Legal
Privacy policy
Last updated: October 11, 2026
This policy explains what data MicroAuth collects, why, and what happens to it. MicroAuth is operated by Zyref, LLC ("we", "us"). The short version: we collect what we need to run the Service, we don't run advertising trackers, we don't sell data, and by design we never see the traffic flowing through your API.
1. The one thing we don't collect
MicroAuth isn't a proxy. Requests from your customers go directly to your servers. What reaches us is data you or our SDK send on purpose: configuration, account details and usage items containing an API key ID, a status code, a count, a timestamp, the pricing policy that admitted the request and an identifier that makes retries safe. We never receive your API request bodies, request headers, query parameters or response bodies.
2. Data we collect and why
Account data
- Your name and email address, to create and secure your account.
- Your password, stored only as a salted bcrypt hash. We can't read it.
- Two step verification data, if you turn it on. The secret is encrypted and recovery codes are stored as hashes.
Workspace and API data
- Workspace names, API settings, branding you upload (such as logos), pricing, plans and custom domain settings, because that is the product.
- If you connect Stripe, your Stripe account ID and its display name. Stripe Connect never gives us your Stripe password, and we don't keep secret keys for your account.
Usage and billing data
- Request counts per API key per hour, credit balances and ledger entries, to run metering and billing.
- Payment records for your MicroAuth plan. Card details are handled entirely by Stripe, and we never see full card numbers.
Security data
- IP addresses, browser user agents and timestamps for sign ins and other security events, used for rate limiting and the activity log.
- An activity log of significant actions in your workspace and its APIs, such as who created a key or changed a price, visible to your team.
3. Your customers' data
People who sign up on your developer portal are your customers. For their data (name, email, password hash, keys, usage and billing records) you are the controller, and we process it on your behalf to provide the Service. We only email your customers for things their own account needs, such as sign in codes, invitations, receipts and balance alerts, and we don't use their data for anything else.
4. Cookies
We use first party cookies only, and only to keep you signed in: an HTTP only session cookie for the dashboard, and one for each developer portal you sign in to. There are no advertising cookies and no third party analytics on the website, the dashboard or the portals.
5. Who else handles the data
We use a small set of providers to run the Service:
- Stripe, for payments and subscriptions.
- Brevo, for email such as sign in codes, invitations and billing notices.
- Cloudflare, for DNS.
- A hosting provider, for the server and database the Service runs on.
Each one processes data only as needed for its role. We don't sell personal data, and we don't share it with data brokers or advertising networks.
6. Security
- All traffic is encrypted with TLS, including portals on custom domains.
- Passwords are hashed with bcrypt, and API keys are stored as SHA-256 hashes.
- Secrets we need to read again, such as SDK secrets and two step verification secrets, are encrypted at rest.
- Sessions use HTTP only cookies, and every request that changes data is checked against the site it came from.
No system is perfectly secure. If we learn of a breach affecting your data, we'll tell you without undue delay. Please report vulnerabilities to security@microauth.com.
7. Retention and deletion
- Account, workspace and API data is kept while your account is active.
- Processed Stripe webhook events are deleted after 90 days.
- Usage receipts, kept so duplicate reports are ignored, are deleted after about 45 days.
- Hourly usage and the activity log are kept for 13 months.
- Expired sessions, sign in codes and invitations are deleted shortly after they expire.
- Ledger entries and payment records have no age limit while the account exists, because they back up billing, disputes and tax records.
- Daily database backups are kept for 14 days, so deleted data can remain in backups for up to 14 days.
The security page has more detail.
8. Your rights
You can view and update most of your data directly in the dashboard, and export your activity log as CSV or read your data through the API. Depending on where you live, you may also have rights to access, correct, delete or port your personal data, or to object to some processing. Email privacy@microauth.com and we'll handle your request. If your customers contact us about data you control, we'll refer them to you and help you respond.
9. International transfers
Our providers may store or process data in the United States and other countries. Where required, we rely on appropriate safeguards such as our providers' standard contractual clauses.
10. Children
The Service isn't directed at children and may not be used by anyone under 16. We don't knowingly collect data from children.
11. Changes to this policy
If we change this policy in a way that matters, we'll email account owners or show a notice in the dashboard before the change takes effect. The date at the top tells you when it was last revised.
12. Contact
Privacy questions go to privacy@microauth.com. MicroAuth is a product of Zyref, LLC.