Privacy Policy
Last updated: August 13, 2026
We understand how sensitive identity data is and are committed to protecting your personal information. This policy explains how Auth-One collects, uses, stores, and protects your information when you use the service, and the rights you have.
1. Information We Collect
To provide identity and access management services, we collect the following information:
- Account information: username, email, password stored in encrypted form, and profile details you choose to provide;
- Organization information: your tenant, department, position, and role or permission assignments;
- Security information: credentials such as two-factor secrets and recovery codes, stored in encrypted form;
- Log information: sign-in time, IP address, device and browser information, and operation audit records.
2. How We Use Information
We use the collected information only for the following purposes:
- Performing authentication, single sign-on, and access authorization;
- Detecting abnormal sign-ins and security risks to protect your account;
- Sending necessary notifications such as verification codes and security alerts;
- Analyzing service usage to improve the product experience.
3. Cookies and Local Storage
We use cookies and browser local storage to keep your sign-in session, interface theme, and language preference so that your experience stays consistent. You can manage or clear this data in your browser, but you may need to sign in again.
4. Sharing and Disclosure
We do not sell your personal information. It is shared or disclosed only in the following cases:
- Administrators of your tenant can view and manage member information within the organization;
- With your authorization, necessary identity information is provided to third-party applications you choose to sign in to;
- As required by laws and regulations or compulsory requests from judicial authorities.
5. Storage and Protection
Your information is stored on servers deployed by the operator. We protect it with the following measures:
- Passwords are hashed with bcrypt, and sensitive credentials are stored encrypted;
- Data in transit is encrypted with HTTPS;
- Role-based access control and operation auditing prevent unauthorized access;
- Audit logs carry integrity verification to prevent tampering.
6. Data Retention
We retain your information only as long as necessary to provide the service. After account deletion, we delete or anonymize your personal information, except where retention is required by law or for security auditing.
7. Your Rights
You have the following rights regarding your personal information:
- Review and correct your profile in the personal center;
- Manage sign-in sessions and revoke authorizations granted to third-party applications at any time;
- Request account deletion and removal of your personal information;
- Contact us with questions or complaints about how your information is handled.
8. Children's Privacy
The platform is intended for business and organizational users and is not directed at children under 14. If we learn that we have inadvertently collected information from a child, we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be announced through the platform or in-app notifications. Continuing to use the service after an update means you accept the revised policy.
10. Contact Us
If you have questions about this policy or personal data protection, contact us through the feedback channel in the console or the administrator of your tenant.
For the full terms governing use of the service, see the User Agreement.
