Privacy Policy
Last updated: 2026-09-07 · previous revision of 2026-08-24
This Privacy Policy explains how auth.my processes personal data.
1. Who we are
auth.my is operated by USSV LLC, registered at 30 N Gould St Ste N, Sheridan, WY 82801 US.
For the core auth.my identity service, account security, fraud prevention, billing, and operation of the platform, USSV LLC generally acts as the controller of personal data.
For certain enterprise or organization-specific processing performed solely on documented instructions from an organization, USSV LLC may act as a processor. That processing is governed by our Data Processing Addendum where applicable.
Privacy contact: [email protected]
2. Scope
This Policy applies to auth.my accounts, authentication and identity services, the auth.my console, organizations and applications registered with auth.my, developer services, security and administrative functions, and public auth.my websites where personal data is collected.
A third-party application you sign in to through auth.my has its own privacy practices.
3. Personal data we process
Identity and contact information
We may process email addresses, verified phone numbers, display name, profile image or avatar, language and account preferences, and account identifiers.
Authentication information
Depending on the methods you configure, we may process public passkey credentials and metadata, encrypted authenticator-app secrets, hashes of backup codes, trusted-device information, authentication method information, identifiers returned by external identity providers, and information needed to recover or protect an account.
Private passkey keys remain on your authenticator and are not provided to auth.my.
External identity providers
If you choose federated sign-in, we may receive identifiers and profile information from providers such as Google, Microsoft Entra, Apple, GitHub, Facebook, LinkedIn, or another provider displayed by the Service.
Available providers may change. We only receive information permitted by that provider and the permissions used for the sign-in.
Sessions, devices, and location
We may process IP address, browser and device type, session identifiers, time of sign-in and activity, authentication method, country derived from network information, and city or region where available.
Location information is approximate and is used for account security, session history, fraud detection, and incident investigation.
Connected Applications
We process information about applications you have signed in to, permissions or scopes requested and granted, consent decisions, sign-in activity, tokens and authorization records, and whether access was blocked or withdrawn.
Because auth.my is the identity provider, it necessarily knows which applications request authentication through auth.my.
We do not use that cross-application information to build advertising profiles or sell audiences.
Organizations
If you create, own, join, or are invited to an organization, we may process organization membership, role and permissions, invitations and join requests, verified organization domains, administrative actions, application ownership, usage records, and information necessary to calculate organization billing.
Where necessary to verify usage or resolve billing disputes, organization administrators may be able to see which members or users contributed to organization usage.
Application and developer information
For application owners we may process application and environment configuration, redirect addresses, verified domains, branding, requested permissions, moderation records, application credentials in protected form, usage statistics, and administrator activity.
Communications
We may process records relating to email or SMS delivery, including destination address or phone number, message type, delivery provider, delivery status, timestamps, and bounce, blocked, or failure information.
We do not use email-open tracking or advertising pixels.
Billing
For paid organizations we may process billing contact, plan, subscription status, invoices and payment status, usage relevant to the plan, and identifiers used to associate the account with our payment provider.
Payment-card details are generally collected and stored by our payment provider rather than auth.my.
Security and audit data
We maintain records of security-relevant events such as sign-ins and failed sign-ins, authentication-method changes, application authorization, session revocation, security settings, administrative access, moderation, abuse controls, and actions taken in response to incidents.
Administrative access to another user's personal information is itself logged.
Support and legal communications
If you contact us, we process the information you provide and the information needed to investigate and respond.
4. Why we process personal data
We process personal data to provide the Service, authenticate users, maintain organizations, process account recovery, maintain sessions, secure the platform, prevent fraud and abuse, administer billing, comply with law, and respond to support and legal requests.
Where applicable, processing necessary to provide the Service is based on performance of our contract with you. Security and abuse-prevention processing is based on our legitimate interests in protecting the Service and its users.
Where applicable law requires consent for a particular processing activity, we request it separately.
The consent screen shown during an application authorization controls which requested data auth.my releases to that Connected Application.
Withdrawing authorization prevents future access through auth.my as described by the Service, but cannot recall information a third party already lawfully received.
Where we act as a processor for an organization, we process Customer Personal Data according to that organization's documented instructions and the Data Processing Addendum.
5. How we share personal data
We do not sell personal data and do not provide personal data to advertising networks for behavioral advertising.
Connected Applications
When you authorize a Connected Application, auth.my provides the application with the identity information and claims authorized for that application. The application becomes responsible for its own use of that information.
Organizations
Organization administrators may receive information necessary to administer membership, applications, security, access, usage, and billing. The exact visibility depends on the relationship between the identity and the organization.
