IDENTITY ACCESS
Terms of servicePrivacyData Processing AddendumSubprocessors
CONTENTS
  1. 1. Who provides the Service
  2. 2. Eligibility
  3. 3. Your auth.my account
  4. 4. Organization-managed identities
  5. 5. Connected Applications
  6. 6. Application owners and developers
  7. 7. Organizations
  8. 8. Plans, usage, and billing
  9. 9. Acceptable use
  10. 10. Security
  11. 11. Privacy
  12. 12. Third-party services
  13. 13. Intellectual property
  14. 14. Feedback
  15. 15. Availability and changes
  16. 16. Suspension and termination
  17. 17. Account deletion
  18. 18. Disclaimer
  19. 19. Limitation of liability
  20. 20. Indemnity by application and organization owners
  21. 21. Governing law
  22. 22. Changes to these Terms
  23. 23. Contact

Terms of Service

Last updated: 2026-09-07 · previous revision of 2026-08-18

These Terms of Service ("Terms") govern your use of auth.my and related services (the "Service").

By creating or using an auth.my account, connecting an application, creating or joining an organization, or otherwise using the Service, you agree to these Terms.

1. Who provides the Service

The Service is provided by USSV LLC, registered at 30 N Gould St Ste N, Sheridan, WY 82801 US ("auth.my", "we", "us", or "our").

General contact: [email protected]

Privacy: [email protected]

Security: [email protected]

2. Eligibility

The Service is intended for users aged 16 or older.

You may not use the Service if applicable law prohibits you from doing so.

If you use the Service on behalf of an organization, you represent that you have authority to bind that organization to these Terms.

3. Your auth.my account

auth.my is a passwordless identity service. Depending on the features enabled for your account, you may sign in using a one-time code sent by email, a one-time code sent by SMS to a previously verified phone number, a passkey, an authenticator application, backup codes, a trusted-device PIN where available, or an external identity provider supported by the Service.

Supported external providers may include Google, Microsoft Entra, Apple, GitHub, Facebook, LinkedIn, and others we may add or remove.

Your account is personal to you. You must not intentionally give another person access to your personal auth.my identity.

You are responsible for maintaining control of your email accounts, phone numbers, passkeys, devices, backup codes, and other authentication methods. You should maintain at least one recovery method that is independent of your primary sign-in method.

4. Organization-managed identities

Some accounts may be associated with an organization.

Where an organization has verified control of a business domain, an identity using that domain may be treated as an organization-managed identity according to the organization's configuration.

If your identity is organization-managed:

  • the organization may control whether you can access its applications;
  • your access may be suspended or removed when your relationship with the organization ends;
  • organization administrators may see information necessary to administer membership, access, security, and billing; and
  • the organization may have additional policies governing your use of its applications.

Membership in an organization does not automatically make every identity organization-owned. External members may remain independent auth.my users.

5. Connected Applications

auth.my allows you to sign in to third-party sites and applications ("Connected Applications").

Before auth.my releases information requested by a Connected Application, the Service displays the application and the data it requests where consent is required.

You may withdraw access from a Connected Application through your auth.my account.

A Connected Application is operated by a third party. Its own terms and privacy policy govern what it does with information after receiving it from auth.my.

We do not control and are not responsible for a Connected Application's own services, content, security, or independent processing of information.

6. Application owners and developers

If you register an application with auth.my, you agree to:

  • provide accurate information about the application and its owner;
  • not impersonate another company, service, or person;
  • register only domains and redirect addresses you are authorized to use;
  • request only data reasonably necessary for your application;
  • protect client credentials and other secrets;
  • promptly rotate credentials you believe may have been compromised;
  • maintain your own privacy notice and terms where required;
  • comply with applicable privacy, consumer-protection, communications, and security laws;
  • honor a user's withdrawal of access where technically applicable; and
  • not use auth.my to facilitate spam, fraud, surveillance, credential theft, unlawful discrimination, or unauthorized collection of personal data.

We may review an application's name, branding, verified domains, requested permissions, or other information before or after making it available to users.

We may suspend an application where we reasonably believe it creates a security, fraud, legal, or user-safety risk.

7. Organizations

An organization may invite members, configure applications, verify domains, manage environments, and assign roles.

The organization is responsible for ensuring that its administrators are authorized to act for it, determining who should have access to its applications, removing access when it is no longer appropriate, complying with laws applicable to its users, and providing notices required for personal data that it asks auth.my to process on its behalf.

For processing where auth.my acts as a processor on behalf of an organization, the auth.my Data Processing Addendum applies if the parties have agreed to it.

8. Plans, usage, and billing

Some features are free and others require a paid plan.

The applicable price, billing interval, included usage, and other commercial terms are shown when a plan is selected or agreed separately with us.

Paid subscriptions renew for the applicable billing period until cancelled, unless the order or checkout terms state otherwise.

Payments may be processed by Stripe or another payment provider identified at checkout. Payment providers may process payment and billing information under their own terms and privacy notices.

Taxes may be added where required by law.

Usage limits may restrict creation of new applications, environments, invitations, or other administrative actions.

Exceeding a usage allowance or a failed subscription payment does not, by itself, cause auth.my to intentionally disable authentication for existing end users.

