Privacy Policy
1. What we collect
SirAuth is an authentication service, so we deliberately collect as little as possible:
- Account data — your email address and hashed authentication material.
- End-user identifiers — emails or passkey credentials of users you authenticate through the API; we store only what your application sends us.
- Operational logs — request timestamps, API endpoint, response status and IP address, retained for 30 days for abuse prevention and debugging.
2. What we never do
- We do not sell or rent personal data.
- We do not read the content of your end users' messages — sign-in emails contain only a single-use link.
- We do not use third-party advertising or session-replay trackers on this website.
3. How data is protected
All traffic is encrypted with TLS. Passwords are never stored — the service is passwordless by design. API tokens and end-user credentials are stored hashed. Access to production systems is limited to operators with hardware-key authentication.
4. Retention
- Operational logs — 30 days.
- Account data — until the account is deleted, then removed within 30 days.
- Data of closed accounts is exported on request for 14 days after deletion.
5. Subprocessors
We run our own infrastructure. The only subprocessors are our hosting and email-delivery providers, listed on request at privacy@sirauth.com.
6. Your rights
You can request access to, correction of, or deletion of your personal data at any time. Depending on your jurisdiction you may also have the right to data portability and to lodge a complaint with a supervisory authority.
7. Contact
Privacy questions: privacy@sirauth.com.