SigilSigil
FeaturesHow it worksSecurityPricingFAQStart free trial
Sign inStart free trial

Privacy Policy

Last updated: 22 July 2026

Sigil personalises email signatures from your organisation's Microsoft 365 directory. This policy explains what data the service processes, why, and what it deliberately never touches.

Who we are

Sigil is provided by Tophhie Cloud (“we”, “us”). When you use Sigil, your organisation is the data controller for its directory data and we act as a data processor on your behalf. For our own account and billing records we act as a controller. You can reach us at privacy@usesigil.app.

What Sigil processes

Directory attributes (to build signatures)

To render a personalised signature, Sigil reads user attributes from your Microsoft 365 directory through the Microsoft Graph API, using permissions your administrator grants at onboarding. These include name, job title, department, company, email address, phone numbers, office and address, manager details, and any on-premises extension attributes your organisation uses. Sigil only ever reads the directory — it never writes to it. These attributes are already visible to colleagues in the address book.

Templates and images you create

Signature templates, compliance footers, campaign banners and the images you upload are stored so the service can render and manage them.

Usage telemetry (to show the service is working)

Sigil records metadata about signature activity so administrators can see whether signatures are reaching users: which mailbox requested a signature, which template version was served, the compose type, and whether the add-in applied it. It also counts clicks on tracked links in signatures and banners. This telemetry contains no IP addresses, no recipient identities, and no message content or rendered signature HTML — counts and metadata only.

Account and billing data

We store your organisation's tenant record and subscription details. Payment card handling is performed by our payment processor; we do not store card numbers.

What Sigil never does

  • It does not read, store or transmit the content of your emails.
  • It does not track individual recipients or log who received what.
  • It does not sell or share personal data for advertising.

Sub-processors

Sigil relies on the following providers to deliver the service:

ProviderPurpose
MicrosoftIdentity (Microsoft Entra ID) and directory data (Microsoft Graph)
CloudflareApplication hosting, storage and caching
StripeSubscription billing and payment card processing

Retention and deletion

Directory data is read on demand to render signatures and cached only transiently. Templates, images and account records are kept for as long as your organisation uses Sigil. Activity telemetry (metadata only) is retained to provide historical adoption reporting. When an organisation is deprovisioned, its templates, images, cached signatures and tenant data are deleted.

Your rights

Depending on your location, you may have rights to access, correct or delete personal data, or to restrict or object to its processing. Because your organisation controls its directory data, please direct such requests to your organisation's administrator; we will assist them as processor. For data we control, contact privacy@usesigil.app.

Changes to this policy

We may update this policy as the service evolves. Material changes will be reflected in the “last updated” date above.

SigilSigil

Consistent, on-brand, always-current email signatures for every mailbox in Microsoft 365.

Start free trial

Product

  • Features
  • How it works
  • Sigil vs Exclaimer
  • Pricing
  • FAQ

Get started

  • Start free trial
  • Admin portal
  • Book a demo

Company

  • Support
  • Privacy
  • Terms

© 2026 Sigil. A Tophhie Cloud product. All rights reserved.

Built on Microsoft 365 & Cloudflare.