Privacy Notice
Last updated July 2026
Who we are
Phaevora, LLC, operator of Sigil Studio, is the data controller for personal data described here. Contact: Maryann@Phaevora.com.
What we collect and why
- Account data (email address, login credentials, authentication provider identifier) — to create and secure your account. Legal basis: performance of our contract with you.
- Content you create (seal designs, names, territories, uploaded logos, issued seal labels and codes) — to provide the Service. Legal basis: performance of contract.
- Usage and technical data (IP address, device and browser information, error logs) — for security, fraud prevention, and improving the product. Legal basis: our legitimate interests.
- Support messages — to answer your questions. Legal basis: legitimate interests.
- Referral and access-code records — to apply free access correctly and prevent abuse. Legal basis: performance of contract and legitimate interests.
Who we share it with
- Service providers and subprocessors that host our database, authentication, and application infrastructure.
- Stripe, our payment processor, for the sale of subscriptions, payment processing, subscription management, invoicing, and tax compliance.
- Professional advisers (legal, accounting) where necessary.
- Authorities where we are required to do so by law.
We do not sell your personal data.
Retention
We keep account and content data for as long as your account is active, and for a limited period afterwards to meet legal, accounting, and dispute-resolution obligations. After that it is deleted or anonymised.
Your rights
Subject to the law where you live, you may request access to your data, correction, deletion, restriction of processing, portability, or object to processing, and withdraw consent where processing is based on consent. You may also complain to your local data protection authority. Email Maryann@Phaevora.com and we will respond within one month.
International transfers
Our providers may process data outside your country, including outside the UK and EEA. Where that happens we rely on appropriate safeguards such as standard contractual clauses or adequacy decisions.
Security
We use appropriate technical and organisational measures, including encryption in transit, access controls, and row-level database security so you can only reach your own records.
Cookies
We use essential cookies and local storage to keep you signed in and to remember a referral link you followed. We do not use advertising cookies. You can clear these at any time in your browser settings.