Deleting your data
Last updated: 2026-08-27
auth.my is a sign-in service. We hold the account you sign in with — your addresses, your sign-in methods and the record of where you used them. This page says how to have all of it deleted, and what deletion does and does not reach.
The operator of your personal data is USSV LLC, registered at 30 N Gould St Ste N, Sheridan, WY 82801 US. Questions about data: [email protected].
Delete it yourself
Sign in at auth.my, open Security and choose to delete the account. Nothing is asked in return and no reason is required.
The account stops working immediately: sessions end, tokens issued to sites are revoked, and no one can sign in with it any more. For 30 days the deletion can still be undone — that window exists for the person who pressed the button by mistake or under someone else's pressure. After it passes, the data is erased from the database, not merely hidden.
If you own an organization, it has to be transferred or deleted first. An organization without an owner leaves its members and applications with no one responsible for them.
What is erased and what stays
Erased: addresses and phone numbers, passkeys and second-factor secrets, sessions, sign-in history, avatar, notification settings, everything connected sites remembered about you here.
Kept, without you in it: the audit log. The entries stay, but they stop pointing at a person — the identifier is replaced, and nothing is left to connect the record to you. The log answers questions like "was this application approved, and by whom" long after any single account is gone, and erasing it would erase the history of decisions rather than your data.
Also kept: what the law requires us to keep, for exactly as long as it requires.
If you cannot sign in
Use the form on this page, or write to [email protected] from the address you signed in with.
We answer every request within 30 days. Before deleting anything we have to be sure the request comes from the owner of the account — otherwise the form would be a way to delete someone else's account. The reply always goes to the address in question, never to the address a request came from.
The confirmation we send says the same thing whether or not an account exists at that address. That is deliberate: a different answer would turn this page into a way to check who is registered here.
Data held by the sites you signed in to
Deleting your auth.my account removes your data from us and takes away the sites' access to it. It does not reach what a site stored on its own side — its orders, messages or profile pages are its own, and we cannot see or delete them.
Ask that site directly. You can see the list of sites you signed in to in your account under Sites, and revoke access there without deleting anything.
Requests through a sign-in provider
If you signed in through Facebook or another provider, you can ask them to have your data deleted here. Such a request removes the link to that provider and the data we received from it; it does not delete the rest of your account, because your account usually holds more than one way to sign in and deleting all of it was not what was asked for. To delete the account entirely, use one of the ways above.
If you can sign in, delete the account yourself, right away, in the danger zone. Open the danger zone
The answer sounds the same whether or not there is an account for the address. Otherwise this form would be a way to check who is registered here.
For example, that you no longer have access to that mailbox. It helps us work out how to verify you.
We answer within 30 days, to the address you gave.