AuthLX

    Legal

    Privacy Policy

    Last updated: June 19, 2026

    In short: AuthLX collects the minimum data needed to run authentication and licensing for your applications — your account email and username, your end-users' sign-in data, hardware identifiers you bind to licenses, and basic technical logs. We use Supabase for data storage and Discord webhooks for operational alerts. We don't sell your data. This policy explains everything in detail and your rights under the GDPR and CCPA.

    1. Who This Applies To

    This Privacy Policy applies to two groups:

    • Customers — developers and companies who create an AuthLX account and integrate our SDK. You are the data controller for your account data and for your end-users' data; AuthLX is your data processor.
    • Visitors — anyone who visits authlx.com. We collect only minimal technical data described below.

    If you are an End-User of a customer's application (not an AuthLX customer yourself), your data is controlled by that customer. Please direct privacy requests about end-user data to the application's operator. AuthLX will assist our customers in fulfilling legitimate requests.

    2. Data We Collect

    2.1 Data you provide

    • Account data: email address, username, and a salted/hashed password when you register. We never store passwords in plain text.
    • Profile data: optional details you add to your account (for example, a nickname or avatar).
    • Application data you configure: application names, versions, owner IDs, license keys, subscription tiers, tokens, and reseller settings you create in the dashboard.
    • Support communications: the contents of messages you send us (for example, support tickets or emails).

    2.2 Data collected automatically

    • End-user authentication data: when your application authenticates a user through AuthLX, we process the credentials and session data necessary to issue an HTTP-only session cookie and validate the session. This may include the end-user's email/username and an IP address.
    • Hardware identifiers (HWID): if you enable hardware-ID binding on a license, we process the device identifier your application sends so the license can be validated against that device.
    • Technical/log data: IP address, browser/user-agent, approximate location (country-level), timestamps, and request logs used for security, abuse prevention, and reliability.

    2.3 Summary Table

    Data categoryExamplesSource
    Account credentialsEmail, username, hashed passwordYou (Customer)
    Application configApp name, license keys, subscriptions, tokensYou (Customer)
    End-user auth dataEnd-user email/username, session, IPYour Application
    Hardware identifiersDevice HWID bound to a licenseYour Application
    Technical/log dataIP, user-agent, timestamps, request logsAutomatic

    3. How & Why We Use Data

    We use personal data only for specific, legitimate purposes:

    • To provide the Service: create accounts, issue and validate sessions, manage licenses, subscriptions, tokens, and HWID binding, and operate your dashboard.
    • To secure the Service: detect, prevent, and respond to fraud, abuse, unauthorized access, and security incidents.
    • To communicate with you: service notices, account-related emails, and responses to your support requests.
    • To comply with legal obligations: meet record-keeping requirements.

    5. Third Parties & Sub-Processors

    We rely on trusted third parties to operate the Service. They process data on our behalf under written agreements:

    ProviderPurposeData involved
    SupabaseDatabase hosting and serverless edge functionsAccount, application, end-user, and log data
    Discord (webhooks)Operational alerts and loggingLimited event metadata (no raw passwords)
    Cloud infrastructureServing the website and APITechnical/log data

    We do not sell personal data to any third party.

    6. When We Share Data

    We may disclose personal data only:

    • To our sub-processors, as described above;
    • To comply with a legal obligation or lawful request from an authority;
    • To protect our rights, property, or safety.

    7. Data Retention

    We keep personal data only as long as necessary for the purposes described here:

    • Account data is retained while your account is active and deleted within a reasonable period after closure.
    • End-user and licensing data is retained for as long as your application uses the Service.

    8. Security

    We take reasonable technical and organizational measures to protect personal data, including: hashed passwords (never plain text), HTTP-only session cookies, transport encryption (HTTPS), access controls, and isolation between customers' data.

    9. Cookies

    AuthLX uses a minimal set of cookies and similar technologies:

    • Essential (session) cookies: the HTTP-only cookie that keeps you signed in.
    • Preference cookies: to remember your choices (for example, theme).

    10. Your Rights (GDPR / UK GDPR)

    If you are in the EU, UK, or EEA, you have the following rights over your personal data:

    Access & RectificationRight to receive a copy of your data and correct any inaccuracies.
    Erasure & PortabilityRequest deletion of your data or export it in a structured machine-readable format.
    Objection & RestrictionObject to processing based on legitimate interests or limit how we process it.

    11. Your Rights (CCPA / US State Laws)

    If you are a California resident, you have the right to Know what personal data we collect, request Deletion, correct inaccuracies, and Opt Out of the "sale" or "sharing" of personal data. AuthLX does not sell personal data.

    12. Children

    The Service is not directed to children under 16, and we do not knowingly collect personal data from them.

    13. International Transfers

    Because AuthLX and its sub-processors process data in countries outside your own — including the United States — your data may be subject to the laws of those countries. We use Standard Contractual Clauses where applicable.

    14. Changes

    We may update this Privacy Policy from time to time. We will change the "Last updated" date above and notify you of any material changes.

    15. Contact & DPO

    For any privacy question, request, or complaint, contact us at: [email protected].

    © 2026 AuthLX. All rights reserved.