POLICY AND TRUST

Data Privacy Policy

How identity, request files, payments, analytics, specialist records, and verification data are protected and controlled.

Effective 24 July 2026 · Version 2.0

Privacy commitments

Signal Academic minimizes identity data, keeps request material private, separates public analytics from private workspaces, and does not sell personal information. We do not publish a student's identity, request, files, institution, or contact details.

No online operator can provide absolute anonymity from itself, authorized processors, payment providers, fraud controls, or lawful authorities. Our guarantee is practical confidentiality, minimized identification, and no public disclosure except with permission or as legally required.

Information collected

  • Contact and preference data, including email, phone or WhatsApp number, locale, and timezone.
  • Request data, including subject, level, deadline, instructions, desired outcome, progress, budget, and files.
  • Transaction, workspace, message, approval, revision, quality, originality, and audit records.
  • Originality verification metadata, including a content checksum, provider scan ID, similarity score, AI alert state, and report reference.
  • Specialist identity, residence, education, assessment, credential, document, and activation records.
  • IP address, user agent, browser language, device platform, viewport and screen size, connection class, page and click activity, request-form outcome, referrer, approximate hosting-platform location, campaign attribution, rate-limit signals, and server logs.

Purposes and legal bases

Information is used to review and perform a contract, answer inquiries, prepare quotes, take payment, deliver support, verify quality, handle revisions and disputes, send a neutral post-completion review invitation, secure the service, prevent fraud, maintain records, comply with law, and improve the user journey.

Where the GDPR or UK GDPR applies, the legal basis is contract, steps requested before a contract, legitimate interests in secure and accountable operations, legal obligations, and consent where required.

Anonymity and access

Public pages never expose private request records. Operational work uses a request ID. Access is limited by role and assignment. A specialist receives only the information and files needed for the assigned scope.

Identity and qualification documents are isolated from assignment records and are never included in public audit displays.

Encryption and security

  • Production traffic uses HTTPS and TLS, and production records and files use encrypted provider storage.
  • Sessions are signed, secure, HTTP-only, and same-site restricted.
  • Private files remain quarantined until security controls or authorized manual review clear them.
  • Copyleaks submissions are sent over TLS with shared-database indexing disabled. The application retains the SHA-256 checksum and result metadata.
  • Administrative actions and quality decisions create audit events.

Processors and disclosures

Limited information may be disclosed to hosting, storage, email, WhatsApp, payment, fraud prevention, malware scanning, originality verification, customer review invitation, and professional advisers. Each receives only what is necessary.

Trustpilot receives the completed client's email, a neutral client label, request reference, locale, and scheduled send time when invitations are enabled. Copyleaks receives the verification file, filename, scan ID, and scan options. Turnitin receives comparable information only when a licensed connection is active.

Sale, sharing, and AI training

Signal Academic does not sell personal information or share it for cross-context behavioral advertising. Request files, instructions, messages, and specialist identity documents are not used to train a public artificial intelligence model.

Retention

  • Request, message, quality, originality, and payment records are normally retained for 24 months after completion or closure.
  • Private request files are normally deleted 180 days after completion, unless a dispute, legal hold, or shorter customer request applies.
  • Payment and tax records may be retained for 7 years where legally required.
  • Unsuccessful specialist identity and qualification documents are normally deleted 12 months after decision.
  • Raw click analytics and IP addresses are retained for 90 days by default.

International transfers

Providers may process information in other countries. Where transfer restrictions apply, Signal Academic uses an adequacy decision, contractual safeguards, a lawful derogation, or another valid transfer mechanism.

Your rights

Depending on location, you may request access, correction, deletion, restriction, portability, or objection, withdraw consent, and object to direct marketing. California residents may have rights to know, delete, correct, limit use of sensitive information, opt out of sale or sharing, and receive equal service.

Identity and authority may be verified before action. Information may be retained for payment, tax, fraud prevention, security, disputes, legal claims, or other lawful exceptions.

Children

The service is for people aged 18 or older. We do not knowingly collect personal information from a child and will investigate and delete it where required.

Contact

Submit a privacy request through the secure contact channel on the website. State the right you want to exercise and provide enough information to locate the record. Never include a password or private access code.