Pocket Office Signature Pro — Privacy Policy
Last updated: 11 September 2026
By default, Pocket Office Signature Pro sends no data anywhere. Everything you
scan, sign, convert or write is processed and stored only on your device. The
developer operates no server, no account system, no analytics and no advertising, and
never receives your documents, your signatures, your notes or any personal data.
A small number of features can send data off the device, and each one is described in
full below: the AI assistant (a third-party AI service), the signature timestamp, an
optional cloud qualified certificate, and optional Microsoft OneDrive access. The AI
assistant, the cloud certificate and OneDrive do nothing at all until you set them up
yourself; the timestamp applies only when you seal a PDF and can be switched off in the
signature settings.
Summary of all data leaving the device
| Data | When it is collected / sent | Who receives it | All uses |
| Nothing at all — scanning, OCR, signature drawing, PDF build,
compression, merging, protection, PDF ↔ Word conversion, QR codes,
business-card recognition, receipt parsing, notes, clipboard and folders |
Always — this is the default state of the app |
No one. Data stays in the app's private sandbox on your device |
Producing the result you asked for, on the device |
| The specific text you select: the OCR text of a document, the text of a note, or
what you type into the assistant |
Only if you paste your own Anthropic API key in Settings and grant explicit
in-app consent. Off until you do both |
Anthropic PBC — api.anthropic.com, United States. Sent directly from your device
over HTTPS, with no intermediary server |
Producing the AI answer shown back to you. Nothing else |
| A SHA-256 hash of the signature value. Not the document, not its text |
When you seal a PDF with timestamping enabled |
APED, qualified EU timestamp authority, Greece —
timestamp.aped.gov.gr/qtss |
Returning a signed RFC 3161 token that proves when the signature was made |
| A SHA-256 hash to be signed, plus OAuth2 authentication with your provider |
Only if you connect a qualified certificate held at an EU trust service provider.
Off until you connect one |
The provider you chose: certSIGN, DigiSign, Trans Sped, InfoCert or Namirial |
Creating the qualified signature value for your document |
| The files you choose to open or save, plus your Microsoft sign-in tokens |
Only if you sign in with your own Microsoft account. Off until you sign in |
Microsoft, through Microsoft Graph / your own OneDrive |
Reading and writing files in your own OneDrive, at your request |
| Purchase transaction |
If you buy the app |
Apple, through your App Store account |
Processing the one-time purchase. The developer receives no payment details |
1. Default behaviour: everything happens on your device
- What data
- Your documents, scans, photos, OCR text, signatures, PDFs, converted files, QR
codes, business cards, receipts, notes, clipboard history and folders.
- How it is collected
- Only from what you create or import yourself in the app — the camera, your photo
library, or files you open. Nothing is gathered in the background.
- Who receives it
- No one. All of this is processed locally on your iPhone or iPad using Apple's
on-device frameworks (Vision for text recognition) and stored in the app's private
sandbox, where it is included in your own device backups.
- All uses
- Producing the result you asked for on the device. There are no accounts, no
sign-in, no user profiles, no analytics, no tracking, no advertising identifiers and no
developer-operated backend. Nothing is sold, shared or used for profiling.
2. Optional AI assistant — third-party AI service (Anthropic)
This feature is off unless you turn it on. It requires two separate
actions from you: pasting your own Anthropic API key in Settings, and granting an
explicit in-app consent.
- What data
- Only the specific text you select for the AI: the OCR text of a document you choose,
the text of a note you choose, or what you type into the assistant. No other file, no
metadata, no identifier about you or your device is added.
- How it is collected
- From your explicit selection in the app, at the moment you ask the AI to act.
- Who receives it
- Anthropic PBC, at api.anthropic.com in the United States. The request goes directly
from your device over HTTPS and is authenticated with your own API key. There is no
intermediary server and the developer never sees the request or the response. Anthropic
handles the data under
Anthropic's privacy policy.
- All uses
- Producing the answer that is displayed back to you in the app. The app makes no
other use of that text and stores no copy of it outside your device.
- Your key and your control
- Your API key is stored in the iOS Keychain on your device only, and is never
transmitted anywhere except to Anthropic as authentication for your own requests. You
can withdraw consent at any time in Settings, which stops all further requests, and you
can delete the key. If you never add a key and never consent, no AI request is ever
made.
3. Digital signature timestamp
- What data
- Only a SHA-256 hash of the signature value. The document itself, its text, its
images and its file name are never sent. A hash is a one-way fingerprint and cannot be
reversed back into the document.
- How it is collected
- Calculated on your device at the moment you seal a PDF, if timestamping is enabled
in the signature settings. You can turn timestamping off, in which case nothing is
sent.
- Who receives it
- APED, a qualified EU timestamp authority in Greece, at
https://timestamp.aped.gov.gr/qtss.
- All uses
- The authority returns a signed RFC 3161 token proving the moment at which the
signature was made. The token is embedded in your PDF. That is the only use.
4. Optional cloud qualified certificate (CSC standard)
This feature is off unless you connect a qualified certificate
yourself.
- What data
- Only the SHA-256 hash to be signed, together with the OAuth2 authentication exchange
with your provider. The document never leaves your device.
- How it is collected
- The hash is computed on your device when you sign; the authentication data comes
from the sign-in you perform with your provider.
- Who receives it
- The EU trust service provider that holds your qualified certificate and that you
chose to connect: certSIGN, DigiSign, Trans Sped, InfoCert or Namirial. Each of them
handles that data under its own privacy policy and under EU eIDAS rules.
- All uses
- Producing the qualified signature value that is then embedded in your PDF on the
device. Access tokens are kept in the iOS Keychain on your device; you can disconnect
the provider at any time.
5. Optional Microsoft account and OneDrive
This feature is off unless you sign in yourself.
- What data
- Your Microsoft sign-in credentials are entered in Microsoft's own sign-in interface
(MSAL) and are never seen by the app or the developer. After sign-in, the files you
choose to open or save are exchanged with your own OneDrive.
- How it is collected
- Only through your explicit sign-in and your explicit choice of a file to read or
write.
- Who receives it
- Microsoft, through the Microsoft Graph API, in the OneDrive account belonging to
you. The developer never sees your account, your tokens or your files. Microsoft handles
the data under the
Microsoft Privacy
Statement.
- All uses
- Reading and writing files in your own OneDrive at your request. Access tokens are
stored on your device in the iOS Keychain; signing out removes them and stops all
further access.
6. Purchases
The app is a one-time purchase handled entirely by Apple through your App Store
account. The developer receives no payment details, no card data and no billing address.
There is no subscription in this app.
7. Device permissions
- Camera — only to scan documents, business cards and QR codes.
- Photos — only when you choose to import images or save exports.
- Contacts — only when you choose to save a scanned business card.
- Face ID — optional app lock. The biometric check is performed by
iOS; the app receives only a success or failure result and no biometric data.
Each permission is requested only when you first use the feature and can be revoked at
any time in iOS Settings.
8. Retention and deletion
Your files and notes stay in the app's sandbox on your device until you delete them;
deleting the app removes them with it. Your Anthropic API key and any provider or
Microsoft tokens stay in the iOS Keychain until you remove them in the app or delete the
app. Because the developer holds no copy of anything, there is no server-side data to
request or erase.
9. Children
The app does not knowingly collect any information from anyone, including children. It
is rated 4+.
10. Changes
If this policy ever changes, the new version will be published at this address and the
"Last updated" date will change.
11. Contact
IPSTSO · office@ipstso.org ·
ipstso.org