Privacy Policy
Effective October 6, 2026 · Last updated October 6, 2026
AnyOAuth provides social sign-in infrastructure. This Privacy Policy explains how we handle information when you visit our website, create an AnyOAuth account, or sign in to an application that uses AnyOAuth.
Information we collect
- Account and identity information. When you sign in with Google, GitHub, or another supported provider, we receive the identity information supplied by that provider. This may include a provider account identifier, name, username, email address, email verification status, and profile image URL. Fields that the provider does not supply may be empty.
- Application settings. We store project names, registered callback URLs, enabled providers, project identifiers, and the association between projects and their owners.
- Sign-in and security information. We process sign-in timestamps, authorization transactions, session information, token hashes, and request information needed to operate and protect the service. Our hosting infrastructure may process IP addresses, request metadata, and diagnostic logs.
- Communications. If you contact us or join our early-access list, we process the information you provide, your contact details, and records needed to deliver and track service emails.
We do not collect your Google, GitHub, or other provider passwords. You enter those credentials directly with the provider. Provider access tokens are used server-side to complete sign-in; we do not persist them in our application database or return them to customer applications.
How we use information
We use information to authenticate accounts, provide a consistent identity profile to the application you choose to sign in to, operate the dashboard, manage projects, send account or requested early-access communications, respond to support requests, and prevent abuse or unauthorized access.
Where applicable data-protection law requires a legal basis, we rely on performing our agreement with you, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where required. You can withdraw consent where processing relies on it.
Google user data
Google sign-in requests basic identity scopes: openid, profile, and email. We use this information for sign-in and identity profiles. We do not request access to your Gmail messages, Drive files, contacts, or calendar.
AnyOAuth’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, sell it, or use it to train generalized artificial intelligence or machine-learning models.
When information is shared
- The application you sign in to. We provide your normalized identity profile to that application after you complete its sign-in flow. Its operator controls what happens to your information within its own service, under its own privacy policy.
- Your identity provider. We communicate with the provider you choose to verify your identity and complete authorization. Its handling of your information is governed by its privacy policy.
- Service providers. Cloudflare provides hosting, database storage, networking, and security infrastructure. MailKite provides service-email delivery and related message handling. These providers process information needed to provide their services.
- Legal and security purposes. We may disclose information when required by law or reasonably necessary to protect the service, investigate abuse, or protect people’s rights and safety.
We do not sell personal information or share it for cross-context behavioral advertising.
Cookies and local storage
We use cookies to bind sign-in requests to the initiating browser, maintain authenticated sessions, and protect the authorization flow. The dashboard may store your theme preference locally in your browser. These functions support sign-in and interface preferences, rather than advertising. Blocking essential cookies may prevent sign-in from working.
Retention and deletion
We retain account information, project settings, and identity profiles while needed to provide the service, until they are deleted, or as necessary for legal and security purposes. Expired authorization transactions, handoff codes, profile tokens, sessions, and rate-limit records are removed by scheduled cleanup. Expiration of a token does not by itself delete the associated profile.
Project owners can delete project identities or entire projects in the dashboard. Deleting an identity removes its stored profile and dependent profile tokens and handoff codes from the active application database. It does not delete data already held by the application you signed in to, end that application’s own sessions, or delete your account with the identity provider.
To request deletion of your AnyOAuth account, early-access entry, or other information we hold, email hello@anyoauth.com. We may need to verify your identity. Infrastructure backups and operational records can have separate retention cycles; some information may be retained where required by law or necessary to resolve disputes or prevent abuse.
Security and international processing
We use measures including HTTPS, exact callback allowlists, browser-bound state, PKCE, project ownership checks, hashed secrets and tokens, and short-lived profile access tokens. No system is completely secure. Read our security model for the technical boundaries.
Our infrastructure and service providers may process information outside your country. Where applicable law requires safeguards for international transfers, those requirements apply to that processing. Contact us if you need information about processing locations or a data-processing agreement before using AnyOAuth for your application.
Your choices and rights
Depending on your location and applicable law, you may have rights to access, correct, delete, or receive a copy of your personal information, restrict or object to processing, withdraw consent, or complain to a data-protection authority. Contact hello@anyoauth.com to make a request. We do not discriminate against people for exercising applicable privacy rights.
For information held by an application using AnyOAuth, contact that application’s operator. We process application-user identities to provide its sign-in integration; the operator is responsible for its own user records, permissions, sessions, and downstream data use. You can also remove AnyOAuth’s access through your identity provider’s account settings; this does not automatically delete previously stored information.
Children
AnyOAuth’s developer website and dashboard are not directed to children under 13. If you believe a child has provided us personal information without the necessary authorization, contact us so we can investigate and address it. Applications using AnyOAuth are responsible for their own age requirements and parental-consent obligations.
Changes to this policy
We may update this policy as the service changes. We will update the date on this page and provide additional notice of material changes where required by law.
Contact
Questions about this policy or the service? Contact AnyOAuth at hello@anyoauth.com.