TON Sign
EN RU
Version 2026-07-31.1

Privacy Policy

TON Sign is designed so personal documents are processed on your device. This policy explains the limited data the service still needs and how you can control it.

Data we process

  • Telegram profile data: ID, first name, username, language and photo URL when Telegram provides them.
  • TON wallet address, file hashes, TON proofs, file names and operation timestamps.
  • For shared rooms, participant metadata and only AES-GCM-encrypted document versions, IVs, salts and checksums.
  • Stars payment orders, Telegram payment charge ID, policy acknowledgements, support requests and protected server-session data.
  • If the free allowance was used, after account deletion an HMAC-protected pseudonymous identifier and the number of free documents used. The raw Telegram ID is not stored in this record.

PDFs, images and visual signatures in personal mode are not uploaded. Your browser processes them locally. A room passphrase is never sent to the server.

Purposes and legal grounds

We use data to authenticate you, provide requested features, retain proofs, synchronize encrypted rooms, process Stars and prevent abuse. The grounds are performance of the service terms, legitimate security interests and, where applicable, legal obligations. We do not sell data or create advertising profiles.

Recipients

Telegram supplies launch data and processes Stars payments. A TON wallet signs a hash; information published to TON may be public and immutable. Our infrastructure provider hosts the server and database. Those providers process data under their own terms. TON Sign does not give them your original personal document.

Retention and security

Account data remains while the account is active. Inactive server sessions expire automatically and never exceed 7 days in total. Support requests remain only while needed to handle the issue and are removed with the account. Minimum payment records may remain as long as needed for refunds, disputes and mandatory accounting. We use HTTPS, HttpOnly cookies, hashed session tokens and client-side room document encryption. If the free allowance was used, after account deletion its protected record remains effective for 12 months so re-registration cannot issue the same allowance again. It is not used for advertising or analytics; expired records are deleted automatically.

Your rights

The “Data & support” screen lets you download a JSON copy and delete your account. Deletion removes or anonymizes the Telegram profile, wallet, proofs, rooms you own and active sessions. A minimum payment record may remain without the Telegram profile. An HMAC-protected record of the number of free documents used remains for up to 12 months. It contains neither the profile nor the raw Telegram ID; matching is possible only on a new sign-in with a separate server key. Encrypted versions in a room owned by somebody else may remain until that owner deletes the room; the uploader is anonymized. Public blockchain data cannot technically be erased. You can also request correction, restriction or object through support.

Age and changes

You must be legally able to accept these terms and make payments in your country. If this policy changes materially, the app will ask you to review the new version.

Contact

Service operator: TON Sign. For data, payment or service questions, contact @tondocsign_bot and use /paysupport. Do not send original documents or signature images.

Privacy Policy Terms of Use Support