IDENTITY ACCESS
Terms of servicePrivacyData Processing AddendumSubprocessors
CONTENTS
  1. Cloudflare object storage
  2. External identity providers
  3. Changes

Subprocessors

Last updated: 2026-09-07

auth.my Subprocessor List

auth.my uses third-party providers to operate particular parts of the Service.

Not every provider processes every user's data. Use depends on configuration, location, and the features being used.

ProviderPurposeData that may be processed
CloudflareNetwork delivery, security, Cloudflare Tunnel, object storageIP address, request metadata, stored avatars, database backup objects and other stored service objects
BrevoTransactional email and optional SMS deliveryEmail address or phone number, message content, delivery metadata
TwilioOptional SMS deliveryPhone number, SMS content, delivery metadata
StripeSubscription billing and payment servicesOrganization billing contact, customer/subscription identifiers, payment and invoice information
InfisicalSecrets-management infrastructureService configuration secrets and encrypted credentials; end-user Personal Data is not intentionally stored there

Cloudflare object storage

Cloudflare infrastructure is used for more than delivery of web traffic.

Where object storage is enabled, it may contain user avatars, service assets, and database backups.

Database backups may contain Personal Data.

Certain sensitive fields in the database are encrypted by auth.my before they are written to the database, but a database backup must still be treated as Personal Data and protected accordingly.

External identity providers

Google, Microsoft Entra, Apple, GitHub, Facebook, LinkedIn and other login providers displayed by auth.my are not listed above merely because a user may choose to sign in through them.

When a user intentionally chooses one of those providers, the provider handles the sign-in under its own privacy terms and may act as an independent controller rather than as an auth.my Subprocessor.

Changes

auth.my may add, replace, or remove providers as the Service changes.

Where a Data Processing Addendum requires advance notice of a new Subprocessor that materially processes Customer Personal Data, we will provide such notice in accordance with that DPA.

Questions about subprocessors may be sent to:

[email protected]

auth.my — sign-in for sites and applications. [email protected]