Signal SessionBack to Signal Session

Legal and trust

Privacy Policy

This working policy explains how Signal Session handles organization accounts, temporary attendee media, approved templates, synthetic results, and documented retained assets.

[LEGAL REVIEW REQUIRED] Working draft—not effective customer terms.
Effective date
Pending legal approval
Last updated
July 30, 2026
Document version
0.1-draft
On this page
  1. Scope
  2. Information collected
  3. Organization and facilitator accounts
  4. Attendee photographs
  5. Approved template videos
  6. Generated synthetic media
  7. Session and processing metadata
  8. Device and security logs
  9. Cookies and authentication technologies
  10. How information is used
  11. Synthetic-media processing
  12. Service providers and subprocessors
  13. Data retention and deletion
  14. Approved retained assets
  15. Security safeguards
  16. International processing
  17. Individual privacy requests
  18. Children
  19. Policy changes
  20. Contact

1. Scope

This policy applies to Signal Session’s controlled synthetic-identity security simulation service. Customer agreements and approved organization instructions may add terms that are consistent with this policy.

2. Information collected

We process organization and facilitator account information, attendee photographs, approved template videos, generated synthetic media, session and processing metadata, and limited device or security logs needed to operate the service.

3. Organization and facilitator accounts

Account data may include name, business email, organization role, account status, sign-in timestamps, and the administrator who provisioned access. Public signup is not offered.

4. Attendee photographs

A facilitator may submit one photograph collected for an authorized exercise. Ordinary attendee photographs are temporary by default and are not carried into a retained derivative.

5. Approved template videos

Organization administrators manage private, reusable driving videos. Templates are distinct from temporary attendee media and may remain available until disabled or deleted by an authorized administrator.

6. Generated synthetic media

A generated result combines an approved template with an attendee photograph. The undisclosed result is intended only for facilitator review and controlled Presentation Mode.

7. Session and processing metadata

We may record session status, timestamps, provider job state, safe failure codes, authorization decisions, presentation events, and deletion state. Audit metadata excludes media, secrets, and invitation tokens.

8. Device and security logs

Limited request, reliability, and security information may be processed to protect the service and investigate misuse. The precise production logging program remains subject to security and legal review.

9. Cookies and authentication technologies

Signal Session may rely on organization or platform authentication technologies to maintain restricted access. No advertising profile is created by the application.

10. How information is used

  • Operate authorized exercises
  • Validate and process private media
  • Generate and present synthetic results
  • Apply retention and deletion instructions
  • Maintain access controls and safe audit history
  • Investigate reliability or suspected misuse

11. Synthetic-media processing

When a paid provider is enabled, Signal Session transfers the approved template and attendee photograph to the selected provider for processing. Current integrations include Magic Hour and Pruna AI routed through Cloudflare AI Gateway. Signal Session temporarily stores inputs and results in private application storage.

12. Service providers and subprocessors

Current architecture dependencies are listed on the Subprocessors page. Providers receive only the information needed for their configured service. Production terms, locations, and retention details require verification before launch.

13. Data retention and deletion

Ordinary session media is temporary by default. Configurable retention is limited by platform rules. Completion revokes presentation access; deletion removes session media from active application storage and requests provider cleanup where supported. Exact provider or backup timing is not guaranteed here.

14. Approved retained assets

Live participation does not authorize future use. A separate request must identify uses, channels, owner, review date, and approval. Any retained or externally shared derivative requires a persistent synthetic-media disclosure.

15. Security safeguards

Implemented safeguards include restricted application access, organization-scoped records, server-side provider credentials, private media bindings, short-lived presentation tokens, and safe audit events. See the Security page for current limitations and planned controls.

16. International processing

[LEGAL REVIEW REQUIRED] Processing locations and any international transfer mechanism must be confirmed before production activation.

17. Individual privacy requests

Requests should be sent to the contact below. Signal Session will coordinate with the applicable organization and respond according to the governing agreement and law after legal review.

18. Children

The service is designed for authorized organizational exercises, not direct use by children or public consumer signup. Any exercise involving a minor requires separate review and authorization.

19. Policy changes

Material revisions will receive a new document version and updated date. Organization administrators should review changes before continued production use.

20. Contact

[LEGAL REVIEW REQUIRED] Privacy contact: privacy@signalsession.example. Replace this placeholder with the approved legal entity, mailing address, and monitored contact before launch.

© 2026 Signal Session
PrivacyTermsAcceptable UseSynthetic Media PolicyData RetentionSubprocessorsSecurityAccessibilityContact