Legal

Privacy Policy

Last updated: August 5, 2026

This Privacy Policy explains how self-IAM ("we", "us") collects, uses, stores, and protects information when you use our website, the hosted self-IAM API (the "Service"), and the self-iam client software. By using the Service, you agree to the practices described here.

1. Information We Collect

We collect the following categories of information:

  • Account and identity data — username, email address, and (when you provide it) phone number, together with a cryptographically hashed password. Google sign-in creates an account with your Google identifier and (if granted) email address.
  • Contact messages — name, email address, subject, and message body that you submit through contact forms.
  • One-time passcodes — temporary codes generated for WhatsApp verification. We store only SHA-256 hashes of these codes, never the plaintext codes.
  • Session and security data — short-lived session tokens, an HTTP-only cookie, and API key usage counters (number of operations per key per day).
  • Technical data — standard web logs such as IP address, user agent, requested route, and timestamps, used for security and abuse prevention.

2. How We Use Information

We use the information we collect to:

  • authenticate users and maintain sessions;
  • route users to the correct organization and deliver contact messages;
  • enforce rate limits and prevent abuse or unauthorized access;
  • operate, secure, and improve the Service; and
  • comply with legal obligations.

3. Legal Basis (GDPR/DPDP)

Where applicable law requires a legal basis, we process personal data based on (i) your consent, (ii) performance of a contract with you, (iii) our legitimate interests in operating and securing the Service, or (iv) compliance with legal obligations. You may withdraw consent at any time without affecting the lawfulness of processing that took place before withdrawal.

4. Storage and Security

Data is stored in managed databases (including MongoDB Atlas) and the Service is hosted on infrastructure providers (including Vercel). We protect data with:

  • passwords hashed with bcrypt (cost factor 10) — plaintext is never stored;
  • API keys and OTP codes stored only as SHA-256 hashes;
  • session tokens signed with a server-side secret and revocable server-side;
  • HTTP-only, SameSite cookies; TLS in transit;
  • time-attack-resistant credential comparisons to prevent account enumeration.

No method of transmission or storage is completely secure. We cannot guarantee absolute security of your data.

5. Sharing and Disclosure

We do not sell your personal data. We share information only with:

  • processors who help us provide the Service (hosting, databases, and the Google and WhatsApp integrations), each bound by appropriate data-processing terms;
  • law enforcement or regulators where required by law or valid legal process;
  • successors in the event of a merger, acquisition, or sale of assets.

6. Data Retention

We retain account data for as long as your account is active. Session records and OTP codes are automatically deleted on expiry (TTL indexes). Contact messages are retained until you request deletion or as required for legal purposes. You may request deletion of your data at any time (see Section 8).

7. Cookies and Local Storage

We use an HTTP-only cookie named ck_session to maintain sessions, and the client software stores a session token in your browser's local storage so you remain signed in. These are functional; we do not use advertising cookies.

8. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, restrict, or delete your personal data, and to object to processing. To exercise these rights, contact us at privacy@selfiam.example. We will respond within the period required by law.

9. Children

The Service is not directed to children under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

10. Third-Party Links

The Service may link to third-party websites or integrate with third-party providers. We are not responsible for their privacy practices; we encourage you to review their policies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes take effect when posted, and the "Last updated" date above will be revised. Material changes will be communicated through the Service where reasonably possible.

12. Contact

For privacy inquiries, contact privacy@selfiam.example or write to self-IAM, via the contact form on this site.

Questions about these documents? Contact legal@selfiam.example or use the contact form.