Last updated: August 22, 2026
CLMSign (the “Service”) provides electronic-signature workflows through the CLMSign web app, Chrome extension, Google Docs add-on, and supported connected experiences such as the CLMSign integration for ChatGPT. This policy explains what data we process, why we process it, and how we protect it.
We use the data only to provide and secure CLMSign, authenticate users, authorize connected apps, create and send signing transactions, generate completed signed records and certificates, maintain audit evidence, provide templates, maintain account balances, process purchases, provide support, prevent abuse and comply with applicable legal obligations.
We do not sell Google user data, ChatGPT-connected account data, documents, signatures or account data. We do not use Google user data, ChatGPT-connected account data or document content for advertising or ad targeting.
The CLMSign integration for ChatGPT uses OAuth 2.1 authorization. When you connect your account, CLMSign presents the permissions requested by the integration. Current read-only permissions may include:
CLMSign verifies the OAuth token and required scope on each protected request. The connection uses short-lived access tokens and rotatable refresh tokens. You can disconnect the integration through the controls provided by ChatGPT; disconnection/revocation prevents new protected requests using the revoked token.
OAuth does not grant ChatGPT access to your CLMSign password, Google password, saved payment credentials, OTP codes, or unrestricted database access.
CLMSign’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The Google Docs add-on is designed to request the minimum access needed for its features. It is not intended to browse or index a user’s entire Google Drive.
We use service providers only as necessary to operate CLMSign. Depending on the feature used, these may include:
We do not authorize these providers to use CLMSign customer documents or Google user data for CLMSign advertising.
When a Google Doc is signed through CLMSign, the completed signed record is the finalized PDF stored by CLMSign together with its signing evidence. The Google Doc remains editable after signing. Changes made to that Google Doc after completion do not modify the completed signed PDF or its recorded document hash.
Draft and non-completed documents may be removed according to the controls available in the Service. Completed signed documents and their related audit evidence may be retained to preserve the integrity and availability of the executed record and to protect the legitimate interests of transaction participants.
OAuth authorization codes are short-lived and single-use. Access and refresh token records expire or can be revoked. Operational records may be retained as needed for security and abuse prevention.
You may request account deletion. If an account has no completed signed records, the account can be deleted. If completed records must be preserved, identifying account credentials may be deleted or anonymized while the executed record and necessary evidence are retained. Requests can be sent to support@signatureflow.com.
CLMSign uses access controls, HTTPS transport, scoped OAuth authorization, PKCE for OAuth authorization-code exchange, token hashing, document hashing, audit logging and other technical measures intended to protect data. No online service can guarantee absolute security.
CLMSign and its service providers may process data in countries different from the user’s country. Where required, we will use appropriate contractual or legal safeguards for cross-border processing.
CLMSign is not directed to children under the age at which they can independently consent to online services in their jurisdiction.
We may update this policy as the Service changes. The current version and update date will remain available at this URL.
Privacy questions or deletion requests: support@signatureflow.com