Authfu

Agreements

Terms of Service

The agreement between you and Authfu covering accounts, acceptable use, uptime, liability and termination.

Last updated

01The agreement

These terms are an agreement between you and Conversift, Inc., the company that operates Authfu. They apply when you create an account, register an application, join an organization, or otherwise use the service.

By using Authfu, you accept these terms. If you use the service for a company or another organization, you confirm that you can accept these terms for it. In that case, you includes that organization.

If you and Conversift, Inc. sign a separate agreement covering Authfu, that agreement supersedes these terms.

02The service

Authfu is a hosted identity provider. It lets people sign in with a single-use magic link sent by email. When a person has enrolled TOTP two-factor authentication, Authfu verifies the TOTP code before sending that email. Merely typing another person’s email address does not send them a sign-in message in that case.

A person may instead use a passkey registered against authfu.app. The same passkey can sign that person in to downstream applications without the email step. Applications connect through standard OpenID Connect, including PKCE and RS256 ID tokens.

The service also provides application and organization consoles, session management, and audit logs for sign-in and administrative events.

Pre-launch

Authfu is a pre-launch service and is still evolving. We may add, remove, or change features as we learn what the service needs. We will give notice before a change that materially reduces the core service you are using where practical.

03Accounts

Each account belongs to one person. Do not share an account or create an account that impersonates someone else. Give us accurate information and keep it current.

You are responsible for activity under your account unless it results from our breach of these terms or our failure to use reasonable security. Tell us promptly at security@authfu.com if you believe your account, email address, passkey, TOTP device, backup codes, or session has been compromised.

Authfu has no password to reset. Account security rests on access to the email address and any second factors or passkeys enrolled on the account. Keep those recovery methods secure.

04Your responsibilities as a customer

If people use Authfu to sign in to your application, you control your relationship with them. We provide authentication; we do not become the operator of your application or decide why you use the identity claims you receive.

You must:

  • publish an accurate privacy notice for your application;
  • have a lawful basis for receiving and using sign-in data, including any profile claims you request;
  • use those claims only for purposes the person would reasonably expect from your notice and the sign-in flow;
  • configure your redirect URIs, keys, sessions, access controls, and application securely; and
  • respond to requests and legal duties that arise from your own relationship with your users.

Our Data Processing Addendum covers personal data we process on your behalf where it applies.

05What you must not do

You must follow our Acceptable Use Policy. It sets out the conduct and applications we do not permit, along with how we respond to violations. That policy forms part of these terms.

06Identity ownership

An app is not an identity tenant

Registering an application gives you control over access to that application, and nothing else. You cannot become one of your users, see the other applications that person uses, or alter that person’s credentials.

A person’s Authfu identity is not created inside your application and does not become your property. Your decision to allow or deny access to your application does not control that person’s access anywhere else.

There is one narrow administrative exception. An organization admin may start a time-boxed session as a member only for a DNS-verified domain the organization controls, and only under the safeguards described in our Privacy Policy. That session can never change credentials. Registering an application does not give a developer this ability.

07Fees

Authfu is currently free to use while it is in pre-launch. Paid plans are not yet available, and we do not collect payment card details.

If we introduce a paid tier, we will announce its price and terms before it takes effect. You will be able to decide whether to buy it. We will not retroactively bill you for usage that was free when it occurred.

08Availability

We do not offer a service-level agreement during pre-launch. The service is provided as-is and may be interrupted, delayed, or unavailable while we develop and operate it. We do not promise an uptime percentage.

We will communicate service status and incidents by email. Where practical, we will also give advance notice of planned maintenance that we expect to disrupt the service.

09Your data

You keep ownership of the data you provide to Authfu. We claim no ownership over your application configuration, and we claim no ownership over the identities of people who use the service. Each person’s rights in their personal data also remain intact.

You give us the limited permission needed to host, copy, transmit, secure, and otherwise process your data to provide the service and meet our legal obligations. That permission ends when the data is deleted, except for copies we must keep to meet a legal obligation.

You may ask us to export or delete your customer data by contacting privacy@authfu.com. We may need to verify that the request comes from an authorized account holder. A request concerning another person’s identity remains subject to that person’s rights and our legal obligations.

10Intellectual property

Conversift, Inc. owns Authfu, its software, documentation, and brand, except for material owned by others. These terms give you a limited, non-exclusive, non-transferable right to use the service while the agreement is in effect.

You may not resell Authfu as your own service. You may not reverse engineer, decompile, or try to extract its source code, except where applicable law gives you a right that cannot be waived. You may build and charge for your own applications that useAuthfu for sign-in.

If you send feedback, you allow us to use it without payment or an obligation to implement it. You keep ownership of anything in that feedback that is independently protected by your intellectual property rights.

11Suspension and termination

Ending the agreement

Either you or we may terminate this agreement at any time. You may do so by closing the relevant account, organization, or application, or by asking us to close it. We may terminate by giving you notice.

Suspension

We may suspend access when we reasonably believe there is a security risk or a breach of the Acceptable Use Policy. We will limit a suspension to what is reasonably necessary and give notice where it is safe to do so. We may act without advance notice when delay would create risk for the service or another person.

After termination

After termination, you may request an export of your customer data for 30 days. We will delete it after that period, subject to data we must retain by law and data that belongs to an individual identity rather than to your application. Sections that are intended by their nature to continue, including ownership, liability, indemnity, and disputes, will continue.

12Disclaimers

During pre-launch, Authfu is provided as-is and as available, without warranties of merchantability, fitness for a particular purpose, non-infringement, or uninterrupted operation. We do not promise that the service will be error-free or meet every use case.

These disclaimers apply only to the extent the law allows. They do not exclude a warranty or right that cannot lawfully be excluded.

13Limitation of liability

To the extent the law allows, neither party will be liable under these terms for lost profits, revenues, goodwill, or data, or for indirect, incidental, special, exemplary, or consequential damages. This applies regardless of the legal theory and even if the party knew that the loss was possible.

Each party’s total liability arising from the service or these terms is capped at the fees you paid us for the service during the 12 months before the event giving rise to the claim. Because Authfu is currently free, that fee-based cap is nominal in practical effect and is currently zero. We state that directly so you can assess the risk of using a pre-launch service.

The exclusions and cap do not apply to fraud, willful misconduct, or liability that cannot be limited by law.

14Indemnity

You will defend and indemnify Conversift, Inc. against a third-party claim arising from your use of the service, the content or operation of your applications, your relationship with your users, or your breach of these terms or applicable law. You do not owe this indemnity to the extent the claim was caused by our breach, negligence, or willful misconduct.

We will notify you promptly of a covered claim and give you reasonable cooperation. You may control its defense and settlement, but may not admit fault for us or impose an obligation on us without our written consent. We will not unreasonably withhold that consent.

15Changes to these terms

We may change these terms as the service evolves. We will email you before a material change takes effect and will say when the revised terms begin to apply. Changes that are not material may take effect when posted with a new revision date.

If you do not accept a material change, you may stop using the service and terminate this agreement before it takes effect. Continuing to use the service after that date means you accept the revised terms.

16Governing law and disputes

The law governing these terms and the venue for disputes are: to be confirmed before general availability; write to legal@authfu.com if this matters to your agreement.

Before filing a formal claim, each party will make a reasonable effort to resolve the dispute directly. This does not prevent either party from seeking urgent court relief when needed to protect accounts, data, security, or intellectual property, and it does not remove any right that applicable law says cannot be waived.

17Contact

Questions or legal notices about these terms can be sent to legal@authfu.com.