Last updated 2026-09-22

Privacy policy

This policy explains what MyLogin.world collects when you use it as an app owner or when you sign in to a service that uses it, and what happens to that data.

What we collect when you sign in

The identity claims your chosen provider releases: a provider subject identifier, your email address and whether the provider marks it verified, your display name, and your profile picture. We also record the time, the service you signed in to, the verification mode used, and the IP address and browser user agent of the request. Provider access tokens are used once to read those claims and are then discarded; they are never stored and never passed to the service you sign in to.

Passkeys and second factors

For passkeys we store the credential identifier, the public key, a friendly name, and usage counters. For authenticator apps we store the shared secret encrypted at rest and hashed recovery codes. We never receive your passkey private key.

What we collect from app owners

Your account identity as above, the services and instances you create, the public keys of your instances, provider credentials you choose to store (encrypted at rest), access policies, and an audit log of changes and security events with timestamps and IP addresses. Payment details are handled by the payment provider you choose; we store the subscription identifier, status, and payment history they report, not card or bank details.

Identifiers

Each service receives a pairwise subject identifier derived for that service alone. Services cannot correlate you with each other through MyLogin.world.

How we use data

To run sign-ins, to let app owners manage access to their services, to detect abuse and enforce rate limits, to send security and billing notifications, and to keep an audit trail. We do not sell data, do not build advertising profiles, and do not track you across services.

Sharing

Identity providers receive the authentication request you initiate. The service you sign in to receives the claims its owner has enabled and a signed result. Payment providers receive what they need to process a subscription. Nobody else receives your data unless the law requires it.

Retention

Expired sign-in requests are deleted within 24 hours. Session records are deleted when they expire or when you sign out. Audit history is kept for the period of the account plan (currently 30 days on Personal and 365 days on Supporter). Everything else is kept while the account exists.

Your controls

App owners can export their configuration and delete their account from the dashboard. Anyone can remove linked login methods, passkeys, and second factors from their MyLogin.world account page, and can delete the account itself. Deletion removes the data described above; audit entries that reference a deleted account keep only an opaque identifier.

Cookies

We use a session cookie on our own domains so you stay signed in, and a short-lived cookie during a sign-in to bind the request to your browser. No third-party or advertising cookies.

Security

Data is encrypted in transit. Secrets at rest are encrypted with keys held on our infrastructure. Report vulnerabilities via the disclosure page.

Changes and contact

We will update the date above when this policy changes and note material changes on the status page. Questions: support@mylogin.world.compas.cs.stonybrook.edu.