Privacy Policy

Effective date:

This Privacy Policy explains how the administrator of this Easy Auth instance (the “Operator”) collects, uses, discloses, and protects information when you use this authentication service (the “Service”). Easy Auth is development-stage software. The Operator is responsible for this deployment and its data practices.

1. Information we collect

Depending on the features you use, the Service may collect:

  • Account information: your name, login email, email-verification status, optional profile image, account role, and account status.
  • Authentication information: protected password credentials, linked identity-provider identifiers and tokens, passkey public-key credentials and device metadata, two-factor authentication records, backup codes, and verification records. The Service does not receive the biometric data or device PIN used to unlock a passkey.
  • Session and security information: session identifiers, IP address, browser or device user-agent information, timestamps, rate-limit and anti-abuse records, and records of security actions such as session revocation or account suspension.
  • Authorization information: trusted applications you authorize, approved scopes, OAuth or OpenID Connect tokens and grants, and related request metadata.
  • Administrative information: trusted-application registrations, configuration, contacts, redirect addresses, and management activity if you administer the identity domain.
  • Communications: information needed to send and manage account verification and password-reset messages.

2. How we use information

We use information to:

  • create, verify, maintain, and secure accounts and sessions;
  • authenticate you and provide password, passkey, and two-factor features;
  • process OAuth 2.1 and OpenID Connect authorization requests;
  • share approved identity claims with trusted applications at your direction;
  • send transactional authentication messages;
  • prevent abuse, enforce rate limits, investigate incidents, and audit security actions;
  • operate, troubleshoot, and improve the Service; and
  • comply with applicable law and protect the Service, its Operator, and other people.

3. Cookies and local storage

The Service uses cookies and browser storage that are necessary for authentication, security, and preferences. These may keep you signed in, temporarily store authentication challenges, remember your last sign-in method, preserve interface state, and save your color-theme preference. Blocking this storage may prevent parts of the Service from working.

4. How information is disclosed

Information may be disclosed:

  • To trusted applications: when you approve an authorization request, the Service provides the application with the identity claims covered by the scopes shown on the consent screen. You can review and revoke application authorizations from your account panel.
  • To service providers: infrastructure and email-delivery providers may process information to host and protect the Service and deliver authentication messages. This deployment uses Cloudflare infrastructure and Turnstile anti-abuse checks, and may use Resend for email delivery.
  • To external identity providers: if you choose Google or GitHub sign-in, that provider receives and processes information under its own terms and privacy policy.
  • For legal and safety reasons: when reasonably necessary to comply with law, respond to valid legal process, investigate abuse, or protect rights and safety.
  • As part of an organizational change: in connection with a merger, financing, reorganization, or transfer of the Service, subject to appropriate safeguards.

The Operator does not sell personal information through the Service.

5. Retention

Information is retained for as long as needed to provide and secure the Service, satisfy legal obligations, resolve disputes, and enforce agreements. Sessions, verification records, and authorization tokens have defined expiration or revocation states. Account, consent, and security records may remain while an account or this deployment is active; audit records may be kept longer to preserve security and administrative history. The Operator may retain limited backups or records when required by law or legitimate security needs.

6. Security

The Service uses technical and organizational safeguards designed to protect information, including restricted administrative access and protected storage for sensitive authentication material. No system is completely secure, and the Operator cannot guarantee that unauthorized access, loss, or misuse will never occur.

7. Your choices and rights

The account panel lets you update available profile information, manage sign-in methods and sessions, and review or revoke trusted-application authorizations. You may also ask the Operator to provide access to, correct, export, or delete personal information, or to restrict or object to certain processing. Available rights depend on applicable law, and some information may be retained for security or legal reasons.

8. International processing

The Operator and its service providers may process information in countries other than the one where you live. Data-protection laws may differ in those countries. Where required, the Operator is responsible for using an appropriate transfer mechanism.

9. Children’s privacy

The Service is not directed to children who cannot legally consent to use an online service in their location. If you believe a child has provided personal information without valid authorization, contact the Operator.

10. Changes to this policy

This policy may be updated as the Service or its data practices change. The revised version will be posted here with a new effective date. Where required, the Operator will provide additional notice or request consent.

11. Contact

For privacy questions or requests, contact the administrator of the Easy Auth instance you use. Because Easy Auth is self-hosted, the administrator of that deployment—not the software project in the abstract—controls the account information processed by the Service.