Legal

Privacy notice

Last updated August 12, 2026

Last updated August 12, 2026. Contact legal@oauth.work for the executed DPA and entity details. Retention periods below match the platform RETENTION constants (audit 365 days, backups 90 days) unless otherwise noted.

This notice explains how OAUTH.WORK ("we") handles personal data in connection with the OAUTH.WORK identity platform (the "Service"). It covers two distinct roles, and the distinction matters for your rights.

Two roles: controller and processor

  • We are a processor for the identity data our customers route through the Service — their end users' profiles, group membership, credentials, and authentication events. The customer organization is the controller. It decides what to collect and why. If you are an end user signing in through a customer's tenant, direct your requests to that organization; we will assist them in responding.
  • We are a controller for our own business data — the accounts of people who sign up for the Service, billing records, support correspondence, and security logs relating to the platform itself.

What we process as a processor

Determined by the customer's configuration, this can include:

  • User records — identifiers, email address, name, profile attributes, and group and role membership, provisioned directly or via SCIM 2.0.
  • Authentication material — password hashes, WebAuthn public-key credentials, TOTP secrets, recovery codes, and registered device metadata. We never store passwords in plaintext.
  • Session and grant state — sessions, refresh tokens, consent records, authorization grants, and delegation records.
  • Federation data — SSO connection settings, social identity links, and directory group membership from connected identity providers.
  • Issued credentials — Verifiable Credentials issued by a tenant and their revocation status.
  • Audit events — an append-only record of authentication, authorization, and administrative actions, including timestamps, actor, and source context.
  • Cryptographic keys — per-tenant private signing keys, envelope-encrypted at rest under a master key.

What we process as a controller

  • Account and contact details for administrators who sign up.
  • Billing and transaction records.
  • Support and security correspondence.
  • Operational logs and abuse-prevention signals, including IP address and request metadata.

Why we process it

As a processor: solely to provide the Service on documented instructions from the customer. As a controller: to operate and secure the platform, to bill for it, to respond to enquiries, and to meet legal obligations. Where required, our lawful bases are performance of a contract, legitimate interests in securing and operating the Service, and compliance with legal obligations.

What we do not do

  • We do not sell personal data, and we do not share it for advertising purposes.
  • We do not use customer data to train machine-learning models.
  • There is no third-party analytics or advertising tracking on this website.

Cookies

We set four cookies, all of them strictly necessary to sign you in and keep you signed in. None are used for analytics, profiling, or advertising, so no consent banner is required.

  • ow_sid — your signed-in session. Issued on the host you signed in on, and sent as __Host-ow_sid over HTTPS.
  • ow_uid — identifies the signed-in user to the consent screen.
  • ow_flow — binds a pending authorization request to your browser, so a request started in one browser cannot be completed in another.
  • ow_mfa — carries a two-step verification challenge between the sign-in screens, so the token is never placed in a URL.

All four are HttpOnly and are cleared when you sign out. Clearing them ends your session; nothing else on the site depends on them.

Retention

Token and credential lifetimes are set by the platform and are short by design:

authorization code ......... 10 minutes
access token ............... 1 hour
ID token ................... 1 hour
delegated (agent) token .... 5 minutes
refresh token .............. 30 days
verifiable credential ...... 90 days
published key cache ........ 24 hours

Record retention:

  • Live tenant records — kept for as long as the customer's account is active, and deleted within [30] days of termination.
  • Audit log — retained 365 days (~12 months), then deleted.
  • Encrypted backups — daily exports retained 90 days, then deleted. A deletion request is reflected in live records immediately and works through backups within this window.
  • Billing records — retained as required by law, typically [7] years.

Sub-processors

We use the following sub-processors to deliver the Service:

  • Cloudflare, Inc. (United States) — compute (Workers, Durable Objects), caching of public key material (KV), backup storage (R2), bot mitigation (Turnstile), and transactional email (sign-in codes, magic links, password resets).
  • Neon Inc. (United States) — managed PostgreSQL, reached through Cloudflare Hyperdrive.
  • Our payment processor — billing and payment processing.

We give notice before adding or replacing a sub-processor, as set out in the DPA. Note that identity providers a customer connects (for example, an enterprise directory or a social login provider) are the customer's own integrations, not our sub-processors.

International transfers

Requests are handled at Cloudflare edge locations worldwide, so processing may occur in any country where Cloudflare operates a data centre. The primary database is hosted in the United States (AWS us-west-2); encrypted backups are stored in Cloudflare R2. Where personal data is transferred out of the EEA, the UK, or Switzerland, we rely on [TRANSFER MECHANISM — e.g. Standard Contractual Clauses] together with supplementary measures. Details are in the DPA.

Security

Signing uses EdDSA / Ed25519 throughout. Per-tenant private keys are AES-GCM envelope-encrypted at rest. Access tokens can be sender-constrained (DPoP), refresh-token reuse is detected and triggers revocation, and administrative actions are written to an append-only audit log. Verification runs on WebCrypto. Our full posture is published at Security.

Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to it. If your data reached us through a customer's tenant, contact that organization — they are the controller and we will support them in responding. For data we control, write to privacy@oauth.work. You also have the right to complain to your supervisory authority.

Contact

OAUTH.WORK. Privacy enquiries: privacy@oauth.work. Legal: legal@oauth.work. Security disclosure: security@oauth.work. [EU/UK REPRESENTATIVE, if required.] [DATA PROTECTION OFFICER, if appointed.]

Changes

We will post updates here and, for material changes, notify account administrators by email at least [30] days in advance.