Privacy Policy
Last updated: July 2, 2026
This Privacy Policy explains how AuthRobo(“AuthRobo”, “we”, “us”) collects, uses, discloses, and protects personal data. AuthRobo provides authentication and Stripe-synced billing infrastructure that other applications (“Customer Apps”) integrate to sign in and manage their own users. Your privacy matters to us, and we only collect personal data we genuinely need to provide the service.
1. Our two roles: controller and processor
Because of how AuthRobo works, we act in two distinct capacities under data-protection law:
- Data controller— for the accounts of developers and organisations who sign up to the AuthRobo dashboard (“Owners”). We decide how that account data is processed.
- Data processor— for the end-user data that Owners collect through their Customer Apps (for example, the people who register or sign in to an app that uses AuthRobo). Here the Owner is the controller and decides why the data is processed; we process it only on the Owner’s instructions to deliver the service.
If you are an end user of an app that uses AuthRobo and you have questions about your data, please contact that app’s operator (the controller) in the first instance. We will assist them in responding to your request.
2. Information we collect
Owner account data (we are the controller)
- Name, email address, and profile image (for example, from Google sign-in).
- Account and plan details, including your AuthRobo subscription status.
- Billing identifiers held by our payment processor (we do not store card numbers).
End-user data (we are the processor, on the Owner’s behalf)
- End-user email address and name, and profile image where provided.
- Authentication credentials in protected form — passwords are stored only as one-way hashes; we never store plaintext passwords.
- Linked sign-in identities (for example, a Google account identifier).
- Session records and subscription/plan data synced from the Owner’s Stripe account.
Technical data
- Log and diagnostic data such as timestamps and request metadata, used to operate and secure the service.
- An essential session cookie set on the AuthRobo dashboard to keep you signed in.
3. How we use personal data
- To provide, maintain, and secure the authentication and billing service.
- To authenticate users and issue and verify access tokens.
- To process Owner subscriptions and keep Customer App subscription data in sync.
- To communicate service and account information (for example, a welcome email on sign-up).
- To detect, prevent, and respond to abuse, fraud, and security incidents.
- To comply with legal obligations.
4. Legal bases for processing
Where the GDPR or similar laws apply, we rely on the following legal bases:
- Contract — to provide the service you or the Owner have requested.
- Legitimate interests — to secure, maintain, and improve the service.
- Legal obligation — where processing is required by law.
- Consent — where you have given consent for a specific activity.
See our GDPR page for a fuller explanation of your rights and how to exercise them.
5. Sharing and sub-processors
We do not sell personal data. We share it only with service providers who help us operate AuthRobo, and only as needed to deliver the service. Current sub-processors:
| Provider | Purpose | Region |
|---|---|---|
| Neon | Managed PostgreSQL database (data storage) | Sydney, Australia |
| Vercel | Application hosting and content delivery | Global |
| Stripe | Payment processing and subscription data | Global |
| OAuth sign-in (where enabled) | Global | |
| [Email delivery provider] | Transactional email | [Region] |
We may also disclose data where required by law or to protect our rights and the safety of others.
6. Data retention
- Owner account data — retained while the account is active and for up to 90 days after deletion, then removed.
- End-user data — retained for as long as the relevant Owner instructs; deleting an end user or an app removes the associated records.
- Billing records — retained as required for financial and legal compliance.
- Logs — retained for a limited period for security and operational purposes.
7. How we protect data
We apply technical and organisational measures appropriate to the risk, including:
- Encryption in transit (TLS) and encryption at rest for stored data.
- One-way hashing of passwords (bcrypt) — plaintext passwords are never stored.
- RS256-signed access tokens verified against a published JWKS.
- Authenticated encryption (AES-256-GCM) of sensitive secrets such as connected payment keys.
- Strict per-application (tenant) isolation so one Owner cannot access another’s data.
- Access controls and least-privilege access to production systems.
8. International data transfers
We and our sub-processors may process personal data in countries other than your own. Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision, as applicable.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. See the GDPR pagefor details and how to make a request. If we process your data as a processor on an Owner’s behalf, we will direct your request to that Owner or assist them in fulfilling it.
10. Cookies
We use a single essential cookie to keep Owners signed in to the dashboard. We do not use cookies for third-party advertising. If we introduce analytics or other non-essential cookies in future, we will update this policy and seek consent where required.
11. Children
AuthRobo is not directed to children and is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, communicated to you.
13. Contact us
For privacy questions or requests, contact privacy@authrobo.com. Data controller: [AuthRobo legal entity name], [registered address].