Sign In

Privacy Policy

Effective Date: September 30, 2026 · Last Updated: September 2026

English

1. Information We Collect

When you register, authenticate, or manage your account through SSO Develop (operating under 555 ID / SSO Identity Provider), we collect only minimal information necessary to deliver secure identity services:

  • Account Profile: Display name, verified email address, optional phone number, and avatar image.
  • Security Credentials: Salted password hashes (bcrypt), public WebAuthn / Passkey credentials (public keys, credential IDs, sign count), and hashed emergency recovery codes. Plaintext passwords are never stored or transmitted.
  • Federated Social Identities: When connecting third-party accounts (Google, Telegram, Facebook, X), we store provider user identifiers and profile avatars under strict avatar Content Security Policies (CSP).
  • Audit Telemetry: Client IP address, user agent, login attempt timestamps, and security session identifiers strictly used for brute-force prevention and session verification.
  • Developer Application Metadata: Client names, redirect URIs, CORS origins, and cryptographic client identifiers used strictly to configure and secure OAuth 2.0 / OIDC integrations.

2. How We Use Information

Your information is used strictly to operate the authentication ecosystem:

  • Authenticating your identity and issuing cryptographically signed RS256 OpenID Connect (OIDC) JWT tokens.
  • Securing accounts against credential stuffing, brute-force guessing attacks, and unauthorized access via rate limiting and automated lockouts.
  • Delivering critical account notices, such as email verification links and password recovery tokens via high-deliverability transactional infrastructure (Resend API / SMTP).
  • Enforcing fair-use developer quotas, operational rate limits, and audit logs to ensure high availability for all connected applications.

3. Third-Party Sharing & Zero-Sale Guarantee

We never sell, rent, monetize, or broker your personal data. Profile information is shared with downstream client applications strictly when you explicitly authorize an OpenID Connect sign-in handshake. Claims exchanged are limited to authorized scopes (e.g. openid, profile, email).

4. Cryptographic Protection & Security Measures

We protect your identity using enterprise-grade cryptographic standards:

  • Encryption in Transit: Mandatory TLS 1.3 encryption across all public endpoints and microservices.
  • Encryption at Rest: Sensitive OAuth tokens and credentials encrypted at rest with AES-256-GCM.
  • Cookie Hardening: Authentication tokens are stored in HttpOnly, Secure, and SameSite=Lax cookies inaccessible to client-side JavaScript.
  • FIDO2 WebAuthn: Passkeys leverage public-key cryptography bound to user devices, providing complete immunity to credential phishing.

5. Data Retention, Soft-Delete & Erasure Rights (GDPR / CCPA)

You have full rights under GDPR, CCPA, and international data protection laws:

  • Right of Access & Rectification: You can view and update your profile anytime in your Account Dashboard.
  • Right to Erasure (Self-Service): You can delete your account directly via the Danger Zone in your dashboard. Active sessions are revoked instantly and public assets purged.
  • User Data Deletion Instructions: Review our comprehensive User Data Deletion Instructions for disconnecting social providers (such as Facebook) or submitting formal erasure requests.
  • 30-Day Soft-Delete Period: In compliance with security auditing regulations, records remain soft-deleted for 30 days before permanent irreversible scrubbing.

6. Privacy Contacts & Data Protection Officer

To exercise your privacy rights or submit a GDPR/CCPA request, contact our Data Protection Officer:

Privacy Requests: [email protected]
General Inquiries: [email protected]