Authfu

Privacy

Privacy Policy

What Authfu collects, why, how long it is kept, who it is shared with, and the rights you have over it.

Last updated

01Who this covers

This policy covers personal data handled by Conversift, Inc., the company that operates Authfu. It applies to two different groups of people.

Customers

Customers are developers and organizations that hold an Authfu account and register applications. We decide why and how to process the personal data used to create, administer, secure, and support those customer accounts. For that data,Authfu is the controller.

End users

End users are people who use Authfu to sign in to a customer’s application. The customer decides why that person’s data is processed and instructs us how to handle it. For that data, the customer is the controller andAuthfu is its processor.

Registering an application does not give its developer control over a person’s identity or credentials. A developer cannot act as an end user or change that person’s credentials.

02What we collect

We collect only the information needed to provide identities, authenticate people, operate the service, and investigate security events. The complete categories are below.

What you give us

  • Your email address, plus any first name, last name, or display name you choose to provide.
  • One optional handle. A handle is globally unique across Authfu and is exposed to applications as the OpenID Connect preferred_username claim.
  • An optional avatar that you upload.
  • If you enroll TOTP two-factor authentication, the TOTP secret and backup codes created during enrollment. The secret is encrypted and the backup codes are hashed.
  • If you register a passkey, its public key and the information needed to associate it with your account. We never receive or store the passkey’s private key.

What using the service creates

  • Session records used to keep you signed in and end sessions safely.
  • Audit entries for sign-in events and administrative actions. When an organization administrator uses a permitted act-as session, the audit entry includes that event and the required reason.
  • A record of the applications you have signed in to through Authfu.

What arrives automatically

Security logs receive the IP address and user-agent string sent with a request. We use those fields to protect accounts, investigate abuse, and diagnose service problems.

The console sets one signed, httpOnly, secure, SameSite session cookie,authfu.session-token. An OAuth redirect also uses a short-livedstate cookie to bind the request to its response. The marketing site atauthfu.com sets no cookies. See our Cookies and Tracking page for the exact behavior.

03What we never collect

There is less data to trust us with

We do not collect passwords because Authfu has no passwords. There is no password database to steal. We also do not collect payment card data, run analytics, create advertising identifiers, track people across sites, or record sessions. The browser makes no third-party requests at all.

Billing is not live. Stripe is not installed, and Authfu does not process card details. Fonts are self-hosted at build time. There is no analytics SDK, tag manager, error-tracking SDK, or session-replay tool hidden behind a consent banner.

04Why we process it

When we act as controller, we rely on the following lawful bases under Article 6 of the GDPR. We do not reuse personal data for unrelated advertising or analytics purposes.

PurposeLawful basisWhat that means
Create and operate customer accounts; provide sign-in and account featuresContract performance — Article 6(1)(b)We need this data to provide the service a customer requests.
Secure accounts, prevent abuse, investigate incidents, and keep audit recordsLegitimate interests — Article 6(1)(f)Our interest is operating a secure and reliable identity service. We consider the effect on the people whose data is involved.
Keep or disclose information when applicable law requires itLegal obligation — Article 6(1)(c)We process only what the applicable obligation requires.
Store optional profile details a person chooses to addConsent — Article 6(1)(a)Consent can be withdrawn without changing whether processing before withdrawal was lawful.

For end-user data, the customer chooses and documents the lawful basis. We process that data on the customer’s instructions under our Data Processing Addendum. The table does not replace the customer’s own privacy notice.

05Who we share it with

A small number of service providers can touch data while helping us run Authfu. Our Subprocessors page names every one, explains its purpose, and lists its region. If a provider is not on that page, it does not touch data held in Authfu.

We do not sell personal data. Authfu has no advertising business, so there is nothing to sell it for. We do not give data to data brokers or ad networks.

We may disclose information when applicable law requires it. We do not treat a request as valid merely because someone asks; it must have a lawful basis and proper authority.

06How long we keep it

Some retention periods are fixed because the product enforces them:

  • Single-use sign-in links and pre-authentication tokens expire within minutes.
  • Test-inbox messages are kept for 24 hours, with no more than the newest 50 messages retained.
  • When an account is deleted, its records are removed.

Final fixed periods for session records, security logs, audit entries, and inactive account data are still under review. We will not invent a number here. This policy will be updated when those periods are settled.

Where we process end-user data for a customer, deletion also follows that customer’s documented instructions and the Data Processing Addendum.

07How it is protected

TOTP secrets use AWS KMS envelope encryption in us-east-2. A customer master key in KMS wraps the data key, and the plaintext key never leaves AWS. Backup codes are stored as SHA-256 hashes.

Passkeys are different: we store only public keys. The private key stays with the person’s authenticator, so a copied passkey table cannot be used to authenticate as that person.

An organization administrator can use a one-hour act-as session only for a member whose email exactly matches the organization’s DNS-verified domain. The administrator must re-authenticate and type a reason. We notify the member and write the event to both audit logs. The session cannot change credentials. Application developers never receive this access merely by registering an app.

Read the Security page for the authentication order, administrative safeguards, and further technical detail.

08Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal data. You may also have rights to object to processing, restrict it, withdraw consent, and complain to your local data-protection supervisory authority.

If you are an end user

Start with the application you signed in to. That customer is the controller and must decide how to answer your request; Authfu acts on its instructions. We will help the customer locate, export, correct, or delete the relevant data.

If you are a customer

Send your request to privacy@authfu.com. We may need to verify that the request concerns your account before acting on it.

Our response time

We will respond to a privacy-rights request within 30 days. If another law requires a shorter period, that shorter period controls.

09International transfers

Personal data handled by the service is processed in the United States. The region column in our Subprocessors page shows where each provider operates. AWS KMS holds encryption keys in us-east-2; it does not hold personal data.

For EU customers, our Data Processing Addendum offers the European Commission’s Standard Contractual Clauses as the transfer mechanism for personal data sent to the United States.

10Children

Authfu is not directed at children under 13, or under 16 in the European Union. Customers must not direct an application using Authfu to those children or send us their personal data without a lawful basis and any consent the law requires.

11Changes to this policy

We may revise this policy as the service changes. Before a material change takes effect, we will email account holders and explain the change. The revision date at the top of this page always shows when the policy last changed.

12Contact

Conversift, Inc.
Privacy questions and rights requests: privacy@authfu.com