
Privacy Policy
Effective October 1, 2026
SignGrant helps photographers, filmmakers and studios create, send, sign and keep model releases, property releases and related records. This policy explains what personal information SignGrant handles, why, who it's shared with, and the choices you have. It applies to the SignGrant website and app, including the signing pages people reach from a release link.
In short: we use information only to run SignGrant. We don't sell it, we don't use it for advertising, and SignGrant has no third-party analytics or ad trackers. Signed releases belong to the photographer or studio who created them.
1. Who we are
SignGrant is operated by Orange Studios, LLC (“SignGrant”, “we”, “us”). You can reach us about privacy at [email protected].
2. Customers, signers and who is responsible
SignGrant is used by two groups of people:
- Customers: the photographers, studios and their team members who have a SignGrant account and create releases.
- Signers: the models, parents or guardians, property owners and witnesses who fill in and sign a release, either from a link or in person on a customer's device.
For account information, we decide how it's used and are responsible for it. For releases and everything in them, the customer who created the release decides what is collected and what happens to the signed release; SignGrant stores and processes it on the customer's behalf, as their service provider (a “processor” under laws such as the GDPR). If you signed a release, the photographer or studio who sent it is your first point of contact about it; see section 11.
3. Information we collect
From customers, when you create an account and use SignGrant:
- Your name, email address, phone number and address.
- Your password, which we store only as a salted, one-way hash, never in readable form.
- Photographer and studio profiles you save: names, studio names, addresses, phone numbers, email addresses and signature images.
- Model Directory entries you save so you can reuse them on new releases: a person's name, email address, phone number, address, date of birth, gender and ethnicity (where you choose to record them), whether they are a minor and their parent's or guardian's name, a photo, and your private notes. These are entered by you, and are shared with the other members of your team.
- Your logo, release templates, email templates, form settings, team members and invitations, and your plan.
About the people on a release, entered by the customer: the model's or property owner's name and email address; shoot details such as the shoot name, date, location and photographer; photos of the model or property; notes; and any custom fields the customer adds.
Past releases you import. On paid plans, customers can upload scans, photos or PDFs of releases signed before SignGrant (see sections 5 and 6). The uploaded document is kept as the release's record, and the details read from it (names, dates, contact details and similar) are saved with the release after you review them.
From signers, when a release is filled in and signed. What's asked for depends on the release form the customer chose. It can include:
- Full legal name, email address, phone number and home address.
- Date of birth.
- For stock-agency forms such as Getty Images, Adobe Stock, or Shutterstock: gender and ethnicity. These questions are optional where the agency's form makes them optional, and are used only to complete that form.
- A parent's or guardian's name, when the model is a minor.
- A witness's name and signature, when the form requires a witness.
- Property details and ownership information for property releases.
- For §2257 records-keeping forms: legal name, other names used, descriptions and photos of two forms of identification (including a government-issued photo ID), and date of birth, as required by U.S. federal law (18 U.S.C. § 2257).
- Drawn signatures.
Signing records. For each release we record the steps of signing: when the signing link was emailed and to which address, when the signing page was opened, when the signer agreed to sign electronically, and when they signed. With those steps we record the IP address and the browser and device information the browser sends (its “user agent”, for example “Safari on iPhone”), and the language the form was shown in. Together these form the release's audit trail, which shows when and how it was signed. We don't collect precise (GPS) location.
Technical information. Like most websites, our servers automatically receive basic request information such as IP addresses, browser type and the pages requested, which we use to operate and secure the service.
4. How we use information
- To provide SignGrant: creating releases, showing signing pages, producing signed PDFs and audit records, and keeping releases organised in your account.
- To send email you ask us to send: signing invitations, copies of signed releases to signers who request one, team invitations, and password resets.
- To save and reload Model Directory entries when you create new releases. When a customer picks a saved person, their saved address, phone number and, for stock-agency forms, date of birth, gender and ethnicity can pre-fill the signing page. The signer can review and change them, and what they enter is saved with the release; the directory itself is never changed by a signer.
- To read and fill in the details of a past release you upload to Import (see section 5).
- To create blockchain timestamps of signed releases (see section 7).
- To copy signed releases to cloud storage you connect (see section 5), when you turn that on.
- To keep SignGrant secure, prevent fraud and abuse, provide support, and meet our legal obligations.
We do not sell personal information, share it for targeted advertising, or use the contents of releases, photos or ID images to train artificial-intelligence models.
5. When information leaves SignGrant
We share information only in these situations:
- With the customer and their team. Everything a signer submits goes to the photographer or studio who sent the release, and to members of their SignGrant team.
- Email delivery. Emails are sent through a mail delivery provider that we use. The provider handles the recipient's address and the message, including any attached signed release.
- Cloud storage you connect. If a customer connects Google Drive, Dropbox or Microsoft OneDrive, signed releases and shoot photos are copied into their own storage. SignGrant asks only for access to the folder it creates (for Google Drive, only files SignGrant made; for Dropbox and OneDrive, SignGrant's own app folder), plus the account's email address to show which account is connected. Once copied, those files are also governed by that provider's privacy policy. You can disconnect at any time in Settings.
