Working draft — not yet legal advice. This document is provided as groundwork and is pending review by qualified counsel. Do not rely on it as a final agreement until that review is complete.

Privacy Policy

Last updated: July 2, 2026

This Privacy Policy explains how AuthRobo(“AuthRobo”, “we”, “us”) collects, uses, discloses, and protects personal data. AuthRobo provides authentication and Stripe-synced billing infrastructure that other applications (“Customer Apps”) integrate to sign in and manage their own users. Your privacy matters to us, and we only collect personal data we genuinely need to provide the service.

1. Our two roles: controller and processor

Because of how AuthRobo works, we act in two distinct capacities under data-protection law:

  • Data controller— for the accounts of developers and organisations who sign up to the AuthRobo dashboard (“Owners”). We decide how that account data is processed.
  • Data processor— for the end-user data that Owners collect through their Customer Apps (for example, the people who register or sign in to an app that uses AuthRobo). Here the Owner is the controller and decides why the data is processed; we process it only on the Owner’s instructions to deliver the service.

If you are an end user of an app that uses AuthRobo and you have questions about your data, please contact that app’s operator (the controller) in the first instance. We will assist them in responding to your request.

2. Information we collect

Owner account data (we are the controller)

  • Name, email address, and profile image (for example, from Google sign-in).
  • Account and plan details, including your AuthRobo subscription status.
  • Billing identifiers held by our payment processor (we do not store card numbers).

End-user data (we are the processor, on the Owner’s behalf)

  • End-user email address and name, and profile image where provided.
  • Authentication credentials in protected form — passwords are stored only as one-way hashes; we never store plaintext passwords.
  • Linked sign-in identities (for example, a Google account identifier).
  • Session records and subscription/plan data synced from the Owner’s Stripe account.

Technical data

  • Log and diagnostic data such as timestamps and request metadata, used to operate and secure the service.
  • An essential session cookie set on the AuthRobo dashboard to keep you signed in.

3. How we use personal data

  • To provide, maintain, and secure the authentication and billing service.
  • To authenticate users and issue and verify access tokens.
  • To process Owner subscriptions and keep Customer App subscription data in sync.
  • To communicate service and account information (for example, a welcome email on sign-up).
  • To detect, prevent, and respond to abuse, fraud, and security incidents.
  • To comply with legal obligations.

4. Legal bases for processing

Where the GDPR or similar laws apply, we rely on the following legal bases:

  • Contract — to provide the service you or the Owner have requested.
  • Legitimate interests — to secure, maintain, and improve the service.
  • Legal obligation — where processing is required by law.
  • Consent — where you have given consent for a specific activity.

See our GDPR page for a fuller explanation of your rights and how to exercise them.

5. Sharing and sub-processors

We do not sell personal data. We share it only with service providers who help us operate AuthRobo, and only as needed to deliver the service. Current sub-processors:

ProviderPurposeRegion
NeonManaged PostgreSQL database (data storage)Sydney, Australia
VercelApplication hosting and content deliveryGlobal
StripePayment processing and subscription dataGlobal
GoogleOAuth sign-in (where enabled)Global
[Email delivery provider]Transactional email[Region]

We may also disclose data where required by law or to protect our rights and the safety of others.

6. Data retention

  • Owner account data — retained while the account is active and for up to 90 days after deletion, then removed.
  • End-user data — retained for as long as the relevant Owner instructs; deleting an end user or an app removes the associated records.
  • Billing records — retained as required for financial and legal compliance.
  • Logs — retained for a limited period for security and operational purposes.

7. How we protect data

We apply technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (TLS) and encryption at rest for stored data.
  • One-way hashing of passwords (bcrypt) — plaintext passwords are never stored.
  • RS256-signed access tokens verified against a published JWKS.
  • Authenticated encryption (AES-256-GCM) of sensitive secrets such as connected payment keys.
  • Strict per-application (tenant) isolation so one Owner cannot access another’s data.
  • Access controls and least-privilege access to production systems.

8. International data transfers

We and our sub-processors may process personal data in countries other than your own. Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision, as applicable.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. See the GDPR pagefor details and how to make a request. If we process your data as a processor on an Owner’s behalf, we will direct your request to that Owner or assist them in fulfilling it.

10. Cookies

We use a single essential cookie to keep Owners signed in to the dashboard. We do not use cookies for third-party advertising. If we introduce analytics or other non-essential cookies in future, we will update this policy and seek consent where required.

11. Children

AuthRobo is not directed to children and is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, communicated to you.

13. Contact us

For privacy questions or requests, contact privacy@authrobo.com. Data controller: [AuthRobo legal entity name], [registered address].