Skip to content

AUTHOMETRY LEGAL

Privacy Policy

This policy explains what information Authometry handles when you use the hosted service, sign in with Google or GitHub, or authorize an application.

Effective July 17, 2026

Who operates Authometry

Authometry is an open-source OAuth 2.0 and OpenID Connect service operated through the Authometry project. Questions about this policy or personal information can be sent to auth@cams.ch3n.cc. The source code and issue tracker are available on GitHub.

Information we collect

  • Account and identity information, such as your name, email address, account identifier, workspace membership, role, and verification status.
  • Google sign-in information limited to the OpenID, email, and profile scopes. This can include your Google account identifier, name, email address, and email-verification status.
  • GitHub sign-in information limited to your basic profile and email scopes. This can include your GitHub account identifier, display name, username, and a verified email address.
  • OAuth activity, including the requesting application, requested permissions, consent decisions, sessions, authorization outcomes, and security traces. Secret-bearing fields are redacted before trace storage.
  • Service and security data, such as IP address, browser user agent, timestamps, request identifiers, audit events, and error details.
  • Configuration and content that workspace administrators submit, including application, policy, scope, webhook, and environment settings.

How we use information

We use this information only to:

  • authenticate users and link the correct identity to a workspace;
  • process OAuth and OpenID Connect requests and record consent;
  • operate, secure, troubleshoot, and improve the service;
  • prevent abuse, investigate incidents, and comply with legal obligations; and
  • communicate service, account, recovery, and security information.

Authometry does not sell personal information and does not use Google or GitHub user data for advertising. Provider access tokens are used to retrieve the identity information described above during sign-in and are not stored by Authometry.

Sharing and service providers

Information may be processed by infrastructure, database, email-delivery, security, and hosting providers that help operate Authometry. We may also disclose information when required by law, to protect users or the service, or during a business transfer. A workspace's administrators can access identity, authorization, and audit information belonging to that workspace.

When you authorize a third-party OAuth application, Authometry shares only the information covered by the permissions displayed on the consent screen and that you approve. That application's own privacy policy governs its later use of the information.

Retention and security

We keep information for as long as needed to provide and secure the service, meet legal obligations, resolve disputes, and enforce agreements. Workspace-configured retention settings control authorization traces and audit events. Residual copies may remain for a limited period in encrypted backups and security records.

Authometry uses encryption in transit, restricted administrative access, signed sessions, CSRF protection, rate limits, exact redirect validation, PKCE, secret redaction, and other safeguards. No online service can guarantee absolute security.

Your choices and deletion

You can revoke Authometry's Google or GitHub access from your provider account settings. Revoking access prevents future provider sign-ins but does not automatically delete the Authometry identity previously created.

You may request access, correction, export, or deletion of your personal information. See the data deletion instructions. Some records may be retained where required for security, fraud prevention, legal compliance, or the rights of others.

International use and children

Authometry may process information in countries other than your own. The service is not directed to children under 13, and we do not knowingly collect their personal information.

Changes to this policy

We may update this policy as the service or legal requirements change. The effective date above identifies the current version. Material changes will be communicated through the service or repository when appropriate.