1. Overview
This Privacy Policy explains how GeniusAuth ("GeniusAuth", "we", "us", or "our") collects, uses, discloses, and protects information in connection with our authentication, authorization, profile, transactional communications, and payments platform (the "Service"), our website, and related applications.
GeniusAuth plays two different roles depending on the data involved:
- For information about our customers — the developers and organizations who sign up for an account — we act as a data controller.
- For the end-user data our customers collect and process through the Service (their users' logins, profiles, and events), we act as a data processor acting on our customer's instructions. In that context, the customer is the controller and is responsible for the lawful basis and notices given to their end users.
By using the Service you acknowledge the practices described here. If you do not agree, please do not use the Service.
2. Who we are & how to reach us
GeniusAuth is operated by [Legal Entity Name], located at [Registered Address]. For any privacy question, request, or complaint, contact us at privacy@geniusauth.com or through our contact page.
If we are required to designate a data protection officer or an EU/UK representative for your jurisdiction, their details will be published here.
3. Information we collect
Account and contact data
When you create an account we collect your name, email address, organization name, and authentication credentials (passwords are stored only as salted, hashed values — never in plaintext). If you contact us, we keep the content of your message and our correspondence.
Customer end-user data (processed on your behalf)
When you build on the Service, we store and process the end-user records you send us — such as identifiers, email addresses, hashed credentials, profile fields you define, roles and permissions, and authentication events (sign-ins, refreshes, password resets). We process this data solely to provide the Service to you and on your instructions.
Usage, device, and log data
We automatically collect technical information needed to operate and secure the Service: IP address, approximate location derived from IP, browser and device details, request timestamps, API endpoints called, and diagnostic logs. Authentication and security events are recorded to detect abuse, prevent account takeover, and meet audit obligations.
Location data
We derive approximate geographic location (city/country level) from IP addresses using an offline geolocation database bundled with the Service. This lookup happens locally — IP addresses are not sent to a third party for geolocation. Location is used for security signals (e.g. unusual-location alerts) and shown in session and event history.
Payment data
If you subscribe to a paid plan or use our payments features, billing is handled by a PCI-DSS-compliant payment processor. We receive limited billing details (such as the last four digits and card brand, billing address, and transaction status) but do not store full card numbers on our systems.
Cookies
We use strictly necessary cookies to keep you signed in and to secure sessions, and a minimal set of preference cookies (such as light/dark theme). See Cookies & tracking below.
4. How we use information
We use information to:
- provide, maintain, and improve the Service and its features;
- authenticate users, manage sessions, and enforce roles and permissions;
- send transactional messages (verification, password reset, one-time codes, security notices, and receipts);
- detect, investigate, and prevent fraud, abuse, and security incidents;
- provide support and respond to your requests;
- process payments and manage billing;
- comply with legal obligations and enforce our agreements.
We do not sell personal information, and we do not use customer end-user data to build advertising profiles or train models for unrelated purposes.
5. Legal bases for processing (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract — to provide the Service you have signed up for and to bill you.
- Legitimate interests — to secure the Service, prevent abuse, and improve our product, balanced against your rights.
- Legal obligation — to meet tax, accounting, and other legal requirements.
- Consent — where required, for example certain optional communications; you may withdraw consent at any time.
For customer end-user data we process as a processor, the customer (controller) is responsible for establishing the lawful basis for that processing.
7. Data retention
We keep information for as long as your account is active and as needed to provide the Service. Security and audit logs are retained according to your plan (7, 30, or 90 days, or as negotiated). After account closure we delete or anonymize personal data within a commercially reasonable period, except where longer retention is required for legal, tax, security, or dispute-resolution purposes.
Customers can delete end-user records and account data through the Service; deletions propagate to backups on our standard backup-rotation cycle.
8. Security
We take the security of identity data seriously. Measures include encryption in transit (TLS), encryption of sensitive data at rest, credential hashing, isolated key storage, least-privilege access controls, refresh-token rotation with reuse detection, optional same-IP session binding, and continuous logging and monitoring.
No system is perfectly secure. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities as required by law and without undue delay.
9. International data transfers
We operate primarily on EU-based infrastructure. Where information is transferred across borders — for example to a backup email provider — we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. Contact us for details of the safeguards applied to a specific transfer.
10. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; and to withdraw consent. To exercise these rights, contact privacy@geniusauth.com. We will verify your identity and respond within the timeframe required by law.
EEA/UK residents may lodge a complaint with their local supervisory authority.
California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information. We do not sell personal information. We will not discriminate against you for exercising your rights.
If you are an end user of one of our customers, please direct your privacy requests to that customer (the controller of your data); we will assist them in responding.
11. Customer responsibilities & data processing
Customers who use GeniusAuth to process their end users' personal data are responsible for: providing appropriate privacy notices to their end users; establishing a lawful basis for processing; obtaining any required consents; and honoring their end users' rights. Our processing of end-user data is governed by our Data Processing Addendum ("DPA"), available on request, which forms part of your agreement with us and describes our obligations as a processor, including confidentiality, sub-processing, security, and assistance with data-subject requests.
13. Children's privacy
The Service is intended for developers and businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it. Customers are responsible for compliance with children's-privacy laws (such as COPPA) that apply to their own end users.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date and, where appropriate, notify you by email or through the Service. Your continued use of the Service after an update means you accept the revised policy.
15. Contact us
Questions, requests, or complaints about privacy? Email privacy@geniusauth.com or reach out through our contact page. We're happy to help.