Legal

Privacy Policy

The short version: your app data lives on your device. AI requests are processed on your device using Apple Foundation Models, and SignPrep operates no AI servers and cannot remotely access your requests or results. SignPrep 1.6 and later add one optional feature that contacts a SignPrep address: SgSL Sign Bank Sync, which downloads Singapore Sign Language signs into your glossary. It is off until you turn it on, and it sends no personal or assignment information.

Effective date: 17 September 2026

← Back to home

Introduction

SignPrep (“the app”) is developed by Daniel Yong. This privacy policy explains how the app handles your information. Your app data is stored locally on your device. SignPrep does not operate an account system, an advertising platform, or an AI server, and the developer cannot remotely access your app data, AI requests, or AI results. One optional feature, SgSL Sign Bank Sync, downloads glossary content from signprep.app. It is described in its own section below, and everything else in this policy applies whether or not you use it.

Data collection

SignPrep does not collect or store your personal data on servers operated by SignPrep. The app itself contains no analytics, advertising, crash reporting, or third-party tracking SDKs. Information can leave your device only for a feature you choose to use: a reviewed web search, an export or share action, directions, the optional SgSL Sign Bank Sync described below, or your own device backup.

On-device data

All data you create within SignPrep is stored locally on your device using Apple's standard on-device storage frameworks. This includes:

  • Calendar assignments imported via EventKit, including any Calendar Notes you choose to import
  • Preparation content — checklists, notes, research findings, key terms, resources, and the context you provide for AI features
  • Glossary entries (videos, labels, descriptions, and notes)
  • DC-S reflection logs
  • Mood and self-care check-in records
  • CPD/CEU records
  • The local Security Activity Log
  • App settings and preferences

This locally stored app data is not remotely accessible to the developer. Deleting the app removes the copy stored within the app from that device; copies you previously exported or included in a device backup remain under your control.

iCloud and device backups

SignPrep stores its data locally on your device. If you have iCloud Backup, or a Finder/iTunes backup, enabled, that local data may be included in your own encrypted device backup — the same as for any other app on your device. This backup is created and controlled entirely by you through Apple, stays within your Apple account, and SignPrep does not operate the backup service or have access to it.

If you handle sensitive assignment details and prefer to keep them out of any backup, the most reliable approach is to keep patient or client identifiers out of the app and your calendar in the first place — SignPrep is designed to work from the job type, not from personal details. SignPrep also includes an opt-in setting, Exclude Data from iCloud Backups (off by default), that attempts to exclude supported app data — the assignment data store, AI-output cache and recovery copies, and known glossary media — from iCloud and Finder/iTunes backups. Note the trade-off: data excluded from backups will not be restored to a new device from that backup. If a file cannot be marked successfully, the app shows Backup Exclusion Incomplete and retries on a later launch.

App Lock and Security Activity Log

SignPrep offers an optional App Lock, separate from your device passcode, that uses a SignPrep-owned four-digit PIN with Face ID or Touch ID unlock on supported hardware. Biometric authentication is handled entirely by Apple’s on-device system — your face or fingerprint data is never seen by, shared with, or stored by SignPrep. Your PIN is stored only on your device. When App Lock is enabled, the app also hides its contents in the app switcher, and repeated incorrect PIN attempts trigger a local cooldown.

The optional Security Activity Log keeps a lightweight, on-device record of app opens, locks, successful and failed unlock attempts, and non-sensitive security-setting changes. It contains no assignment content, is never transmitted to SignPrep, and Clear Log permanently removes it from your device.

Calendar access

SignPrep requests read-only access to your device calendars through Apple EventKit in order to display upcoming interpreting assignments. Calendar import and storage happen locally, and SignPrep does not upload calendar data to a SignPrep-operated server. If you permit Calendar Notes to be used for AI preparation, selected information may be included in an Apple Intelligence request as described below. You can revoke calendar access at any time in your device's Settings › Privacy & Security › Calendars.

Calendar Notes

SignPrep can optionally import the notes attached to your calendar events as read-only context for assignment preparation. This is off by default: you enable it with Use Calendar Notes for Preparation in Settings, and existing assignments are never silently opted in. Each calendar-imported assignment can inherit the global setting or explicitly include or exclude its notes from AI context. Imported notes are shown separately from your own notes, are never edited back to your calendar, and never appear in widgets, notifications, Live Activities, Apple Watch surfaces, Spotlight, Siri, exports, logs, or analytics. When you permit it, Calendar Notes may be included in an Apple Intelligence request processed on your device. SignPrep cannot remotely access the request or result.

