Privacy
In plain English
Sigil holds your OAuth tokens so your AI agents don't have to. We never sell your data. We never read your inbox, your calendar, your Drive, your repos, or your messages — those API calls are initiated by your agents at your direction, and Sigil's job is only to enforce the permissions you set. Your tokens are encrypted at rest with hardware-backed keys. You can export or delete your account at any time.
1. Who we are
Sigil is operated by the founding team behind Maturo.ai. The legal entity standing behind Sigil is being finalised as of June 2026 and will be a UK limited company. For purposes of the UK GDPR and EU GDPR, the data controller for Sigil is reachable at [email protected].
2. What Sigil is
Sigil is a personal credential gateway. You connect third-party services (Gmail, Google Calendar, Google Drive, Notion, Slack, GitHub, etc.) to Sigil once. Then you connect AI assistants (Claude, Cursor, OpenClaw, ChatGPT, custom MCP clients) to Sigil. When an AI assistant wants to act on your behalf, it asks Sigil. Sigil checks what you've permitted, makes the upstream API call using your credentials, and returns the result.
This means Sigil sits in the path of every API call your AI makes. We process the request and response — but we are not the originator of the call, and we do not access these services on our own behalf.
3. What we collect
3.1 Account data
- Your email address — required to create an account and to send transactional email (password reset, security alerts, billing).
- Your Auth0 user ID — assigned when you sign up. We use Auth0 (auth0.com/privacy) to handle authentication.
- Your name, if you provide one — optional. Used to address you in the dashboard.
- Your IP address and user-agent — captured on sign-in and on sensitive actions (consent screen, revoke). Used to populate the audit log and detect anomalous activity.
3.2 Credentials you connect
When you connect a third-party service to Sigil, the OAuth refresh token and access token from that provider are:
- Encrypted at rest in Azure with a per-user data encryption key, which is itself wrapped under a master key held in Azure Key Vault (HSM-backed).
- Decrypted only when an authorised AI agent makes a request that requires them, and only inside an authenticated process boundary.
- Never logged in plaintext, never emailed, never displayed in the dashboard.
- Refreshed automatically when the upstream provider rotates them. The old tokens are overwritten.
3.3 Activity data
- Audit log — every action your agent takes through Sigil is recorded: which agent, which tool, which scope, the SHA-256 hash of the parameters (not the parameters themselves), the timestamp, the outcome (allowed / denied / error). Visible to you in real time at
app.joinsigil.com/dashboard/audit. - Grant history — when you tick a scope on the consent screen, when you revoke it, which agent it applied to.
- Anomaly signals — request rates per agent, used to alert you when an agent behaves out of character.
3.4 Billing data
If you subscribe to a paid plan, Stripe handles the card and billing data — we never see or store full card numbers. We store your Stripe customer ID, your active plan, and your renewal date.
4. Why Sigil requests each Google OAuth scope
Sigil requests narrow Google OAuth scopes only when you choose to connect a Google service. Each is requested for the specific feature it backs. None are used for any other purpose.
| Scope | Why we request it |
|---|---|
https://www.googleapis.com/auth/gmail.send | To allow your AI agent to send email on your behalf, when you have explicitly granted that permission to that specific agent. |
https://www.googleapis.com/auth/gmail.readonly | To allow your AI agent to read messages from your inbox, when you have explicitly granted that permission. We do not modify or delete email. |
https://www.googleapis.com/auth/calendar.events | To allow your AI agent to list upcoming calendar events and to create new events, when you have explicitly granted those permissions. We do not request the broader calendar scope. |
https://www.googleapis.com/auth/drive.readonly | To allow your AI agent to search your Drive and read the content of documents you have directed it to. Read-only. |
https://www.googleapis.com/auth/drive.file | To allow your AI agent to create files in your Drive scoped to files the integration itself creates or opens. The agent never sees files outside of those it has been granted access to. |
https://www.googleapis.com/auth/spreadsheets | To allow your AI agent to read cell values from Sheets you direct it to, and to append rows to those Sheets when you have granted write permission. |
openid email | To identify which Google account you connected, so re-connecting overwrites the existing record rather than creating a duplicate. |
Sigil's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties for advertising, we do not use it to serve ads, we do not allow humans to read it except where you have given affirmative agreement for specific messages, where necessary for security purposes (e.g. investigating abuse), or to comply with applicable law.
5. Who sees your data
- You. Always.
- Your AI agents. Only to the extent of the scopes you have granted to that specific agent, and only for the specific request they initiated. They never see your tokens.
- Sigil engineers. Only in narrow operational circumstances — investigating a bug you have reported, responding to a security incident, complying with a lawful request. Engineer access to production data is logged.
- No-one else. We do not share, sell, rent, or trade your data. We do not give your data to AI vendors (Anthropic, OpenAI, etc.) — Sigil acts on requests originated by your agents; it does not originate calls of its own to those vendors.
6. Subprocessors
We use the following services to operate Sigil. Each is bound by a data processing agreement.
| Vendor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Application hosting, database, Key Vault | UK South |
| Auth0 (Okta) | User authentication | EU |
| Stripe | Subscription billing | US / EU |
| Sentry | Application error tracking (no user data in payloads) | US |
| Microsoft Azure Communication Services | Transactional email (sign-in, billing, security alerts) | EU |
| Netlify | Static marketing site (joinsigil.com) only | US |
An always-current subprocessor list is at joinsigil.com/security#subprocessors. We will give 30 days' notice before adding a new subprocessor that processes user content.
7. Where your data lives
The primary production database, the Azure Key Vault holding the master encryption key, and all application servers are in the UK South Azure region. Backups are encrypted and remain in-region. International transfers (e.g. when you visit our site from outside the UK or EU) are governed by Standard Contractual Clauses where applicable.
8. How long we keep it
- Account data — until you delete your account, then within 30 days.
- OAuth tokens — until you revoke the connection or delete your account. Refresh tokens are also revoked upstream when you delete.
- Audit log — 90 days for users on the free plan, 365 days on paid plans. You can export your full audit log at any time.
- Billing records — 7 years after your last payment, as required by UK tax law.
- Backups — 30 days, encrypted at rest.
9. Your rights
You can do any of the following at any time, from your dashboard or by emailing [email protected]:
- Access / export — download a JSON of everything we hold on you, from
app.joinsigil.com/account. - Delete — wipe your account end-to-end. Cancels your subscription, revokes upstream OAuth grants where supported, deletes connections, tokens, agents, grants, and audit log. Completed within 30 days; some billing records retained as required by law.
- Correct — change your email, name, or billing details from your dashboard.
- Object / restrict — narrow how we use your data.
- Portability — your export is JSON, suitable for moving to a competitor.
- Complain — to the UK Information Commissioner's Office (ico.org.uk) or your local DPA.
10. Children
Sigil is not designed for or directed at people under 16. We do not knowingly collect data from anyone under that age. If you believe we have, email [email protected] and we will delete it.
11. Cookies and tracking
The marketing site (joinsigil.com) uses no analytics or advertising trackers. The dashboard (app.joinsigil.com) sets a session cookie for authentication and an opt-in analytics cookie (Mixpanel) used solely for product usage metrics. Analytics are opt-in only and can be revoked at any time from the dashboard footer banner.
12. Security
Sigil's security posture — encryption, key management, vulnerability disclosure, incident response — is documented in detail at joinsigil.com/security. If you have found a security flaw, please report it to [email protected] first.
13. Changes to this policy
We will notify you by email at least 30 days before any change that materially affects how we use your data. Minor clarifications and corrections are published with an updated effective date.
Questions? Email [email protected]. A real person reads every message.