Privacy notice

Last updated 24 July 2026

This notice covers Authly ID — the account you use to sign in. Apps that accept an Authly ID publish their own notices for whatever they do with your data after you sign in.

What we collect

Creating an Authly ID stores only what is needed to identify you and let you sign in:

  • Account details — your email address, and your first and last name if you provide them.
  • Credentials — a salted hash of your password (never the password itself), plus any authenticator app or passkey you choose to register.
  • Preferences — your chosen interface language.
  • Linked accounts — if you sign in with Google, the identifier Google gives us for you and the email address on that account.
  • Sign-in activity — the IP address, browser and device of your active sessions, and a short log of authentication events (sign-in, sign-out, failed attempts).

We do not collect payment details, and we do not sell or share your data with advertisers.

Why we process it

Account details and credentials are processed to perform the service you asked for — giving you a single sign-in across connected apps. Sign-in activity and authentication events are processed on the basis of our legitimate interest in keeping accounts secure: they are what let us detect brute-force attempts and let you spot a session you do not recognise.

What connected apps see

When you sign in to an app with your Authly ID, that app receives your user identifier, your email address, your name, and whether your email is verified. It does not receive your password, your two-factor secrets or your passkeys — those never leave Authly ID.

You can review every app that has access, and revoke it, from the Applications page of your account.

Who else is involved

Authly ID runs on servers we operate in the EU (Hetzner, Nuremberg, Germany). Transactional email — address verification and password resets — is delivered by Brevo. Anonymous, cookie-free usage statistics are collected by a self-hosted Umami instance on our own infrastructure; no third-party analytics or advertising trackers are loaded.

How long we keep it

Your account details are kept for as long as your Authly ID exists. Authentication event logs are kept for 7 days. Sessions expire automatically after 10 hours, or 30 minutes of inactivity.

Your rights

Under the GDPR you can access, correct, export, restrict or erase your personal data, and object to processing based on legitimate interest.

  • Access and correct — the Personal info page of your account.
  • Erase — the Danger Zone on that same page deletes your Authly ID and its data permanently.
  • Anything else — write to us and we will respond within one month.

You also have the right to lodge a complaint with your national data protection authority.

Cookies

Authly ID sets only strictly necessary cookies: the ones that keep you signed in across apps, remember your language, and protect the sign-in form against cross-site request forgery. There are no advertising or profiling cookies, so there is no consent banner to click through.

Contact

Authly ID is operated by AppAtlas. Email support@appatlas.eu or use the contact form for any privacy question or data request.

Manage or delete your data from your account at any time.

Open my account