1. Information We Collect
When you register or sign in using Single Sign-On (SSO), we collect necessary account information including your display name, email address, password hash, and OAuth provider profile identifiers (e.g. Google, Facebook, X) where applicable.
We record security audit telemetry (IP addresses, login timestamps, user-agent details) strictly to protect your account against unauthorized access, credential stuffing, and brute-force attacks.
2. How We Use Information
- Authentication & Authorization: Verifying identity, maintaining session integrity across connected SSO services, and issuing OIDC tokens.
- Security & Incident Prevention: Monitoring failed login attempts, detecting anomaly patterns, and enforcing rate limiting.
- Communication: Sending critical security alerts, password reset verification links, and account change notices.
3. Data Protection & Encryption
Passwords are never stored in plain text; they are hashed using salted cryptographic algorithms (bcrypt). Sensitive OAuth tokens are encrypted at rest with AES-256-GCM. All communication across our services enforces HTTPS with TLS 1.3 encryption.
4. Third-Party Sharing
We do not sell, rent, or trade your personal data. Data is only shared with authorized OIDC client applications that you explicitly consent to connect to your SSO account.