Camera, microphone, and location access

The app requests camera access solely to record sign language videos for your personal glossary. The videos you record are stored locally on your device and are never uploaded or shared with any server. SignPrep does not request microphone access.

SignPrep does not request location access on iPhone or iPad, and does not determine your device’s location. When you tap for directions, the assignment address is handed to your maps app as a link, and that app takes over from there.

Notifications

SignPrep may request permission to send local notifications to remind you about upcoming assignments. Notifications are generated and scheduled entirely on your device. No push notification servers are used.

Apple Foundation Models

SignPrep uses Apple Foundation Models for AI-powered features such as Briefings, preparation suggestions, glossary word suggestions, and self-care recommendations. Requests are processed on your device.

AI preparation may use selected assignment information — the assignment title, domain, location, assignment notes, context you add, and Calendar Notes when you permit them. Only information selected for the AI feature is included in its request. Apple states that Apple Intelligence is designed so no one else can access your data, not even Apple. SignPrep operates no AI servers and cannot remotely access your requests or results.

Learn more from Apple at Apple Privacy. You can review what your current SignPrep choices allow at any time with Privacy Preview in the app.

Reviewed web search

Preparation includes an optional reviewed web search. SignPrep builds a more general query on your device, checks it for likely identifying details, and shows it to you — you review, edit, and approve the query before anything is searched. A query that still appears to contain protected information is blocked. Only when you approve a query is it opened as a web search, which is handled by your search provider under its own terms. Automated checks help remove likely identifiers, but no automated check can recognise every possible identifying phrase — always review the query before searching.

Optional SgSL Sign Bank Sync

SignPrep 1.6 and later include an optional feature called SgSL Sign Bank Sync. It downloads Singapore Sign Language signs from the SgSL Sign Bank and adds them to the glossary on your device. It is the only part of SignPrep that contacts an address operated for SignPrep, and it is the only part of this policy where Cloudflare, GitHub, or Google Analytics are involved.

Who it is for, and how to turn it off

The feature is offered only if your default sign language in SignPrep is SgSL (Singapore Sign Language). It is off until you turn it on. SignPrep asks you once, in the Glossary tab, and you can turn it on or off at any time in Settings, under Glossary, as SgSL Sign Bank Sync.

Turning it off stops every check and every download this feature makes, so SignPrep stops contacting signprep.app until you turn it back on. Signs that have already been added stay in your glossary until you remove them, for example with Reset Glossary.

What it does

When the feature is on, SignPrep checks signprep.app for SgSL Sign Bank glossary packs, then downloads them and adds them to your glossary through the same preview and import that SignPrep already uses for glossary files. You see a preview once per release before anything is added.

New content is published on the 1st and 15th of each month. SignPrep checks quietly when you open the app, at most once a day and only after a publish date has passed. It may also check in the background if iOS allows it, which is not guaranteed, so opening the app is the reliable way to get new content. There is also a Check for Updates button.

The full sign bank is about 1.4 GB, in six parts, downloaded one part at a time. Downloads use Wi-Fi only unless you allow mobile data, and they pause in Low Power Mode. Before a part is added, SignPrep checks it against the size and SHA-256 digest published for that part. A part that does not match is deleted, and nothing from it is added. Downloaded sign bank media is excluded from device backups, because it can be downloaded again.

What your device sends, and what it does not

Requests go to signprep.app over HTTPS. Each request carries a fixed access code that is the same in every copy of SignPrep. It identifies the app, not you and not your device. SignPrep sets its User-Agent to “SignPrep” and its language header to “en”, so it does not send your device model, your iOS build, or your language preferences.

SignPrep sends no account, because there are no accounts. It sends no name, no email address, no glossary content, no assignments, no reflections, no notes, and no CPD records, and it sends no identifier that SignPrep has created. Nothing about your assignments, clients, reflections, or notes is ever sent. This feature is unrelated to SignPrep’s AI features, which are covered above.

As with any download, the servers that handle the request can see your device’s IP address.

The services involved, and what each one keeps

The pack files are not served by signprep.app itself. signprep.app returns a short-lived link, and your device then downloads the file directly from GitHub’s file servers, where the packs are stored as release assets.