- AI document reading (Import). When a customer uses Import, the uploaded document (its text, or an image of its pages) is sent to Anthropic, PBC, whose Claude model reads it and returns the details to pre-fill the release. Anthropic processes it only to provide that result for us, and under our agreement with Anthropic it is not used to train its models. Nothing is sent to Anthropic unless a customer uploads a document to Import. Anthropic's own privacy terms also apply to that processing.
- Stock agencies. A customer may submit a release to an agency such as Getty Images, Adobe Stock, or Shutterstock. That is the customer's decision and is covered by the agency's own privacy policy; SignGrant doesn't send releases to agencies itself.
- Legal reasons. When we believe in good faith that the law, a court order or a valid legal request requires it, or to protect the rights, safety or property of our users, the public or SignGrant.
- Business changes. If SignGrant is involved in a merger, acquisition or sale of assets, information may transfer to the new owner, who will remain bound by this policy for information collected under it.
6. AI-assisted import
Import is optional and available only on paid plans. When a customer uploads a document, an AI model reads it to suggest the release's details; the customer then reviews and corrects them before anything is saved, and a person, not the AI, decides what is kept. The original document is stored as the release's record. Imported releases are labelled as imported and have no SignGrant audit trail or blockchain timestamp, because SignGrant did not witness the original signing. Customers should upload only releases they are entitled to hold and use. We do not use releases, photos or ID images to train AI models.
7. Blockchain timestamps
When a release is signed, SignGrant computes a SHA-256 fingerprint of the signed release and submits only that fingerprint to the public OpenTimestamps service, which anchors it in the Bitcoin blockchain. This lets anyone later prove that the release existed, unchanged, at that time.
The fingerprint is a one-way code: no personal information can be recovered from it, and no names, photos or other release contents are sent. Because the Bitcoin blockchain is public and permanent, the fingerprint can't be removed once it's anchored, even if the release itself is later deleted from SignGrant.
8. Cookies and local storage
SignGrant uses one essential cookie to keep you signed in. It expires after seven days, or when you sign out. We also store a few display preferences in your browser's local storage, such as whether you dismissed the setup checklist. SignGrant doesn't use advertising, analytics or third-party tracking cookies.
9. How long we keep information
- Releases are kept for as long as the customer keeps them in their account. Releases are often legal records that need to be kept for years, so the customer decides when to delete them. Deleting a release removes its photos and ID images too. Archiving only hides it from the main list.
- Account information is kept while the account is open. When an account is closed at the customer's request, we delete its data within 30 days, except where we must keep something longer by law.
- Model Directory entries are kept until the customer deletes them or closes the account. Deleting an entry removes its photo too; it does not change releases already created from it.
- Backups may keep deleted data for a limited time until they are overwritten.
- Blockchain fingerprints are permanent (see section 7).
10. Security
We protect information with measures including encrypted connections (HTTPS), salted one-way hashing of passwords, encryption of the access keys for connected cloud storage, and access controls, so only the customer's own team can see their releases. SignGrant staff access account information only when needed to provide support, for example when resetting a password at your request, or to keep the service secure. No online service can be perfectly secure, but we work to protect your information and will notify affected customers of a breach as the law requires.
11. Your choices and rights
Customers can view and update their account details, templates and releases in the app at any time, delete releases, disconnect cloud storage, and ask us to close their account, send them a copy of their data, or correct or delete information by emailing [email protected].
Signers: a signed release is a record held by the photographer or studio who sent it, and releases often grant rights that can't simply be withdrawn. Please contact that photographer or studio first about access, correction or deletion. If you can't reach them, contact us at [email protected] and we will pass your request on and help where we can.
Depending on where you live (for example in the European Economic Area, the United Kingdom, or U.S. states such as California), you may have rights to access, correct, delete or receive a copy of your personal information, to object to or restrict some processing, and to complain to your local data-protection authority. We will not treat you differently for exercising these rights. Where we rely on consent, you can withdraw it at any time. Our legal bases for processing are performing our contract with customers, our legitimate interest in running and securing SignGrant, meeting legal obligations, and, where required, consent.
12. Minors
SignGrant accounts are for adults. We don't knowingly let anyone under 18 open an account. A model on a release may be a minor; in that case the release is signed by, and the minor's information is provided by, a parent or legal guardian, under the control of the customer who created the release.
13. Where information is stored
SignGrant stores information on servers we operate in the United States. If you use SignGrant from elsewhere, your information will be transferred to and stored there, and email and cloud-storage providers may process it in other countries. Where the law requires, we use appropriate safeguards for these transfers.
14. Changes to this policy
We may update this policy as SignGrant changes. We'll change the effective date above, and for significant changes we'll let customers know by email or in the app before the change takes effect.
15. Contact us
Questions or requests about privacy: [email protected].
Orange Studios, LLC