IDENTITY ACCESS
Terms of servicePrivacyData Processing AddendumSubprocessors
This revision is no longer in force
It is kept so that you can see what you agreed to at the time. Read the current one

Privacy Policy

Revision of 2026-08-24

auth.my is an authentication service. Our job is to confirm that you are you and to tell the site you are signing in to. We try to collect the minimum of data needed for that job.

Who processes the data

The controller of your personal data is USSV LLC, registered at 30 N Gould St Ste N, Sheridan, WY 82801 US. Write to [email protected] with any question about your data.

What data we collect

What you tell us yourself

  • Email address — the main identifier of the account and the channel for one-time codes.
  • Display name — optional, used only inside your own console.
  • Passkeys — the public part of the key and its name. The private part never leaves your device and is not available to us.
  • Linked Google and Microsoft accounts — the account identifier at the provider and the email address from its profile.

What arises from use

  • Sessions — the kind of device and browser, the IP address, the time of last activity. Needed so that you can see where a sign-in happened and end a session that is not yours.
  • Event log — sign-ins, codes sent, passkeys linked, settings changed, administrator actions. Needed to investigate incidents and so that you can see what has happened to your account.
  • Connected sites — which site, when it first appeared, how many sign-ins, and what data you allowed it to receive.

What we do not do

  • We do not show advertising and do not pass data to advertising networks.
  • We do not sell personal data.
  • We do not track you across the sites you sign in to.
  • We tell connected sites nothing beyond what you explicitly allowed on the consent screen.

Why we process it

The grounds are the performance of our contract with you (providing the sign-in service) and our legitimate interest in security: detecting code guessing, abuse and compromised accounts. One-time codes are sent to your mail because without them there is no way to sign in.

How we protect the data

  • Email addresses and phone numbers are stored encrypted. They are searched through a "blind index" — an irreversible fingerprint, not the value itself.
  • One-time codes and backup codes are stored only as hashes. Not even we can recover them from the database.
  • The connection is protected by TLS, and the server's service ports are not exposed.
  • Administrator access to other people's data is written to the log, viewing included.

Whom we pass data to

We use contractors without whom the service does not work:

  • Brevo — delivery of messages with one-time codes. Receives the recipient's address and the text of the message.
  • Cloudflare — protection and delivery of traffic. Processes the IP address and request metadata.

If you sign in through Google or Microsoft, those companies learn about the fact of a sign-in to auth.my — that is how any sign-in through an external provider works. Their processing of data is governed by their own policies.

We will disclose data on a lawful demand from an authorised body, but only to the extent that the demand actually covers.

How long we keep it

  • Account data — for as long as the account exists.
  • Sessions — until they expire or until you sign out, after which they are marked revoked.
  • One-time codes — minutes; spent ones are deleted within a day.
  • Event log — kept even after the related data is deleted, to the extent needed for security.
  • Deleted accounts — 30 days, while the deletion can still be undone; after that everything about you is erased and the address becomes free again.
  • Database backups — 14 days, then overwritten.

Your rights

You can:

  • look at your data in the console: addresses, devices, sessions, connected sites;
  • withdraw access from any connected site;
  • end any active session;
  • delete your account;
  • download a copy of all your data from the Security screen;
  • ask for a correction — write to [email protected].
Note

What deletion actually does. Sign-in stops the moment you delete the account. For 30 days the deletion can still be undone — that is the only reason the data is still there. After that everything about you is erased: addresses, phone numbers, keys, the authenticator app, linked accounts, devices and the history of connected sites. What stays is the event log without the address, the device or the city — we keep it for security — and database backups, which are overwritten within 14 days.

Cookies

We use only technically necessary cookies: they keep your session and protect the sign-in form against request forgery. There are no analytics or advertising cookies, which is why we show no consent banner — there is nothing to consent to.

Children

The service is not intended for children under 16. If you learn that a child has created an account, tell us and we will delete it.

Changes to this policy

For material changes we will give notice to the address attached to your account at least 14 days in advance. The date of the last update is shown at the top of the page.

Contacts

[email protected] — questions about personal data [email protected] — vulnerability reports

auth.my — sign-in for sites and applications. [email protected]