Privacy policy
Last updated 6 August 2026
This is a working draft written to be complete enough for payment-processor review. Read it against how the product actually behaves and revise before launch — you are the one with the legal background here.
What we collect
- Account: your email address and shipping address.
- Record: your legal name, year of birth, sex if you provide it, state of execution, which interventions your document refuses, and the date you signed it. Your full date of birth only if you specifically choose to display it.
- Document: the file you upload.
- Contacts: the name, relationship, and mobile number of the people you nominate.
- Access records: each time your page or document is opened we record the time, IP address, approximate city and country, network operator, browser and device type, and a cryptographic fingerprint of exactly what was displayed.
What appears publicly
Your page is reachable by anyone holding your code, without a password. It shows what you chose during setup: your name, birth year or full date of birth, sex if provided, what your document refuses, the statute, your nominated contact, and a link to your signed document. Nothing else about you appears there.
Your page is marked to keep search engines out and has no directory or index. Your code cannot be guessed at any practical scale. It is not, however, secret from anyone who can see the object you are wearing.
Who we identify
We record that an access happened. We do not know who did it — there is no login for readers, and we do not require anyone to identify themselves. We do not attempt to unmask readers, and we do not sell, rent, or share access records with advertisers or data brokers.
Text messages
Each contact you nominate receives one message asking them to confirm. We send alerts only to numbers that have replied YES. Anyone can reply STOP at any time and we stop immediately, for every record their number is attached to. Message and data rates may apply.
HIPAA
We are not a HIPAA covered entity or business associate. The information you give us is not protected health information in our hands. We describe our actual practices here rather than relying on that status.
Service providers
We use Cloudflare (hosting, storage), Stripe (payments — we never see your card number), Resend (email), and Twilio (text messages). Each receives only what it needs to do its job.
Retention
We keep your record and document while your subscription is active. On cancellation, your page comes down immediately and your document is deleted within 30 days. Access records and consent records are kept for seven years, because they are the evidentiary purpose of the service.
Your rights
Write to hello@wearabledocs.com to see, correct, export, or delete what we hold. We respond within 30 days. Depending on your state you may have additional rights; we extend these to all customers regardless of residence.
Children
The service is for adults. We do not knowingly collect information from anyone under 18.