Privacy Policy
Last updated: July 23, 2026
This Privacy Policy describes how Auth.io collects, uses and protects information when you use our authentication platform, both as an account holder and as an end user of applications that integrate with us.
1. Information we collect
Account information: name, username, email address, phone number and password (stored hashed) when you create an account.
Usage information: realms, clients, keys and configuration you create, plus operational logs such as sign-in events, token issuance and audit records needed to run the service.
Billing information: subscription and payment details are processed by Stripe; we do not store full card numbers.
2. How we use information
To provide and operate the service: authenticating users, issuing tokens, enforcing tenant isolation and showing you dashboards and audit trails.
To bill your subscription, communicate service updates, respond to support requests and improve the product.
We do not sell your personal data or the personal data of your end users.
3. Data of your end users
When you use Auth.io to authenticate the users of your own applications, you remain the controller of their personal data; Auth.io processes it on your behalf to deliver the authentication service.
End-user data is isolated per realm and is never shared across tenants.
4. Data retention
We keep your data while your account is active. When you delete resources or your account, associated personal data is deleted or anonymized within a reasonable period, except where retention is required by law (for example, billing records).
5. Security
Data is encrypted in transit (TLS) and at rest. Passwords are stored using strong one-way hashing, and signing keys can be rotated per client.
No method of transmission or storage is completely secure; we continuously work to protect your data but cannot guarantee absolute security.
6. Your rights
Depending on your jurisdiction (including under GDPR and LGPD), you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing.
You can exercise these rights through your account settings or by contacting us.
7. Cookies
We use strictly necessary cookies for session management and a cookie to remember your theme preference. We do not use third-party advertising cookies.
8. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email or through the service before they take effect.
Questions about this document? Contact us at hello@authio.com.