CLMSign Privacy Policy

Last updated: August 22, 2026

CLMSign (the “Service”) provides electronic-signature workflows through the CLMSign web app, Chrome extension, Google Docs add-on, and supported connected experiences such as the CLMSign integration for ChatGPT. This policy explains what data we process, why we process it, and how we protect it.

Connected apps in plain language: connecting CLMSign to ChatGPT does not give ChatGPT your CLMSign password. CLMSign uses OAuth access tokens with limited permissions. In the current read-only integration, ChatGPT can access only the account/document/evidence information covered by the permissions you approve. The integration does not sign, send, void, purchase, or modify documents on your behalf in its read-only version.

1. Data we process

2. How we use the data

We use the data only to provide and secure CLMSign, authenticate users, authorize connected apps, create and send signing transactions, generate completed signed records and certificates, maintain audit evidence, provide templates, maintain account balances, process purchases, provide support, prevent abuse and comply with applicable legal obligations.

We do not sell Google user data, ChatGPT-connected account data, documents, signatures or account data. We do not use Google user data, ChatGPT-connected account data or document content for advertising or ad targeting.

3. CLMSign for ChatGPT and OAuth

The CLMSign integration for ChatGPT uses OAuth 2.1 authorization. When you connect your account, CLMSign presents the permissions requested by the integration. Current read-only permissions may include:

CLMSign verifies the OAuth token and required scope on each protected request. The connection uses short-lived access tokens and rotatable refresh tokens. You can disconnect the integration through the controls provided by ChatGPT; disconnection/revocation prevents new protected requests using the revoked token.

OAuth does not grant ChatGPT access to your CLMSign password, Google password, saved payment credentials, OTP codes, or unrestricted database access.

4. Google API data and Limited Use

CLMSign’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The Google Docs add-on is designed to request the minimum access needed for its features. It is not intended to browse or index a user’s entire Google Drive.

5. Service providers and connected platforms

We use service providers only as necessary to operate CLMSign. Depending on the feature used, these may include:

We do not authorize these providers to use CLMSign customer documents or Google user data for CLMSign advertising.

6. Signed record vs. editable Google Doc

When a Google Doc is signed through CLMSign, the completed signed record is the finalized PDF stored by CLMSign together with its signing evidence. The Google Doc remains editable after signing. Changes made to that Google Doc after completion do not modify the completed signed PDF or its recorded document hash.

7. Retention and deletion

Draft and non-completed documents may be removed according to the controls available in the Service. Completed signed documents and their related audit evidence may be retained to preserve the integrity and availability of the executed record and to protect the legitimate interests of transaction participants.

OAuth authorization codes are short-lived and single-use. Access and refresh token records expire or can be revoked. Operational records may be retained as needed for security and abuse prevention.

You may request account deletion. If an account has no completed signed records, the account can be deleted. If completed records must be preserved, identifying account credentials may be deleted or anonymized while the executed record and necessary evidence are retained. Requests can be sent to support@signatureflow.com.

8. Security

CLMSign uses access controls, HTTPS transport, scoped OAuth authorization, PKCE for OAuth authorization-code exchange, token hashing, document hashing, audit logging and other technical measures intended to protect data. No online service can guarantee absolute security.

9. International processing

CLMSign and its service providers may process data in countries different from the user’s country. Where required, we will use appropriate contractual or legal safeguards for cross-border processing.

10. Children

CLMSign is not directed to children under the age at which they can independently consent to online services in their jurisdiction.

11. Changes

We may update this policy as the Service changes. The current version and update date will remain available at this URL.

12. Contact

Privacy questions or deletion requests: support@signatureflow.com