  • signprep.app, hosted on Cloudflare Pages. The code that answers these requests does not write a request log and does not read or record IP addresses. It does send the analytics events described below.
  • Cloudflare, as the hosting provider. Cloudflare carries out short-lived operational logging as a service provider. Cloudflare does not retain raw request logs unless log retention is explicitly enabled, and it is not enabled.
  • GitHub, which delivers the pack files. GitHub keeps IP addresses in its service logs for security and operations, under its own privacy statement.
  • Google Analytics (GA4), used to count pack downloads. The event is sent by signprep.app from the server, not by your device, so your IP address is not sent to Google. Two events are used. sgsl_pack_download is sent when a pack file is requested, and carries a client_type value that says whether the request came from the app or from a web browser, and an asset_name value, the file name of the pack. sgsl_auth_denied is sent when a request is refused because its access code is not recognised, and carries only the type of route that was asked for: the pack list, a download, or the page. It carries no file name. Every event carries a new random identifier created for that one event, so events cannot be linked to each other or to you.

SignPrep’s checks for new content are not sent to Google Analytics. Only an actual download is counted. None of this is linked to a person, and none of it is used for tracking or advertising. It tells the developer how often packs are downloaded, and nothing more.

Third-party services

The app integrates no advertising or tracking services, sets no cookies on your device, and uses no tracking technologies. Information can leave the app only to perform a feature you choose to use. This includes a query you approve for reviewed web search, directions opened in a maps provider, an exported file you share, a backup controlled through your Apple account, or the optional SgSL Sign Bank Sync. That one feature involves Cloudflare, GitHub, and Google Analytics, as set out above. Each external service handles the information it receives under its own privacy terms. This website is separate from the app and is covered under This website below.

What SignPrep receives

SignPrep does not sell, monetise, or receive a copy of your assignment data, AI requests, AI results, reviewed search queries, exports, or backups. The developer has no remote dashboard or backend through which to view any of it. The one thing the developer can see is the pack activity described under Optional SgSL Sign Bank Sync, which counts downloads and is not linked to a person. Information sent to a service you choose is sent directly from your device for that feature and is not routed through SignPrep-operated servers.

This website

Everything above is about the SignPrep app. The signprep.app website is separate, and it is measured differently. The site uses Cloudflare Web Analytics. It sets no cookies and uses no local storage to measure anything, so no analytics cookie is set when you read these pages.

What Cloudflare Web Analytics measures

It records page views, visits (a page view that arrives from another site or from a direct link), how long the page took to load together with a breakdown of that timing, and the Core Web Vitals measurements: Largest Contentful Paint, Interaction to Next Paint, and Cumulative Layout Shift. For those it also records which element on the page affected the score, and the path of the page. See Cloudflare’s high-level metrics documentation.

It groups what it records by country, host, page path, referring site, device type (desktop, mobile, or tablet), browser, operating system, and navigation type, such as a reload or a back or forward step. Bot traffic can be excluded. See Cloudflare’s dimensions documentation.

Cloudflare states that it uses no client-side state such as cookies or local storage to collect these metrics, that it does not fingerprint individuals, that it does not track visitors across the sites that use it, and that it does not collect or use visitors’ personal data. See About Web Analytics. The measuring script is loaded from static.cloudflareinsights.com, and what it measures is sent to this site’s own /cdn-cgi/rum address.

Cloudflare keeps the unsampled figures for 7 days, then aggregates them to about 10 per cent of the original volume for longer-term storage. See Cloudflare’s Web Analytics FAQ.

Other things these pages load

The fonts used on every page are served by api.fontshare.com, which receives your IP address as part of delivering them. The App Store badge image on the home page is served by toolbox.marketingtools.apple.com, which receives your IP address in the same way. Neither sets a cookie.

What this site stores in your browser

One thing, and it is not analytics: if you use the light and dark toggle, your choice is kept in your browser’s local storage so the site opens the way you left it. It never leaves your browser, and clearing your browsing data removes it.

The hidden glossary download page, at a separate address, sets one cookie, and only after you sign in to it with its password. It records nothing but the fact that the password was correct, it is the same value for everyone who signs in, and it is strictly necessary for that page to work. It is not set when you read this site.

The app, and the pack download count

Separately, and unrelated to how these pages are measured, signprep.app sends Google Analytics an event when an SgSL Sign Bank pack is downloaded. That event is sent by the server rather than by your device, uses a new random identifier each time, sets no cookie, and does not carry your IP address. It is described in full under Optional SgSL Sign Bank Sync above.

The SignPrep app does not load these pages and does not contain any analytics script. Using the app sends nothing to Cloudflare Web Analytics.

Children's privacy

SignPrep is not directed at children under the age of 13. The app does not knowingly collect information from children.

Changes to this policy

If this privacy policy is updated, the revised version will be posted at this URL with an updated effective date.

Contact

If you have questions about this privacy policy, please contact support@signprep.app.