Effective date: 3 September 2026
Data controller: Signlo, Inc., a Delaware corporation,
8 The Green #25812, Dover, DE 19901, United States
Data Protection Officer (DPO): the founder, appointed
DPO: contact privacy@signlo.com
Representative in the EU (GDPR Art. 27): Emmanuel Jacq,
16 rue de Marignan, 75008 Paris, France,
privacy@signlo.com
Signlo is built for the Deaf community. We collect the least data we need to run a video-first social network, we treat your sign-language video as sensitive data, and we never sell your data. You can download your data and delete your account from inside the app at any time.
| What we collect | Account (email), profile (name, handle, bio, name-sign), your videos/photos/captions, who you follow, messages, RSVPs, device push token, basic app/diagnostic data, and (only if you opt in) a coarse (~5 km) approximate location. |
| Sensitive data | Your sign-language video (face + hands) is treated as special-category data (GDPR Art. 9). We never use it to identify or track you, and we do not run face recognition. |
| Why | To run the service, keep it safe, and improve it. |
| Who sees it | You and the people you choose; our infrastructure providers; our trust-and-safety partners for moderation/CSAM handling. |
| Where it's stored | United States (Supabase, US region; Cloudflare global CDN). |
| Your controls | In-app data export and account deletion; block/report; opt-in (not default) for location and sound. |
| Selling data | Never. |
The data controller is Signlo, Inc., a Delaware corporation, 8 The Green #25812, Dover, DE 19901, United States. The founder is the appointed Data Protection Officer. For any privacy request or question, contact privacy@signlo.com.
Signlo is not established in the European Union, so under GDPR Article 27 we have designated a representative in the Union: Emmanuel Jacq, 16 rue de Marignan, 75008 Paris, France, reachable at privacy@signlo.com. If you are in the EU or EEA you may address the Representative instead of, or as well as, Signlo on any data-protection matter, and so may your supervisory authority.
You give us: - Email address: to sign you in (one-time code) and send essential account messages. - Profile: display name, handle, bio, sign languages, Deaf-identity tag, optional interpreter/ relay tags, avatar photo, and your name-sign and intro videos. - Your Content: sign-language videos, photos, captions, comments. - Social graph: who you follow, your group memberships, event RSVPs, and the messages you send (including sign-language video messages). - Reports and blocks you make.
We collect automatically: - Device push token: only if you enable notifications, so we can send visual message alerts. - Basic technical/diagnostic data: app version, device type, crash reports, and aggregate product analytics, used to keep the app stable and improve it. Our analytics and diagnostics providers are PostHog (product analytics) and Sentry (crash and error reporting).
Only if you opt in: - Approximate location: to help you find signers and events near you. We compute a coarse (~5 km) geohash on your device; your precise GPS is never sent to our servers. Sharing is off by default, you choose the precision (nearby / city / country / continent), and you can turn it off any time. Turning it off removes your stored location.
We do not ask for more than we need, and we do not require sound; audio is opt-in and off by default.
Sign-language video shows your face and hands and is central to Signlo. Because it can reveal who you are and information about you, we treat it as special-category (sensitive) personal data under GDPR Article 9. Our safeguards:
We do not sell your personal data and do not use your content to train advertising profiles.
Signlo stores data in the United States. If you are in the EU/EEA, UK, or elsewhere, your data is transferred to the US. We rely on appropriate safeguards for these transfers (such as the EU Standard Contractual Clauses with our US providers).
We keep your data only as long as needed to run the service and meet legal obligations. See the companion Data Retention & Breach document for the full schedule. In short:
Depending on where you live (GDPR/UK GDPR, and US state laws such as the CCPA/CPRA), you can:
To exercise a right we can't fully serve in-app, contact the DPO at privacy@signlo.com. We do not discriminate against you for exercising your rights.
Signlo is for adults (18+) only. We do not knowingly collect data from anyone under 18. If we learn an account belongs to a minor, we remove it. Any suspected child-safety content is handled through our trust-and-safety/CSAM process.
We use row-level security, encrypted connections (TLS), signed links for private video, least- privilege server functions, and rate limiting. No system is perfectly secure; see the Data Retention & Breach document for how we respond to incidents.
This website sets no cookies and runs no third-party trackers. There is no consent banner because there is nothing to consent to. If that ever changes, we will ask you before it does, not afterwards.
In the app, we store a small amount of data on your device so it can work: your sign-in session, your language and accessibility settings, and cached video so your feed is not re-downloaded every time. Product analytics can be turned off in Settings; sign-in and settings storage cannot, because the app cannot function without them.
We do not use advertising identifiers, we do not build advertising profiles, and we do not run third-party ad or social tracking pixels.
If we make material changes, we will notify you in the app or by email before they take effect.
Privacy questions and data requests:
privacy@signlo.com. The founder
is the appointed Data Protection Officer.
EU/EEA users may instead contact our Article 27 Representative, Emmanuel
Jacq, 16 rue de Marignan, 75008 Paris, France.
You also have the right to lodge a complaint with your local data
protection authority.
Postal address: Signlo, Inc., a Delaware corporation, 8 The Green
#25812, Dover, DE 19901, United States.