party, we process your name and email address (and any other details the sender entered about you, such as your split on a song) in order to prepare the agreement and, if the sender sends it for signature, to deliver a signing link to your email through our e-signature provider.

We process this information because it is necessary to provide the service our user asked for: preparing a contract that involves you and inviting you to sign it. We use it for nothing else. Specifically, we will not send you marketing unless you separately and explicitly opt in, and we do not sell it.

If you sign a document, our e-signature provider keeps the signing audit trail, and the sender keeps the executed document in their account. If you later create a keysig account using the same email address you signed with, you will automatically see the agreements you are a party to, read-only.

If you believe your information was added to keysig improperly, or you want it removed from a draft that has not been executed, contact us at hello@keysig.co and we will work with you. Note that we cannot unilaterally alter executed contracts, which are legal records between you and the other parties.

4. How We Use Information

We use information only to run keysig:

  • To provide the Service: drafting, pre-filling, rendering, sending, signing, storing, and organizing agreements, deriving ownership records from your executed agreements, and operating your account.
  • To process payments, meter plan usage, and administer the referral program.
  • To send transactional email: email confirmation, sign-in links, signing invitations and reminders (via our e-signature provider), a welcome email, notices to counterparties that an agreement involving them was prepared, completed-agreement copies to view-only recipients you add, optional track reminders you set, label roster invitations, password reset emails, the marketing confirmation link, paper-signed notices to other signers, and notices from support actions.
  • To provide support when you contact us.
  • To secure the Service, monitor for errors, prevent abuse, and enforce our Terms of Service.
  • To measure whether our advertising works, limited to the public marketing pages and a signup conversion signal, as described in Section 8.
  • To comply with law.

Things we do not do: we do not sell personal information; we do not run analytics or ad trackers inside the authenticated app, and no agreement content, name, or email address is ever sent to an advertising service; and we do not use your agreement content to train artificial intelligence models. Plain-language definitions shown in the Service come from our own glossary; your agreement content is not sent to any AI service.

5. Who We Share Information With

We share information only with the service providers that operate the platform, each acting on our instructions, plus the recipients you direct us to send things to. Our providers are:

  • Supabase (database, authentication, and file storage): holds account, profile, agreement, party, track, collaborator, billing-ledger, and consent data, and executed PDFs in private storage. Privacy policy at supabase.com/privacy.
  • Vercel (web hosting): serves the website and keeps standard request logs, including IP addresses. Privacy policy at vercel.com/legal/privacy-policy.
  • Stripe (payments): receives the details you enter at checkout, including your card. keysig never sees your card number. Privacy policy at stripe.com/privacy.
  • DocuSeal (electronic signatures): receives the content of agreements sent for signature, each signer's name and email, and the names and email addresses of any view-only (CC) recipients you add, and maintains signing events and the signature audit trail. Privacy policy at docuseal.com/privacy.
  • Resend (transactional email): receives recipient email addresses and the content of the emails we send. Privacy policy at resend.com/legal/privacy-policy.
  • Deezer and MusicBrainz (music catalog lookups): when you run a catalog audit or look up a released track, we send them the artist or track name you typed so they can return matching releases. We send them nothing else: no name, no email, no account id, and no agreement data. Privacy policies at deezer.com/legal/personal-datas and metabrainz.org/privacy.
  • Sentry (error monitoring): receives scrubbed technical error reports from the app, as described in Section 2. Reports carry at most an opaque account id; emails, names, and identifier numbers are redacted before sending, and no agreement content is included. Privacy policy at sentry.io/privacy.
  • Meta and Google (ad measurement on public pages only): when enabled and you have consented through our cookie notice, our public marketing pages load the Meta Pixel and the Google tag to count page views on those pages and a single "account created" conversion event. These tags receive no name, email, user id, or agreement data from us, and they do not load inside the authenticated app. They set their own cookies, described in Section 8. Privacy policies at facebook.com/privacy/policy and policies.google.com/privacy.
  • Credits.fm (music catalog and rights data): when you run a catalog audit or look up a released track, we send them the artist or track name you typed, and they return matching releases and associated ISRCs and rights data. Privacy policy at credits.fm/privacy.
  • Cloudflare (encrypted backups): stores encrypted backup copies of our database and stored files, including executed PDFs, for disaster-recovery purposes. Each backup is encrypted with a key that only keysig holds, so Cloudflare cannot read its contents, and backups are kept only for a limited period before being cycled out in the ordinary course. Privacy policy at cloudflare.com/privacypolicy.

Beyond these providers, we share information only: with the people you direct (the signers and parties you add); within a label account as described in Section 7; with additional service providers we engage to operate, secure, or improve the Service, each bound by confidentiality and data protection obligations consistent with this policy, in which case we will update this policy and, for material changes in the categories of data shared, provide notice as described in Section 13; if required by law, legal process, or to protect the rights, safety, or property of keysig or others; or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to your information until you are told otherwise. We have never been subject to such a transaction as of the date above.