Where a payment remains overdue after any applicable grace period, we may downgrade the organization to a free or lower plan.

Unless otherwise stated at purchase, payments are non-refundable except where a refund is required by applicable law.

9. Acceptable use

You must not:

  • attempt to access another person's account without authorization;
  • automate guessing of authentication codes or credentials;
  • create accounts or traffic for the purpose of abuse, spam, fraud, or artificial usage;
  • bypass rate limits, fraud controls, or security restrictions;
  • interfere with the availability of the Service;
  • probe or exploit vulnerabilities without authorization;
  • use the Service in violation of law or another person's rights; or
  • use the Service to mislead users about the identity of an application or organization.

Good-faith security research should be reported to [email protected].

We will not pursue a researcher solely for a good-faith report that avoids privacy violations, data destruction, persistence, extortion, and disruption.

10. Security

We use technical and organizational measures intended to protect the Service and personal data.

No online service can guarantee absolute security.

You must notify us promptly if you believe your account, application credentials, or organization have been compromised.

We may revoke sessions or credentials, temporarily restrict an account, or take other protective measures where reasonably necessary to contain a security incident.

11. Privacy

Our processing of personal data is described in the Privacy Policy.

Organizations using auth.my to process personal data on their behalf may also be subject to the Data Processing Addendum.

12. Third-party services

The Service relies on third-party infrastructure and service providers, including providers for network delivery, messaging, storage, payments, and federated sign-in.

Those services may become temporarily unavailable or change their functionality.

We are not responsible for a third party's independent services or acts outside our reasonable control.

13. Intellectual property

auth.my, its software, branding, documentation, and other materials are owned by us or our licensors except where expressly licensed otherwise.

These Terms do not transfer ownership of our intellectual property.

You retain ownership of content, branding, logos, and information you submit to the Service.

You grant us a limited license to host, reproduce, and display that material only as necessary to provide, secure, moderate, and operate the Service.

14. Feedback

If you voluntarily provide product feedback, you allow us to use that feedback without restriction or compensation, provided we do not identify you publicly without permission.

15. Availability and changes

The Service is under active development.

We do not promise uninterrupted or error-free operation.

We may modify features, security requirements, supported providers, limits, or technical interfaces.

Where a change materially affects paid functionality or legal rights, we will provide reasonable notice where practicable or required by law.

Do not make auth.my the only method of access to a system whose loss of access would create unacceptable harm unless you have independently determined that the Service and your recovery arrangements meet your needs.

16. Suspension and termination

You may stop using the Service at any time.

You may request deletion of your personal auth.my identity through the Service.

We may restrict or suspend an account, organization, or application where these Terms are materially violated, payment obligations remain overdue, we reasonably believe the account or application is compromised, continued operation creates a security or legal risk, or we are legally required to do so.

Where practicable, we will limit a restriction to the affected account, application, or organization rather than unrelated users.

17. Account deletion

Deleting an account immediately prevents ordinary sign-in.

A deletion request may remain reversible for 30 days.

After the recovery period, personal data is removed or de-identified from active systems according to the Privacy Policy.

Residual copies may remain in disaster-recovery backups until those backups expire through their normal retention cycle.

18. Disclaimer

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" TO THE MAXIMUM EXTENT PERMITTED BY LAW.

WE DISCLAIM IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT TO THE EXTENT SUCH WARRANTIES MAY LEGALLY BE DISCLAIMED.

Nothing in these Terms excludes warranties or rights that applicable law does not permit us to exclude.

19. Limitation of liability

To the maximum extent permitted by applicable law, neither party will be liable for indirect, incidental, special, exemplary, punitive, or consequential damages, or for lost profits or lost business arising from the Service.

For claims arising from a paid organization account, our aggregate liability arising out of the Service during any twelve-month period will not exceed the fees paid by that organization to auth.my during the twelve months preceding the event giving rise to the claim.

For a user of a free Service, our aggregate liability will not exceed USD 100.

These limitations do not apply to liability that cannot legally be limited or excluded, including where applicable liability resulting from fraud, willful misconduct, or other liability that applicable law requires to remain unlimited.

20. Indemnity by application and organization owners

If you use the Service on behalf of a business or organization, that entity agrees, to the extent permitted by law, to defend and indemnify us against third-party claims resulting from its Connected Applications, data or branding it supplied, unlawful instructions it gave us, its violation of applicable law, or its violation of these Terms.

This section does not apply to an individual consumer acting solely in a personal capacity.

21. Governing law

These Terms are governed by the laws of the State of Wyoming, United States, without regard to conflict-of-law principles.

Subject to mandatory law to the contrary, disputes concerning these Terms may be brought in courts having jurisdiction in Wyoming.

Nothing in this section deprives a consumer of mandatory rights or remedies that cannot be waived under the law applicable to that consumer.

22. Changes to these Terms

We may update these Terms.

For a material change affecting existing users, we will provide notice at least 14 days before the change takes effect where reasonably practicable, unless an earlier change is required for security, legal compliance, or to prevent abuse.

The date at the top identifies the current version.

23. Contact

General: [email protected]

Privacy: [email protected]

Security: [email protected]

auth.my — sign-in for sites and applications. [email protected]