Privacy Policy
Last updated: July 21, 2026
1. Introduction and Scope
LoginMe ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and protect your personal information when you use our authentication and Customer Identity and Access Management (CIAM) services.
This Privacy Policy applies to:
- Users who register accounts and use our authentication services
- Organizations and their administrators who use our platform
- Visitors to our website and users of our services
By using LoginMe, you acknowledge that you have read and understood this Privacy Policy and agree to the collection and use of your information as described herein.
2. Data Collection Practices
2.1 Information We Collect
We collect the following types of personal data:
- Account Information: Email address, password (hashed), and account metadata
- Identity Information: User ID, email address, and profile information from OAuth providers (Google, GitHub, Facebook, Microsoft, Apple)
- Organization Data: Organization name, API keys, configuration settings, and usage statistics
- Authentication Data: JWT tokens, session information, and authentication event logs
- Technical Data: IP addresses, device fingerprints, browser type, and usage analytics
- Communication Data: Support requests, feedback, and correspondence
2.2 How We Collect Information
We collect information through:
- Direct submission when you register, create an account, or use our services
- OAuth providers when you authenticate using social login (Google, GitHub, Facebook, Microsoft, Apple)
- Automatic collection through cookies, logs, and analytics tools
- API usage and service interactions
3. Data Processing Purposes
We process your personal data for the following purposes:
- Service Provision: To provide authentication services, user management, and access control
- Account Management: To create and manage your account, organizations, and API keys
- Authentication: To verify your identity and enable secure access to applications
- Security: To protect against fraud, abuse, and unauthorized access
- Compliance: To comply with legal obligations and regulatory requirements
- Support: To respond to your inquiries and provide customer support
- Analytics: To improve our services, analyze usage patterns, and optimize performance
4. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR) and applicable data protection laws, we process your personal data based on:
- Contractual Necessity: Processing necessary to perform our contract with you and provide our services
- Legitimate Interests: Processing for our legitimate business interests, such as security, fraud prevention, and service improvement
- Legal Obligations: Processing required to comply with applicable laws and regulations
- Consent: Where you have provided explicit consent for specific processing activities
5. Data Retention Policies
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law:
- Account Data: Retained while your account is active and for up to 30 days after account deletion
- Authentication Logs: Retained for up to 90 days for security and audit purposes
- Organization Data: Retained while the organization is active and for up to 30 days after termination
- Legal Requirements: Some data may be retained longer if required by law or for legal proceedings
Upon request, we will delete your personal data in accordance with applicable data protection laws, subject to legal retention requirements.
6. Your Rights (GDPR Article 15 & CCPA)
You have the following rights regarding your personal data:
6.1 GDPR Rights (EU/EEA Users)
- Right of Access: Request a copy of your personal data we hold
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of how we process your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent where processing is based on consent
6.2 CCPA Rights (California Users)
- Right to Know: Request disclosure of personal information collected, used, or sold
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt-out of the sale of personal information (we do not sell personal information)
- Right to Non-Discrimination: Exercise your rights without discrimination
6.3 How to Exercise Your Rights
To exercise your rights, please contact us at:
Email: authlessclient@gmail.com
Subject Line: "Privacy Rights Request"
We will respond to your request within 30 days (or as required by applicable law).
7. Data Sharing and Sub-Processors
7.1 Sub-Processors
We use the following sub-processors to provide our services:
- OAuth Providers: Google, GitHub, Facebook, Microsoft, Apple (for social authentication)
- Cloud Infrastructure: [Cloud Provider Name] (for hosting and data storage)
- Email Services: [Email Service Provider] (for transactional emails)
- Analytics: [Analytics Provider] (for service analytics and monitoring)
All sub-processors are bound by contractual obligations to protect your data and comply with applicable data protection laws.
7.2 Data Sharing
We do not sell, rent, or trade your personal data. We may share your data only:
- With sub-processors necessary to provide our services (as listed above)
- When required by law or legal process
- To protect our rights, property, or safety, or that of our users
- With your explicit consent
8. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) or your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): We use EU-approved SCCs for data transfers
- Adequacy Decisions: We transfer to countries with adequacy decisions where applicable
- Binding Corporate Rules: Where applicable, we rely on approved binding corporate rules
By using our services, you consent to the transfer of your data to countries outside your jurisdiction, subject to the safeguards described above.
9. Security Measures
We implement industry-standard security measures to protect your personal data:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure token handling and JWT management with per-organization secrets
- Multi-tenant data isolation and access controls
- Regular security audits and vulnerability assessments
- SOC 2 compliance standards
- GDPR and privacy compliance measures
- Access controls and authentication requirements
While we implement robust security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data.
10. Cookie Policy
We use cookies and similar technologies to:
- Maintain your session and authentication state
- Remember your preferences and settings
- Analyze service usage and performance
- Provide security features and fraud prevention
Types of Cookies:
- Essential Cookies: Required for service functionality (cannot be disabled)
- Analytics Cookies: Help us understand how you use our services (can be disabled)
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect service functionality.
11. Contact Information for Privacy Inquiries
For privacy-related inquiries, data protection requests, or questions about this Privacy Policy, please contact us:
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. We will notify you of material changes by:
- Posting the updated Privacy Policy on our website
- Updating the "Last updated" date at the top of this policy
- Sending email notifications for significant changes (where applicable)
Your continued use of our services after changes become effective constitutes acceptance of the updated Privacy Policy.