1. Introduction
Sudomimus is an identity provider and authentication platform that helps applications verify the identity of their users without managing passwords. We act both as the service you sign in with and as an identity provider that, under your control, passes a limited set of identity details to the applications you choose to sign into. Sudomimus also offers a developer and organization platform where businesses register applications and manage how their users sign in.
This Privacy Policy explains what information we collect when you use Sudomimus, how we use it, how and when we share identity details with applications, and the choices available to you.
2. Information We Collect
Account information: when you sign up, we store your email addresses and a unique internal account identifier. We also store your name if you provide it. An account can have several verified email addresses. You can mark one as primary.
Authentication credentials: for passkey sign-in, we store the public key of your WebAuthn credential. We also store details such as its name and creation date. We do not store the private key; it stays on your device. For email sign-in, we store the information needed to issue and verify one-time codes.
Connected third-party and native logins: if you sign in with Google, GitHub, Discord, Battle.net, or X, we store the subject identifier that the provider assigns to you. We also store basic profile details, such as an email address or username, that the provider returns during sign-in. For Steam, we store your Steam ID. If Family Sharing applies, we also store the owning Steam ID. If you use an access key for native-client authentication, we store the records needed to validate it.
Identity claims you choose to share: you can allow individual applications to receive your email address, first name, or last name. We record your choices so that we can apply and revoke them. See "Sharing Your Identity With Applications" below.
Authentication logs: we record authentication attempts for security monitoring, abuse prevention, and debugging. Each record includes a timestamp, originating origin, success or failure, and a general reason.
Device information: when you authenticate, we may record the request's user-agent string and IP address for the purposes described above.
Developer and organization information: if you create an organization or register an application, we store the details you provide. These include organization and application names, configuration, sign-in rules, adopted email domains, and federation connector settings. We also store credentials you supply for those connectors.
3. How We Use Information
We use this information to provide and operate the authentication service and the developer and organization platform. We use it to verify your identity during sign-in and share only the identity details you have authorized with applications you sign into.
We also use this information to detect, investigate, and prevent fraud, abuse, and security incidents. We use it to communicate with you about your account and the service, and to comply with legal obligations.
We do not use your information to build advertising profiles. We do not sell your information to third parties.
4. Sharing Your Identity With Applications
When you sign into an application through Sudomimus, the application does not receive your internal account identifier or your raw email address by default. Instead, it receives a purpose-scoped, opaque identifier that is unique to that application (or group of applications). That identifier cannot be linked back to you, or correlated against unrelated applications, without information only Sudomimus holds.
Beyond that opaque identifier, an application receives personal details — your email address, first name, or last name — only if you have explicitly granted them. Claim sharing is off by default: nothing is shared until you grant it, and you can revoke a grant at any time, after which the application stops receiving that detail on subsequent sign-ins. Some applications mark certain claims as required; if you decline a required claim you may be unable to complete sign-in to that application, but the choice remains yours.
Where an application signs you in using the OpenID Connect protocol, the identity details returned are further limited to the scopes that application requested and you authorized.
5. Organization-Managed and Enterprise Sign-In
If the organization that controls your email domain (for example, your employer) has adopted that domain with Sudomimus, it can influence how accounts using addresses on that domain sign in. An organization may require that sign-ins for its domain go through its own enterprise identity provider (single sign-on), or it may block Sudomimus sign-in for that domain entirely.
When you sign in through such an enterprise identity provider, identity details such as your verified email address are exchanged between that provider and Sudomimus to establish your identity. Your organization may be able to see that, and when, you authenticate through its provider. These controls apply only to addresses on a domain the organization has verified it controls.
6. Cookies and Browser Storage
Sudomimus uses cookies and browser storage for sign-in and account access. Depending on the service and the action you take, cookies may hold sign-in credentials or protect a sign-in flow. Browser session storage may hold temporary state needed to complete a sign-in. These items support the authentication or account access you request.
Sudomimus also uses cookies or browser local storage to remember language and appearance preferences. These preferences help the site display your choices on later visits. They are separate from sign-in credentials.
You can clear these items using your browser controls. Clearing sign-in cookies may require you to sign in again. Clearing temporary flow state may interrupt a sign-in in progress. Clearing language or appearance preferences resets those choices; it does not itself sign you out. Clearing browser storage does not by itself revoke a server-side session.
7. Data Retention
We retain account information for as long as your account exists. Records used for fraud prevention and security investigations may be retained for up to 180 days. When you delete your account, we delete or anonymise associated personal data within a reasonable time, except where retention is required by law.
If we permanently discontinue the Service, we will explain the available account-data options when reasonably practicable. We will delete or anonymise remaining personal data within a reasonable time, except where retention is needed for security investigations or required by law. You may contact us about your data if the account controls are no longer available.
8. Service Providers
We do not sell your personal information. To operate the service we rely on a small number of service providers, such as a transactional email provider for delivering one-time codes and account notifications, and cloud infrastructure providers for hosting. These providers process information only on our instructions.
Separately from these providers, when you choose to sign in through a third-party login (such as Google, GitHub, Discord, Battle.net, X, or Steam) or through an organization's enterprise identity provider, information is exchanged with that party to complete sign-in, subject to that party's own privacy policy. How we share your identity details with the applications you sign into is described in "Sharing Your Identity With Applications" above.
9. Your Rights
Depending on your location, you may have rights to access, correct, export, or delete the information we hold about you, and to object to or restrict certain processing. You can review and revoke the identity details shared with each application, and manage your connected third-party logins, directly in product. Account deletion is also available directly in product — see the next section. To exercise the other rights, or if the in-product flow does not work for your situation, contact us at the address below. We will respond within the timeframe required by applicable law.
10. Deleting Your Account
To permanently delete your Sudomimus account, visit the Privacy view at with.sudomimus.com/privacy and use the "Delete my account" control in the Danger Zone. We ask you to re-type your email address (or display name, for accounts without an email) to confirm.
When you delete your account, we erase the personal data we hold about you: your name, email address records, passkey public keys, third-party login subject identifiers (Google, GitHub, Discord, Battle.net, X, and Steam), any access keys you registered, and the per-application claim-sharing choices you made. Records used for fraud prevention and security investigations may be retained for up to 180 days.
Already-issued access tokens are not actively revoked — they expire by their normal short-lived TTL (typically a few hours). Refresh tokens are revoked immediately.
If you are the sole active owner of an organization that still holds live applications or sectors, you must retire those resources or add another active owner before deleting your account. The in-product flow tells you which organizations or applications are blocking deletion. We will not silently delete other people's data along with yours.
Account deletion is irreversible. Once erased, an account cannot be recovered; signing up again with the same email creates a fresh, unrelated account.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date on this page when we publish a new version. When appropriate, we will also notify you through the Service. This policy explains our data practices; it does not treat continued use as consent to every kind of data processing.
12. Contact
Questions about this Privacy Policy or our privacy practices can be sent to [email protected].