1. Information We Collect
When you register, authenticate, or manage your account through SSO Develop (operating under 555 ID / SSO Identity Provider), we collect only minimal information necessary to deliver secure identity services:
- Account Profile: Display name, verified email address, optional phone number, and avatar image.
- Security Credentials: Salted password hashes (bcrypt), public WebAuthn / Passkey credentials (public keys, credential IDs, sign count), and hashed emergency recovery codes. Plaintext passwords are never stored or transmitted.
- Federated Social Identities: When connecting third-party accounts (Google, Telegram, Facebook, X), we store provider user identifiers and profile avatars under strict avatar Content Security Policies (CSP).
- Audit Telemetry: Client IP address, user agent, login attempt timestamps, and security session identifiers strictly used for brute-force prevention and session verification.
- Developer Application Metadata: Client names, redirect URIs, CORS origins, and cryptographic client identifiers used strictly to configure and secure OAuth 2.0 / OIDC integrations.
2. How We Use Information
Your information is used strictly to operate the authentication ecosystem:
- Authenticating your identity and issuing cryptographically signed RS256 OpenID Connect (OIDC) JWT tokens.
- Securing accounts against credential stuffing, brute-force guessing attacks, and unauthorized access via rate limiting and automated lockouts.
- Delivering critical account notices, such as email verification links and password recovery tokens via high-deliverability transactional infrastructure (Resend API / SMTP).
- Enforcing fair-use developer quotas, operational rate limits, and audit logs to ensure high availability for all connected applications.
3. Third-Party Sharing & Zero-Sale Guarantee
We never sell, rent, monetize, or broker your personal data. Profile information is shared with downstream client applications strictly when you explicitly authorize an OpenID Connect sign-in handshake. Claims exchanged are limited to authorized scopes (e.g. openid, profile, email).
4. Cryptographic Protection & Security Measures
We protect your identity using enterprise-grade cryptographic standards:
- Encryption in Transit: Mandatory TLS 1.3 encryption across all public endpoints and microservices.
- Encryption at Rest: Sensitive OAuth tokens and credentials encrypted at rest with AES-256-GCM.
- Cookie Hardening: Authentication tokens are stored in
HttpOnly,Secure, andSameSite=Laxcookies inaccessible to client-side JavaScript. - FIDO2 WebAuthn: Passkeys leverage public-key cryptography bound to user devices, providing complete immunity to credential phishing.
5. Data Retention, Soft-Delete & Erasure Rights (GDPR / CCPA)
You have full rights under GDPR, CCPA, and international data protection laws:
- Right of Access & Rectification: You can view and update your profile anytime in your Account Dashboard.
- Right to Erasure (Self-Service): You can delete your account directly via the Danger Zone in your dashboard. Active sessions are revoked instantly and public assets purged.
- User Data Deletion Instructions: Review our comprehensive User Data Deletion Instructions for disconnecting social providers (such as Facebook) or submitting formal erasure requests.
- 30-Day Soft-Delete Period: In compliance with security auditing regulations, records remain soft-deleted for 30 days before permanent irreversible scrubbing.
6. Privacy Contacts & Data Protection Officer
To exercise your privacy rights or submit a GDPR/CCPA request, contact our Data Protection Officer: