Information SiteSign Off handles
SiteSign Off can store a company name, logo, contact and address details, license and site information; customer names and contact/site addresses; job dates, categories, status, notes, materials, checklists, punch lists, before/during/after photos and captions; customer and technician signatures and timestamps; change descriptions, prices and approvals; quotes, line items, costs, markup, discounts, fees, tax settings, terms and internal notes; price-book and template data; workgroups; report preferences; and archived signed PDF bytes. It uses this information to organize work, create quotes and closeout reports, collect the approvals people choose to enter, sync selected records, and share selected jobs.
Local storage and permissions
Personal records are stored in local SwiftData and related app file storage. The iPhone/iPad version can use Camera and Photo Library access for job photos; the Mac version uses images selected through a file picker. The reviewed app does not request location, microphone, or notification access. Local storage and signatures are protected by the device, operating system, and app sandbox but are not represented as separately end-to-end encrypted. Obtain permission before photographing people or property or collecting, storing, syncing, exporting, or sharing another person's identity, contact details, work, or signature.
Optional private Job Sync
When enabled, Job Sync uploads the company profile and jobs—including customer/site fields, photos, signatures, and change orders—as ordinary CloudKit record fields and assets in the user's private database. Quotes, templates, price-book data, report defaults, and archived signed PDFs are not part of Job Sync in the reviewed version. Apple processes iCloud identity, storage, network, and account information under its terms. Turning sync off stops future syncing but does not erase CloudKit records, and deleting the app alone is not cloud deletion.
Workgroups and recipients
Workgroups use Apple CloudKit sharing. An owner selects jobs and invites participants; those participants can receive selected job, customer, photo, signature, and change-order content through the owner's private/shared databases. Owners should remove participants or stop sharing in Apple's sharing sheet when access is no longer appropriate. Participants, customers, managers, or other recipients can retain screenshots, exported reports, job packages, or other copies, and SiteSign Off cannot recall them.
Exports, backups, and restores
SiteSign Off creates customer and quote PDFs, editable .sitesignoffjob packages, and a full .sitesignoffbackup only when requested. A full backup can contain all personal business records, photos, signatures, quotes, templates, settings, and archived signed PDFs. It uses a SHA-256 checksum to detect changes and operating-system file protection at creation, but the JSON backup is not encrypted. Destinations and recipients control exported copies. A full restore replaces personal local data and does not replace or erase shared workgroup jobs in iCloud. Protect files, verify recipients, and keep an independent backup before restore or deletion.
Retention, deletion, signatures, and legal limits
Local records remain until deleted through available controls or the app and its data are removed. When Job Sync is enabled, record deletions sync while online. Turning sync off or uninstalling is not a promise that private/shared CloudKit data, exports, backups, screenshots, or recipient copies are erased. Remove sharing access first, delete relevant records online, and verify. The reviewed app has no single Clear All Cloud Data control, so unresolved cloud-deletion requests should be sent to privacy support. Signatures, timestamps, checksums, prices, statuses, and archived reports document what was entered; they do not authenticate identity, guarantee legal enforceability, prove safety/code/permit/inspection/tax compliance, or replace contracts or professional advice.
Services and security
The reviewed Swift app has no developer-operated remote processing endpoint, advertising SDK, third-party analytics, cross-app tracking, subscription, or in-app purchase. Apple provides App Store, iCloud, CloudKit, and sharing services. If a future version adds another service that receives app data, this policy and related disclosures will be updated before use. No storage, transmission, signature, backup, or security control can be guaranteed error-free or immune from loss or unauthorized access.
Website, support, rights, children, and changes
SiteSign Off's app practices above are separate from its brentgaddis.com pages, which use first-party aggregate analytics through Cloudflare without visitor/session IDs, cookies, raw or hashed IPs in analytics, full URLs/referrers, form contents, or raw click histories; coarse aggregates are retained up to 24 months. Cloudflare processes requests to deliver and protect the site. Support and privacy forms process the app selection, reason, reply email, subject, message, Turnstile security signals, and delivery metadata and send the message to support@brentgaddis.com; form contents are not written to website analytics or a website message database. Support email is kept only as reasonably needed for support, security, disputes, and legal obligations, then deleted or de-identified. The site does not use cross-site behavioral advertising or sell/share personal information for that purpose, so DNT and GPC do not change its behavior. SiteSign Off is not directed to children under 13. Applicable law may provide access, correction, deletion, or appeal rights; use the privacy form or email the public contact. Material changes will be posted here with a new effective date and additional notice or consent when required.
Questions
Contact Brent Gaddis with privacy questions about SiteSign Off.