Service providers
We use providers that help operate the Service. These may include:
- Cloudflare — network protection, traffic delivery, tunnel infrastructure, and object storage. Cloudflare infrastructure may process request metadata and IP addresses and may store objects such as user avatars and database backups;
- Brevo — transactional email and, where configured, SMS delivery;
- Twilio — optional SMS delivery where configured;
- Stripe — subscription, billing, and payment services;
- Infisical — secrets-management infrastructure; and
- other providers listed in our current Subprocessor List.
Database backups may contain personal data even where particular sensitive fields within the database are encrypted at the application layer.
External sign-in providers
When you choose an external sign-in provider, that provider receives the information inherently necessary to complete the sign-in and processes data under its own privacy policy.
Legal and safety requests
We may disclose information where we reasonably believe disclosure is required by law or valid legal process, or where necessary to protect the rights, security, and safety of auth.my, our users, or others.
Corporate transactions
If our business is reorganized, financed, acquired, or sold, personal data may be transferred as part of that transaction subject to applicable law and appropriate confidentiality protections.
6. International data transfers
auth.my is operated by a United States company and personal data may therefore be processed in the United States and other countries where our service providers operate.
Where EU/EEA law requires an appropriate safeguard for a restricted transfer, we use an applicable transfer mechanism such as the European Commission's Standard Contractual Clauses.
Where UK law requires an appropriate safeguard, we use an applicable UK transfer mechanism, such as the UK International Data Transfer Addendum or International Data Transfer Agreement.
7. Retention
We keep personal data only for as long as necessary for the purpose for which it was collected, subject to legal and security requirements.
Our current retention framework is:
- active account data — while the account remains active;
- pending account deletion — 30 days, during which deletion can be reversed;
- one-time authentication codes — normally minutes, with spent or expired records removed within approximately one day;
- email and SMS delivery logs containing destination information — up to 90 days;
- session records — for the life of the session and for the period needed to display and investigate security history;
- identifiable security and audit records — up to 12 months unless a longer period is reasonably necessary for an active security investigation, dispute, fraud matter, or legal obligation;
- billing and financial records — for the period required by applicable accounting and tax law; and
- database backups — normally up to 14 days.
After the 30-day account-deletion recovery period, personal data is removed from active systems or de-identified according to our deletion process.
Security events that remain after account deletion are stripped of direct account identifiers and information such as address, device, and city to the extent described by our deletion process.
Personal data may continue to exist temporarily in disaster-recovery backups. Backups are not used for ordinary business purposes and expire through the normal backup-retention cycle.
If a backup is restored, deletion requirements applicable to previously deleted data must be reapplied.
8. Security
Our security measures include, as applicable, TLS for data in transit, application-layer encryption of sensitive personal data, hashing of one-time and backup codes, restricted administrative access, audit logging, rate limiting and abuse controls, protected secrets management, database backups, restoration testing, security monitoring, and session and token revocation mechanisms.
No security system eliminates all risk.
9. Your rights
Depending on where you live, you may have rights including access, correction, deletion, portability, restriction, objection, withdrawal of consent where processing is based on consent, and the right to complain to a competent data-protection authority.
The auth.my console provides direct access to many of these functions, including reviewing identity information, sessions and Connected Applications, downloading an export, and requesting deletion.
You can also write to [email protected].
We may need to verify your identity before fulfilling a request.
We will not discriminate against you for exercising a privacy right protected by applicable law.
10. Connected Applications and your data
A Connected Application receiving information from auth.my is responsible for its own processing after receipt.
Deleting your auth.my account does not automatically delete information already held independently by every Connected Application.
You should contact the relevant application if you want it to delete data it controls.
11. Cookies
We use cookies and similar local storage necessary for authentication, session management, account security, request-forgery protection, language and interface preferences, and trusted-device functionality.
We do not use advertising cookies or third-party behavioral advertising trackers in the auth.my account service.
12. Children
auth.my is not intended for children under 16.
We do not knowingly permit a child under 16 to maintain an auth.my account.
If we learn that an account belongs to a child who is not eligible to use the Service, we may suspend the account and take steps to delete the personal data in accordance with applicable law.
Contact [email protected] if you believe an ineligible child has created an account.
13. EU and UK representatives
If applicable law requires us to appoint a representative in the European Union or the United Kingdom, the representative's current contact information will be published here:
EU representative: [TO BE ADDED IF APPLICABLE]
UK representative: [TO BE ADDED IF APPLICABLE]
14. Changes
We may update this Policy when our Service, providers, or legal obligations change.
For material changes affecting existing users, we will provide notice where required by law or reasonably practicable.
The current revision date appears at the top.
15. Contact
Privacy questions and requests: [email protected]
Security reports: [email protected]
General support: [email protected]