Terms
OpenAI Plugin Privacy Notice
How the SignatureAPI plugin for ChatGPT and Codex collects, uses, shares, and retains personal data.
This notice explains how Signature API, Inc. processes personal data through the SignatureAPI plugin for OpenAI products, including ChatGPT and Codex.
The plugin connects your SignatureAPI account to the OpenAI product you use. It lets you upload documents, request signatures, monitor signing, retrieve completed documents, and manage related emails and webhooks.
This notice covers plugin use. Our website Privacy Policy covers website and marketing activities. Our Data Processing Addendum (DPA) governs processing on behalf of business customers. This notice supplements those documents and does not change the DPA’s contractual commitments.
Information we receive
We receive the arguments and resources sent with plugin requests, together with authorization and technical request information. Connecting the plugin does not itself give SignatureAPI access to your full conversation history or all files in your workspace. Text or files included in a tool request are processed as described below.
| Category | Information | Purpose |
|---|---|---|
| Account and authorization | Account and user identifiers, account name, authorization tokens, permissions, connected client identifiers and name, and connection activity dates. Account lookups can include the authorized user’s email address. | Authenticate requests, select the account, enforce access, and manage connections. |
| Documents and uploads | Files you supply or reference, file names, types, sizes, checksums, upload references, and download URLs. Documents can contain personal data. | Store and prepare documents for signing, inspect their structure, and produce completed files. |
| Signature requests | Recipient names and email addresses, envelope titles, messages, document fields, template values, metadata, routing, and authentication settings, non-secret audit references, and authentication timestamps supplied with a request. | Create and manage the signing workflow you request. |
| Signing records | Signatures and initials, entered field values, recipient actions, authentication results, signing status, and audit records associated with your envelopes. | Record signing activity, show progress, and provide signed documents and audit logs. |
| Email and webhook settings | Email overrides, webhook destination URLs, labels, event filters, and related identifiers. | Send signing communications and deliver events to configured destinations. |
| Queries and diagnostics | Search terms, filters, resource identifiers, request identifiers, timestamps, source IP addresses, client and protocol headers, response status and size, and error details. | Retrieve requested information, operate the plugin, troubleshoot failures, and protect access. |
Connection records include first and most recent activity, the authorizing user, and revocation status. Technical logs can contain session identifiers supplied by the client and excerpts from error responses. These records support connection management, security, and troubleshooting.
Information returned to OpenAI
Tool results are sent to the requesting OpenAI product so it can answer your request or continue your workflow. The OpenAI plugin endpoint returns only the fields selected for each tool. Results can contain:
- Account name and available test/live modes. The connected user’s email, user ID, account ID, and connection details are not returned.
- Envelope and document identifiers, titles, labels, topics, routing, language and time settings, recipient and sender names and emails, status, activity dates, and ceremony settings. Authentication evidence, captured field values, and free-form envelope metadata are not returned.
- Upload references, file metadata, document page dimensions, detected placeholders, template field names, and processing errors.
- Signed-document and audit-log download links, ceremony links where the selected authentication method allows them, and related expiration information.
- Email sender and recipient addresses, delivery details, and signing-request or deliverable subjects and bounce details. Subjects and bounce details for other email types are omitted to prevent authentication-code disclosure. Only test-mode signing-request emails include rendered-content and ceremony links. Live email content and authentication-code content are not returned.
- Event types, timestamps, and nested correlation fields: envelope and object identifiers, recipient type and key, deliverable type and name, and included document identifiers. Arbitrary event payload fields are not returned.
- Webhook configuration and delivery attempts, including destination URLs, event identifiers, timestamps, HTTP status, and response timing. Destination response bodies are not returned.
- Documentation search results and errors describing unsuccessful requests. Raw upstream error bodies and debug payloads are not returned.
Creating a webhook returns a link to the Dashboard, where you can retrieve its signing secret and store it directly in your integration. The plugin’s webhook tools do not return signing secrets to OpenAI. Do not paste secrets into the conversation. Treat document and ceremony links as confidential.
