Effective 2026. SIGIL is made by Hadger (IP Shmigirilov).
SIGIL has no server, no account and no analytics. The phrases you type, the marks the app draws and the images you import are processed only on your device. Nothing you write is transmitted by us, ever. What SIGIL keeps, which is your recent marks, your groups and their names, and the signature you set for your cards, lives in local storage on your iPhone or iPad.
Group keys are generated on your device and stored in the iOS Keychain. They are never sent anywhere by us and we have no copy of any of them. That has a consequence worth stating plainly: if you lose a key and have no backup, we cannot recover it and neither can anyone else. Key export and backup are free in the app at every tier, always, for exactly that reason.
A mark is an image, and you are the one who shares it. An open mark is not private: anyone with SIGIL can read it, which is exactly what makes it travel. A mark written in a group reads only for the people holding that group's key, and it carries no visible sign of which group it belongs to, or even that it is keyed at all. Treat a key the way you would treat a spare key to your flat: whoever holds it can read everything written in that group, and write in it too.
When you share, SIGIL pre-fills a caption with a link to this website so that whoever sees the mark can find the app. The caption carries nothing about your phrase, and you can delete it before you send.
App Store purchases (Apple StoreKit). Everything else, including writing a mark, saving it, importing one and reading it, works in Airplane Mode. There is no Private Cloud Compute and no cloud model. Nothing leaves the device unless you tap Share and hand an image to the system share sheet yourself.
Data Not Collected. There is no account, no identifier, and no tracking of any kind.
Writing a mark, and reading one you import from Photos or Files, needs no permission: the system picker is not gated behind an authorization dialog. Reading from the clipboard may show iOS's own Allow Paste prompt. SIGIL requests two permissions, each only at the moment it is first needed: add-only access to your photo library, when you first save a mark to Photos, and the camera, when you first choose Camera to read a mark shown on another screen or printed on paper. The camera image is read on your device and nothing leaves it. There is no microphone, location, contacts, health or notification access.
SIGIL is not a messenger. It has no inbox, no contacts, no directory and no transport of its own, so there is no message history on any server because there is no server. Sending a mark means sharing an image through an app you already use, under that app's own privacy policy.
Any mark or group can be removed in the app at any time; deleting a group deletes its key from the Keychain. Deleting the app deletes everything it stored.
hadger.support@gmail.com