Privacy Policy
Model Agreement — Last updated: July 14, 2026
1. Information We Collect
Model Agreement collects the following information that you voluntarily provide or generate through the app:
- Profile Information: Name, email, phone number, social media handle, and base location
- Agreement, NDA, and Event Data: Session details, rates, terms, jurisdiction selections, client/counterparty information, and signatures
- 2257 Records: Compliance records are stored locally in the app's encrypted database and are not sent to our servers
- Contract Scans: Photos and text you submit for contract scanning are processed locally on your device using on-device OCR. Contract text is not stored on our servers.
- Signing Verification Data: When a party signs an agreement via a web signing link, we record the timestamp, IP address, approximate location (city/region/country), browser/device information, document hash when available, and electronic-signature consent version. This data is collected to verify the authenticity of electronic signatures and is not displayed to either party.
- Android Beta Signup Data: If you join the Android beta test from our website, we collect the email address connected to your Google Play Store account, signup timestamp, and hashed request metadata used for abuse prevention.
2. How We Use Your Information
- To generate booking agreements and PDFs
- To create web signing links for your clients and NDA counterparties
- To store your data securely on your device
- To display agreement status and booking history
- To support optional sign-in, push notifications, subscriptions, crash reporting, App Check, and non-PII product analytics
- To manage Android beta tester access and send beta download instructions
3. Data Storage
On Your Device
Core app data is stored locally on your device. 2257 performer records are stored locally in an encrypted database and are not sent to our servers.
Web Signing Links
When you generate a web signing link, the agreement or NDA terms and signatures needed for that signing flow are stored on Cloudflare's infrastructure. Unsigned links expire after 30 days. Signed records are retained for 7 years for signature verification and record retention. Signing link data includes terms, session details, rates when applicable, signatures, and signing verification metadata.
4. Data Sharing
We do not sell, rent, or share your personal information with third parties. Your data is only shared in these ways:
- With your clients: When you send an agreement or signing link, the recipient sees only the terms you've included
- Firebase: Optional auth, push notifications, crash reporting, App Check, and non-PII product analytics are processed through Google Firebase
- Cloudflare: Web signing pages are hosted on Cloudflare Workers
- Google Play: Android beta tester access requires the email address connected to your Google Play Store account
5. Third-Party Services
- Google Firebase: For optional auth, push notifications, crash reporting, App Check, and non-PII product analytics — governed by Google's privacy policy
- Cloudflare Workers & KV: For hosting web signing pages — governed by Cloudflare's privacy policy
- Google ML Kit: For OCR text recognition in contract scanning — all processing happens on-device
- Google Play: For Android beta tester opt-in and app distribution
6. Data Retention
- Device data: Stored until you delete it or delete the app
- Push notification tokens: Stored on our server only while an active signing link exists
- Unsigned signing links: Expire after 30 days if not signed
- Signed agreements and NDAs: Retained for 7 years for signature verification and record retention, including signing verification data. Both parties should save their own copies for personal records.
- Android beta signup data: Retained for up to 180 days unless a longer period is needed to manage tester access, prevent abuse, or respond to support requests.
7. Your Rights
You can:
- Delete your profile and all data from within the app
- Delete individual agreements and client records
- Revoke unsigned signing links from the app, which deletes the associated unsigned link data from our server
- Signed agreements and NDAs are retained for 7 years for signature verification and record retention and cannot be deleted early by either party individually, as both parties have an interest in the signed record
8. Security
Your data is stored locally on your device and protected by the platform's built-in encryption. Web signing links use HTTPS encryption.
9. Children's Privacy
Model Agreement is not intended for use by anyone under the age of 18. We do not knowingly collect information from minors.
10. Changes to This Policy
We may update this privacy policy from time to time. Changes will be reflected in the "Last updated" date above.
11. Contact
For privacy-related questions or data deletion requests, contact us at: privacy@modelagreement.com
Model Agreement • Protect Your Terms