6. Electronic Signature Data

When an agreement is sent for signature, our e-signature provider processes it on our behalf: it renders the document, emails each signer a unique signing link, records signing events (such as when a document is viewed, signed, or declined), and produces the executed PDF and its audit trail. Signature audit data, which can include signer IP addresses and timestamps, is collected by the provider as part of making the signature verifiable. keysig receives status updates about these events and stores the executed PDF in your account's private storage.

7. Label Accounts

If your keysig account is part of a record label's roster, each agreement you create is either label work or your own personal work: the choice is shown before you start drafting, defaults to the label while your membership is active, can be switched before the agreement is created, and is fixed once the agreement is created. The label's staff (its owner and administrators) can see, on a read-only basis:

  • The agreements created under the label, along with your monthly usage under the label's limits.
  • A catalog view of the tracks those label agreements cover and of the ownership details they document (the parties, splits, roles, and rights-organization identifiers, and whether each of those tracks has label agreements covering it). This exists so a label can keep the paperwork on its own work complete; it never includes your personal agreements, or tracks and ownership details documented only by them.

Label staff cannot edit or delete your agreements, tracks, or anything else in your account. You can leave a roster at any time from your account settings, and a label can remove you; either way you keep everything in your account, and the label keeps read-only access to the agreements created under it while you were a member. Roster invitations are sent by email and include the invitee's email address and inviting label.

If a label uploads its own agreement templates, the template text and configuration are visible to the label's roster in the template picker, and the uploaded source file is stored privately and visible only to that label's staff.

8. Cookies and Browser Storage

Storage the Service itself uses. keysig sets no cookies of its own. We use the browser's storage for the Service to function:

  • Sign-in session. Your authentication session token is kept in your browser's local storage by our authentication library so you stay signed in.
  • Access code. During our private preview, the access code you enter is kept in local storage so you are not asked again on that device.
  • Demo drafts. If you try the demo without an account, your draft lives only in your browser's local storage until you create an account and choose to save it. Nothing is written to our servers during the demo.
  • Invitation, referral, and preference tokens. Short-lived items such as a pending label invitation token or the referral code from a link you followed are kept in browser storage until used. Logged-out track audit. If you run a catalog audit before creating an account, the results are kept in your browser's session storage so they can be used to help populate your account with tracks once you create one; if you do not create an account in that browser session, the results are discarded.

Ad measurement cookies on public pages, only with your consent. When our ad measurement is enabled, we ask before loading anything. A cookie notice appears at the bottom of the page with three choices: "Accept all," "Reject non-essential," and "Manage preferences." Nothing is pre-selected, and no optional tag loads until you choose. If you accept, the public marketing pages (the landing pages, demo, guides, and sign-in and sign-up pages) load the Meta Pixel and the Google tag, which set their own cookies to count visits to those pages and account-signup conversions. We configure them to receive no name, email, or account data from us, and they are never loaded inside the authenticated app, where your agreements live. If you reject, the tags are not loaded at all.

Changing your mind. A "Cookie preferences" link in the footer of the Service reopens the choice at any time. Withdrawing consent stops the measurement: the tags are told to stop, no further events are sent, and they are not loaded on your future visits. Your choice is stored in your browser's local storage; if we materially change what we ask consent for, we will ask again. You can also block these cookies with your browser's settings or a content blocker; the Service works fully without them.

Global Privacy Control. If your browser sends the Global Privacy Control (GPC) signal, we treat it as a rejection of ad measurement: the tags do not load, the ad measurement choice is shown as off and locked, and the signal overrides any earlier acceptance. We honor GPC as a legally recognized opt-out signal.

Everything else. Inside the authenticated app there are no analytics, advertising, or session-recording scripts of any kind. Third-party pages you visit as part of a flow, such as Stripe's checkout page or DocuSeal's signing page, are operated by those providers and may set their own cookies under their own policies.

9. Data Retention and Deleting Your Account

We keep your information for as long as your account exists, so your agreements are there when you need them.

Deleting your account. You can delete your account at any time from the settings page. Deletion is immediate for your profile, draft (unsigned) agreements, parties, tracks, collaborators, notifications, usage ledger, subscription records, and login. Executed agreements and their stored signed PDFs are retained for 30 days after deletion (extendable to 60 days if a counterparty has an open, unresolved access issue) before they too are permanently deleted, so other parties who relied on your account to access a signed document have a window to obtain their own copy. Notwithstanding the foregoing, agreements you created under a label account that were sent for signature or signed remain with that label on a read-only basis indefinitely, even after you delete your account; only your unsent label drafts and personal drafts are deleted along with your account. Download and share final copies of any executed agreements you or your counterparties need before deleting your account. If your account owns a label account, contact us first so we can transfer the label to another member of its roster or close it; a label owner's account cannot be deleted until that is done. Deleting your account also cancels any paid subscription with our payment processor immediately.

