Legal
Privacy Policy
Last updated: August 4, 2026
This policy explains what data MicroAuth collects, why, and what happens to it. MicroAuth is operated by Zyref, LLC ("we", "us"). The short version: we collect what we need to run the Service, we do not run advertising trackers, we do not sell data, and by design we never see the traffic flowing through your API.
1. The one thing we do not collect
MicroAuth is not a proxy. Requests from your customers go directly to your servers. What reaches us is metadata you or our SDK send on purpose: configuration, account details and usage items containing an API key ID, status code, count, hourly timestamp and retry-safe identifier. Every reported authenticated request is counted; its status decides whether it also creates a customer charge. We never receive your API request bodies, request headers, query parameters or response bodies.
2. Data we collect and why
Account data
- Name and email address, to create and secure your account.
- Password, stored only as a modern salted hash (Argon2id). We cannot read your password.
- Two-factor authentication data, if you enable 2FA. TOTP secrets are encrypted and backup codes are stored as hashes.
Workspace and tenant data
- Workspace names, tenant configuration, branding assets you upload (such as logos), pricing plans and custom domain settings, because that is the product.
- If you connect Stripe, your Stripe API keys, stored encrypted at rest and used only to act on your behalf (creating checkout sessions, syncing plans, receiving webhooks).
Usage and billing data
- Aggregated request counts per API key per hour, credit balances and ledger entries, to run metering and billing.
- Payment records for your MicroAuth subscription. Card details are handled entirely by Stripe; we never see full card numbers.
Security data
- IP addresses and timestamps for security-sensitive events such as logins and failed attempts, used for rate limiting, lockout protection and the audit trail.
- An audit log of significant actions in your workspaces and portals (who created a key, who changed a plan), visible to you.
3. Your customers' data
People who sign up on your developer portal are your customers. For their data (their name, email, password hash, keys, usage and billing records) you are the controller and we process it on your behalf to provide the Service. We do not contact your customers except for transactional email triggered by their own actions, such as verification codes and invitations, and we do not use their data for anything else.
4. Cookies
We use first-party cookies only, and only for signing you in: an HTTP-only session cookie and a CSRF protection cookie. There are no advertising cookies and no third-party analytics trackers on the application or the portals.
5. Who else touches the data (subprocessors)
We use a small set of providers to run the Service:
- Stripe, for payments and subscriptions.
- Brevo, for transactional email such as verification codes and alerts.
- Cloudflare, for DNS, content delivery and storage of uploaded branding assets.
- DigitalOcean, for the servers and databases the Service runs on.
Each processes data only as needed for its role. We do not sell personal data, and we do not share it with data brokers or advertising networks.
6. Security
- All traffic is encrypted with TLS, including custom portal domains.
- Passwords are hashed with Argon2id; API keys are stored as SHA-256 hashes.
- Sensitive secrets, such as connected Stripe keys and 2FA secrets, are encrypted at rest.
- Sessions use HTTP-only, secure cookies with CSRF protection.
- Failed logins trigger progressive lockouts and account alerts.
No system is perfectly secure. If we learn of a breach affecting your data we will notify you without undue delay. Vulnerability reports go to security@microauth.com.
7. Retention and deletion
- Account and workspace data is kept while your account is active.
- Processed or ignored raw Stripe webhook events are removed after 90 days. Dead events retained for investigation are removed after 365 days.
- Completed, expired or failed checkout coordination records are removed after 90 days. Subscription tombstones used for safe webhook replay are removed after 365 days.
- SDK usage idempotency receipts are removed after 60 days. Expired previous tenant-secret hashes are cleared after their configured rotation overlap.
- Sent transactional email outbox rows are removed after 90 days and dead rows after 365 days. Used or expired password-reset token rows are removed 7 days after use or expiry.
- Credit ledgers, payment records, usage aggregates and audit records currently have no age-based purge. We retain them with the owning account data for billing, disputes and security review.
- Account or workspace deletion can be delayed while a live subscription or open checkout remains. Once accepted, relational child records are deleted by ownership rules. Provider backups and detached branding files may remain until their separate lifecycle expires.
More detail is available in oursecurity and retention documentation.
8. Your rights
You can view and update most of your data directly in the application, and export customer and usage data as CSV or through the API. Depending on where you live, you may also have rights to access, correct, delete or port your personal data, or to object to certain processing. Emailprivacy@microauth.com and we will handle your request; if your customers contact us about data you control, we will refer them to you and assist you in responding.
9. International transfers
Our infrastructure providers may store or process data in the United States and other countries. Where required, we rely on appropriate safeguards such as our providers' standard contractual clauses.
10. Children
The Service is not directed at children and may not be used by anyone under 16. We do not knowingly collect data from children.
11. Changes to this policy
If we change this policy in a way that matters, we will email account owners or show a notice in the application before the change takes effect. The date at the top tells you when it was last revised.
12. Contact
Privacy questions go toprivacy@microauth.com. MicroAuth is a product of Zyref, LLC.