This Privacy Policy applies to two groups:
If you are an End-User of a customer's application (not an AuthLX customer yourself), your data is controlled by that customer. Please direct privacy requests about end-user data to the application's operator. AuthLX will assist our customers in fulfilling legitimate requests.
| Data category | Examples | Source |
|---|---|---|
| Account credentials | Email, username, hashed password | You (Customer) |
| Application config | App name, license keys, subscriptions, tokens | You (Customer) |
| End-user auth data | End-user email/username, session, IP | Your Application |
| Hardware identifiers | Device HWID bound to a license | Your Application |
| Technical/log data | IP, user-agent, timestamps, request logs | Automatic |
We use personal data only for specific, legitimate purposes:
For users in the EU/UK/EEA, we rely on the following lawful bases under Article 6 of the GDPR:
We rely on trusted third parties to operate the Service. They process data on our behalf under written agreements:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database hosting and serverless edge functions | Account, application, end-user, and log data |
| Discord (webhooks) | Operational alerts and logging | Limited event metadata (no raw passwords) |
| Cloud infrastructure | Serving the website and API | Technical/log data |
We do not sell personal data to any third party.
We keep personal data only as long as necessary for the purposes described here:
We take reasonable technical and organizational measures to protect personal data, including: hashed passwords (never plain text), HTTP-only session cookies, transport encryption (HTTPS), access controls, and isolation between customers' data.
If you are in the EU, UK, or EEA, you have the following rights over your personal data:
If you are a California resident, you have the right to Know what personal data we collect, request Deletion, correct inaccuracies, and Opt Out of the "sale" or "sharing" of personal data. AuthLX does not sell personal data.
The Service is not directed to children under 16, and we do not knowingly collect personal data from them.
Because AuthLX and its sub-processors process data in countries outside your own — including the United States — your data may be subject to the laws of those countries. We use Standard Contractual Clauses where applicable.
We may update this Privacy Policy from time to time. We will change the "Last updated" date above and notify you of any material changes.
For any privacy question, request, or complaint, contact us at: [email protected].