What survives deletion. A few narrow records outlive an account, for good reason:

  • Marketing consent records (email, consent timestamp, IP) are kept as an audit trail of consent, and unsubscribes are honored against them.
  • Records our payment processor and e-signature provider are required to keep (such as payment records and signature audit trails) are retained by those providers under their own policies.
  • Copies of executed agreements that other parties already received by email or downloaded are theirs and are outside our systems.
  • Residual copies may persist for a limited time in encrypted backups of our database before being cycled out in the ordinary course.

Non-user information. Information about non-user parties lives inside the owning user's account data and follows it: it is deleted when the agreement or the owning account is deleted, subject to the same carve-outs above.

10. Security

We take the security of agreement data seriously and implement reasonable technical and organizational safeguards, including:

  • Encryption in transit (TLS) for all connections to the Service and between our systems and our providers, and encryption at rest for the database and file storage as provided by our infrastructure provider.
  • Row-level security in our database, so each account can access only its own records, enforced at the database layer rather than only in application code.
  • Executed documents kept in private storage, accessible only through short-lived signed links generated for authorized users.
  • Access controls that keep administrative tooling to account and subscription metadata: keysig's own admin console cannot read the contents of your agreements.
  • Passwords handled by our authentication provider using industry-standard hashing; webhooks verified with signed secrets; payment card data handled entirely by Stripe.

No service can promise perfect security, and we do not. If we learn of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.

11. Your Rights and Choices

Everyone, regardless of location:

  • Access and portability. Your agreements and profile are visible in your account, and you can download your documents as PDFs.
  • Correction. You can edit your profile and drafts directly in the app.
  • Deletion. You can delete individual drafts, or delete your entire account from settings, as described in Section 9.
  • Marketing. Marketing is opt-in only; we do not email marketing to anyone who has not explicitly asked for it. Any marketing email we send will include an unsubscribe link, and you can opt out at any time by emailing hello@keysig.co.
  • Anything you cannot do in the app, you can request by emailing hello@keysig.co. We will verify that the request comes from the email associated with the data before acting on it.

California residents. The California Consumer Privacy Act, as amended by the CPRA, gives you the right to know what personal information we collect, use, and disclose (this policy is that disclosure), to access it, to correct it, to delete it, and to not be discriminated against for exercising those rights. We do not sell personal information. Our only advertising-related disclosure is the consent-based ad measurement on our public marketing pages described in Section 8; to the extent that counts as "sharing" under California law, the "Cookie preferences" link in the footer of the Service is our "Your Privacy Choices" control: it lets you turn ad measurement off (or never turn it on; it is off until you accept), and we also honor the Global Privacy Control signal as an opt-out, as described in Section 8. You can additionally opt out by emailing hello@keysig.co.

Sensitive personal information. The only sensitive personal information categories we process are account log-in credentials (handled by our authentication provider, as described in Section 2) and precise information you choose to include in agreement content (such as payment or financial deal terms you enter). We use sensitive personal information solely to provide the Service you request and do not use or disclose it for purposes that trigger a right to limit use under the CPRA. To exercise any right, email hello@keysig.co; you may use an authorized agent if we can verify the request. We will respond within the time set by law.

Outside the United States. keysig is operated from the United States, our templates are built around United States law, and information is processed and stored in the United States. If you use the Service from elsewhere, your information will be transferred to, and processed and stored in, the United States, which may not have data protection laws equivalent to those in your jurisdiction. Where the General Data Protection Regulation (GDPR) or the UK GDPR applies to you, we process your personal information on the following legal bases: performance of a contract with you (providing the Service), our legitimate interests (such as securing and improving the Service), your consent (such as for ad measurement cookies described in Section 8), and compliance with legal obligations. You have the rights to access, correct, delete, restrict, or object to processing of your information, to data portability, and to lodge a complaint with your local supervisory authority. Where required, we will put appropriate safeguards in place for transfers of personal information out of the European Economic Area, the United Kingdom, or Switzerland. Where local law grants you rights to access, correct, delete, restrict, or object to processing of your information, or to data portability or to complain to a supervisory authority, you can exercise them by emailing hello@keysig.co and we will honor them as the law requires.

12. Children

The Service is for adults: you must be at least 18 to create an account, and it is not directed to children under 13 (or under 16 where a higher age applies). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact hello@keysig.co and we will delete it.

13. Changes to This Policy

We may update this policy from time to time. If we make a material change, we will give you reasonable advance notice, such as by email to your account address or a prominent notice in the Service. The "Last updated" date at the top shows when this policy last changed. Continuing to use the Service after a change takes effect means the updated policy applies.

14. Contact Us

Privacy questions and requests: hello@keysig.co

Mail: Keysig Inc., 107 Park Blvd, Malverne, NY 11565

If you contact us about your data, we will confirm receipt and respond as quickly as we can, and always within any deadline the law sets.

keysig is not a law firm and does not provide legal advice. Have agreements reviewed by qualified counsel before signing.