Privacy Policy

Last updated: 29 August 2026

This Privacy Policy explains how VelvetAuth (“we”, “us”, or “our”) collects, uses, and shares information when you use our website and authentication platform (the “Service”).

1. Who this applies to

2. Information we collect

Account information: username, email address, password (stored hashed), plan level, and optional settings such as 2FA.

Billing information: payment status and subscription details. Card payments are processed by Stripe; we do not store full card numbers on our servers.

Application and license data: app configuration, license keys, variables, webhooks, logs, sessions, and related records you create.

End-user / client data (when your app uses our API): identifiers you send (for example usernames, emails, HWIDs, IPs, session tokens), depending on how you configure your integration.

Technical data: IP address, browser/device info, timestamps, and security logs used for abuse prevention and reliability.

Support data: messages you send through tickets or email.

3. How we use information

We do not sell your personal information.

4. Legal bases (where applicable)

Depending on your location, we process data because: (a) it is needed to perform our contract with you; (b) we have a legitimate interest in running a secure service; (c) we have consent where required; or (d) we must comply with legal obligations.

5. Sharing

We may share information with:

If you connect optional services (for example a WireGuard VPS you control), data needed for that feature is sent to systems you configure.

6. International transfers

We may process data in Australia and other countries where our providers operate. Where required, we use appropriate safeguards for cross-border transfers.

7. Retention

We keep account and service data while your account is active and for a reasonable period afterward for backups, disputes, security, and legal requirements. You may request deletion of your account; some records (for example billing or security logs) may be retained where we must keep them.

8. Security

We use industry-standard measures such as hashed passwords, encrypted transport (HTTPS), access controls, and rate limiting. No method of transmission or storage is 100% secure. You are responsible for protecting your API secrets and for configuring your own applications safely.

9. Cookies and similar tech

We use cookies and similar technologies for sign-in sessions, security (including CSRF protection), and basic site functionality. These are primarily necessary for the Service to work rather than advertising.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to / restrict certain processing. Account holders can update many details in the dashboard. To make a privacy request, contact us using the details below. We may need to verify your identity first.

If you are an end user of a third-party app that uses VelvetAuth, contact that app’s owner first — they control much of the data about you.

11. Children

The Service is not directed to children under 16. If you believe we have collected information from a child inappropriately, contact us and we will take appropriate steps.

12. Changes

We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Continued use of the Service after an update means you acknowledge the revised policy.

13. Contact

Privacy questions or requests: open a support ticket from your VelvetAuth account, or email [email protected].