Legal
Privacy Policy
Last updated: August 3, 2026
This policy explains what data MicroAuth collects, why, and what happens to it. MicroAuth is operated by Zyref, LLC ("we", "us"). The short version: we collect what we need to run the Service, we do not run advertising trackers, we do not sell data, and by design we never see the traffic flowing through your API.
1. The one thing we do not collect
MicroAuth is not a proxy. Requests from your customers go directly to your servers. What reaches us is metadata you or our SDK send on purpose: configuration, account details and usage counts (how many billable requests an API key made in a given hour). We never receive request bodies, headers, query parameters or responses from your API.
2. Data we collect and why
Account data
- Name and email address, to create and secure your account.
- Password, stored only as a modern salted hash (Argon2id). We cannot read your password.
- Two-factor authentication secrets and backup code hashes, if you enable 2FA, stored encrypted.
Workspace and tenant data
- Workspace names, tenant configuration, branding assets you upload (such as logos), pricing plans and custom domain settings, because that is the product.
- If you connect Stripe, your Stripe API keys, stored encrypted at rest and used only to act on your behalf (creating checkout sessions, syncing plans, receiving webhooks).
Usage and billing data
- Aggregated request counts per API key per hour, credit balances and ledger entries, to run metering and billing.
- Payment records for your MicroAuth subscription. Card details are handled entirely by Stripe; we never see full card numbers.
Security data
- IP addresses and timestamps for security-sensitive events such as logins and failed attempts, used for rate limiting, lockout protection and the audit trail.
- An audit log of significant actions in your workspaces and portals (who created a key, who changed a plan), visible to you.
3. Your customers' data
People who sign up on your developer portal are your customers. For their data (their name, email, password hash, keys, usage and billing records) you are the controller and we process it on your behalf to provide the Service. We do not contact your customers except for transactional email triggered by their own actions, such as verification codes and invitations, and we do not use their data for anything else.
4. Cookies
We use first-party cookies only, and only for signing you in: an HTTP-only session cookie and a CSRF protection cookie. There are no advertising cookies and no third-party analytics trackers on the application or the portals.
5. Who else touches the data (subprocessors)
We use a small set of providers to run the Service:
- Stripe, for payments and subscriptions.
- Brevo, for transactional email such as verification codes and alerts.
- Cloudflare, for DNS, content delivery and storage of uploaded branding assets.
- DigitalOcean, for the servers and databases the Service runs on.
Each processes data only as needed for its role. We do not sell personal data, and we do not share it with data brokers or advertising networks.
6. Security
- All traffic is encrypted with TLS, including custom portal domains.
- Passwords are hashed with Argon2id; API keys are stored as SHA-256 hashes.
- Sensitive secrets, such as connected Stripe keys and 2FA secrets, are encrypted at rest.
- Sessions use HTTP-only, secure cookies with CSRF protection.
- Failed logins trigger progressive lockouts and account alerts.
No system is perfectly secure. If we learn of a breach affecting your data we will notify you without undue delay. Vulnerability reports go to security@microauth.com.
7. Retention and deletion
- Account and workspace data is kept while your account is active.
- When you delete a workspace or your account, associated data is deleted, except records we must keep for legal, billing or security reasons, which we keep no longer than needed and then delete or anonymize.
- Aggregated usage records that no longer identify anyone may be kept for capacity planning.
8. Your rights
You can view and update most of your data directly in the application, and export customer and usage data as CSV or through the API. Depending on where you live, you may also have rights to access, correct, delete or port your personal data, or to object to certain processing. Email privacy@microauth.com and we will handle your request; if your customers contact us about data you control, we will refer them to you and assist you in responding.
9. International transfers
Our infrastructure providers may store or process data in the United States and other countries. Where required, we rely on appropriate safeguards such as our providers' standard contractual clauses.
10. Children
The Service is not directed at children and may not be used by anyone under 16. We do not knowingly collect data from children.
11. Changes to this policy
If we change this policy in a way that matters, we will email account owners or show a notice in the application before the change takes effect. The date at the top tells you when it was last revised.
12. Contact
Privacy questions go to privacy@microauth.com. MicroAuth is a product of Zyref, LLC.