Last updated: September 2026
This policy describes what Sigil One collects, why, who handles it, and what you can ask us to do. It is written to match the product as it runs today. If the product changes, this page changes with it.
Sigil One is operated by Dylan Fratangeli, doing business as Sigil Systems. Questions about this policy or your data go to sigilonehq@gmail.com.
When you create an account we collect your email address and the credential you choose: a password, or a Google sign-in handled by Google and Supabase. Passwords are held by our authentication provider, not stored by Sigil One in readable form. If you enrol an authenticator app, we keep the enrolment needed to verify your codes. Sign-in sessions use essential cookies; we do not use advertising cookies.
Sigil One stores what you enter or confirm so the workspace can function: holdings across crypto, stocks, ETFs and funds, real estate, and metals, with quantities, cost basis, acquisition dates, entered values, custody or location notes, and the evidence behind them; annual property tax records; disposal records; modeled sale decisions with their assumptions, comparisons, notes, and outcomes; and the reports you generate.
Saved decisions are preserved as they were saved. Later changes to your records do not rewrite a saved decision; the app records what changed so you can see the difference. Earlier versions of edited records and the history of a decision are kept for that reason.
When you import a CSV, Sigil One stores the parsed rows, the source column headers, batch details such as file name and a hash of the file, parse warnings, and your review choices. The original file is temporary input and is not stored by the import workflow. This applies to asset imports and to household imports. Do not include passwords or account credentials in an import.
You may optionally add a public Bitcoin mainnet address as a read-only evidence source. The address, an optional label you choose, and the public transaction observations retrieved for it are stored with your account. To retrieve that history, the address is sent to Blockstream, a third-party provider of public blockchain data, each time you add it or choose Refresh.
Sigil One never asks for, accepts, or stores private keys, seed phrases, or exchange credentials. It cannot sign transactions, move funds, trade, or take custody of anything. Address activity is public on-chain data; it does not establish cost basis or ownership. Retrieval is limited to recent confirmed and pending transactions, and larger histories are marked partial. Bank and brokerage account connections are not available in the product.
If you create or join a household, Sigil One stores the household name, who its members are, each member's role and status, the specific permissions the owner has granted, and the history of those grants. Roles such as owner, adult member, dependent member, professional, or temporary delegate describe permissions inside the product, not a person's legal status.
Invitations are stored only as a one-way hash of the invitation token. The QR code is generated for display and is not stored. A person who scans an invitation must sign in and request membership; the request is recorded, and nothing about the household is shared with them until the owner approves a role and permissions.
Household financial records include accounts and balances, income, bills, subscriptions, other recurring obligations, budgets, one-off cash events, tax references, and references to asset holdings. Each record is marked private or shared. Private records are visible only to the person who created them. Shared records are visible only to members whose permissions cover that kind of record. Cash-flow forecasts, shortfall detection, modeled rearrangement options, and Merlin observations are calculated from those records for the person viewing them and respect the same permissions.
Household subscription requests store the original proposal, the reviewer's decision and any modification, and when it happened. Approving a request records the household's decision; it does not purchase anything or contact a merchant. Saved household decisions and the authority history are kept as records that are not edited in place.
The tax-readiness workspace derives a checklist, open items, and questions for your CPA from your tax references, household records, and linked asset facts. You may upload supporting documents (PDF, PNG, JPEG, CSV, or text, up to 10 MB each). Uploaded documents are stored in private object storage with a content hash and can be shared with household members who hold the tax-document permission. A readiness export bundles those records into a ZIP for you to hand to a preparer.
Sigil One does not file federal or state tax returns and does not transmit anything to the IRS or any tax authority. Nothing in the workspace computes your tax liability or gives tax advice.
When you look for assistance resources, you choose a country and, for the United States, an optional state for that search. That choice is used with the conditions visible in your records to match a reviewed list of official and established programs. Sigil One does not store a location profile, contact any program, submit an application, or determine eligibility. Programs decide eligibility, and their sites have their own terms and privacy practices.
Merlin observations and the specialist views are deterministic software that reads your Sigil records and applies fixed rules. No generative AI model is used, no third-party AI service receives your records, and no person reviews them. Specialist names describe a scope of records, not a licensed professional, and nothing they show is personalized professional advice.
To understand which parts of the product work, Sigil One records product events on its own servers: for example that a decision was saved, an import was completed, a household was created, or a Merlin observation was followed. Events come from a fixed catalogue whose attributes accept only predefined values, so a balance, amount, name, address, note, or document can never be inside an event. Your account and household identifiers are replaced by one-way hashes before an event is stored. Visitors who use the demo without an account are recorded as anonymous demo activity.
These events are used only for internal aggregate measurement: activation, retention, workflow completion, friction, and infrastructure planning. They are shown only to the operator in an owner-only dashboard and only as aggregates. They are not sold, shared, used for advertising, or sent to any other system. Any future use beyond internal product measurement would require a change to this policy first.
Separately, Vercel Web Analytics collects page-view and aggregate traffic statistics for the site as described in Vercel's documentation. We do not use advertising trackers.
Payments for paid reports are processed by Stripe. Sigil One receives confirmation of the payment and stores the resulting entitlement so you can download the output. We do not store your card number, bank account details, or full payment credentials. Stripe's handling of your payment information is governed by Stripe's privacy policy.
Generated reports and handoff packages (PDF, CSV, and archive files) are stored in private object storage so you can download them again under their entitlement. Their contents come from your records.
Sigil One runs on the following providers, each of which processes data only to provide the service: Supabase (authentication, database, and object storage, hosted in the United States), Vercel (hosting and site analytics), Stripe (payments), Blockstream (public Bitcoin data, only for addresses you add), and Google (only if you sign in with Google). We do not use other data processors.
We do not sell your personal or financial data, and we do not share it with third parties for their marketing. Data leaves Sigil One only when you download or export it, when you share a household record with members you have authorized, when a provider above processes it to run the service, or when the law requires disclosure.
Data is stored in cloud infrastructure with access limited to your account and, for household records, to the members you have authorized. Database rows are protected by row-level security, documents and reports are private objects verified by content hash, and you can add an authenticator app to your account. No system is perfectly secure, and you are responsible for keeping your credentials private and for the accuracy of what you enter.
Records stay for as long as your account exists, because the product is built to preserve the history behind a decision. Some records are kept as append-only history by design: saved decisions, earlier record versions, household authority and review history, uploaded documents, and product events. Temporary processing input such as an uploaded CSV file is discarded after parsing. Payment records, security logs, and anything we must keep to meet a legal obligation or resolve a dispute are retained for as long as that need lasts.
You can view and correct your records inside the product, download your paid outputs and the free household readiness export, and leave a household or change what you share. You can request a copy of your data or deletion of your account and its records by emailing sigilonehq@gmail.com. Deletion is handled by the operator, not automatically, and we will confirm what was removed. We may keep what the retention section describes, and shared household records that other members rely on may remain in the household. Product events do not contain your account identifier and are kept as pseudonymous aggregate history.
Depending on where you live, you may have additional rights under applicable privacy law, such as access, portability, correction, restriction, or the right to complain to a supervisory authority. Contact us and we will respond in line with the law that applies to you.
Sigil One accounts are for adults. The service is not directed to children under 13, and we do not knowingly collect their personal information. A household's dependent-member role is a permission setting chosen by the household owner; it does not indicate that the member is a minor.
We may update this policy when the product changes, and the date above will change with it. Questions can be directed to sigilonehq@gmail.com. See also the Terms of Service and the Refund Policy.