The plugin can return information already stored in your account, including records created outside the plugin. A list request may return several matching records. Use specific identifiers and filters when you only need one record. Document content and permitted test email content can contain personal information supplied by you, recipients, or your systems. The plugin does not return document passwords. Obtain any required password directly through your organization’s approved channel.
How we use and share information
We use this information to carry out requested operations, authenticate access, maintain signing records, deliver communications, and provide support and security. Processing of customer personal data remains subject to the DPA’s purpose limitations and prohibition on selling that data.
Information can be shared with:
- OpenAI: the product making a plugin request receives its results. OpenAI’s processing, retention, and model-training practices depend on your product, agreement, and settings. See OpenAI’s Privacy Policy.
- Your organization and signing recipients: authorized account users can access platform records according to their permissions. Recipients receive signing communications and access to documents according to the workflow you configure.
- Destinations you configure: webhooks send event data to your specified endpoints. Requests to document sources, redirect destinations, and other configured services can disclose request information to those services.
- Service providers: cloud hosting, storage, databases, authentication, email delivery, webhook delivery, logging, and support providers process information to provide the service. The DPA’s subprocessor list identifies providers and their purposes.
- Authorities or other legally required recipients: information may be disclosed where required by law, subject to the DPA and applicable obligations.
Data is processed in the United States and may be processed in other countries identified in the DPA. The DPA describes the safeguards for applicable international transfers.
Retention and deletion
Customer personal data is retained for the duration of an active subscription and for 30 days afterward, as specified in the DPA. You may delete envelopes at any time; the DPA provides for erasure of associated personal data within 30 days. Its data-return and termination provisions also apply.
Temporary upload records are set to expire after 24 hours. Copies incorporated into envelopes follow envelope retention. An upload or download link expiring does not mean that every stored copy of the document has been deleted.
The plugin gateway’s access logs and plugin service’s execution logs have a 14-day retention period. This period does not describe retention of envelope audit logs, customer records in the underlying platform, or records held by OpenAI. Connection records, including revocation information, remain associated with the account to manage and enforce access; disconnecting is not a request to erase those records.
Copies already returned to OpenAI, downloaded by recipients, or delivered to webhook destinations are subject to those recipients’ retention practices. Deleting an envelope from SignatureAPI does not delete those copies.
Your controls
- Choose what to share. Supply only documents and fields needed for the task. Use synthetic data for tests.
- Control actions. Review recipients, documents, and destinations before authorizing live operations. Test mode does not send signing emails to real recipients, but still stores test data and returns tool results. Configured test webhooks can send data to their destinations.
- Disconnect access. Use Connected applications in the SignatureAPI Dashboard to disconnect a connection. You can also remove the plugin from your OpenAI product. Disconnecting does not cancel existing envelopes, stop configured webhooks, delete stored documents, or erase conversation history.
- Manage stored records. Use SignatureAPI’s supported controls to cancel or delete envelopes and disable or delete webhooks. Contact us for account-level deletion or data-return requests.
- Manage OpenAI copies. Use the privacy and data controls available in your OpenAI product for conversations, files, and other information held there.
- Exercise your rights. Contact us about access, correction, deletion, portability, restriction, or objections to processing. Where we process data for your organization, we coordinate with that organization under the DPA. We may need to verify your identity and authority to act.
Sensitive information
Do not submit payment card information, protected health information, government identifiers such as social security numbers, passwords, API keys, or one-time authentication codes through plugin inputs. This applies to documents, template values, metadata, authentication evidence, and free-text fields as well as chat messages intended for the plugin.
Complete sign-in and verification challenges through their designated interfaces. Ordinary e-signature workflows process signatures and related evidence. This plugin does not offer government-ID or biometric identity-verification challenges. Do not use it to collect biometric identifiers or other restricted sensitive personal data. Authorizing the plugin does not itself provide consent from document recipients.
Documents and existing account records can contain sensitive information. Review their suitability before uploading them or requesting them through the plugin. This notice does not mean that the plugin automatically detects or removes sensitive content.
Contact and changes
For privacy questions or requests, contact contact@signatureapi.com. Identify the account and request without sending passwords, authentication codes, or unnecessary document content.
We publish updates on this page and update the revision date when this notice changes.