Privacy Policy
Effective date: October 1, 2026.
In short
- If you self-host our software, this Privacy Policy does not apply to your instance. Your copy is governed by its license, and you are the provider of your instance to its users and the controller of any of their personal data that reaches you.
- The Triauth Authenticator hosted by us at
auth.triauth.orgkeeps no account for you on our side. Your keys, identifiers and private profile are stored in your browser. - Anything that you or your domain administrator publishes in the DNS is public.
- You can ask us what we hold about you, have it corrected or deleted, object, and complain to a data protection authority.
- This summary is for convenience only, and the full text below is what applies.
1. Who we are and what this Policy covers
1.1 Controller. The controller of personal data processed in connection with the Services is the person or entity that operates the Triauth project and provides the Services under the Terms, as identified in Section 16. In this Policy, "we", "us" and "our" refer to that person or entity. You can reach us about privacy matters at privacy@triauth.org.
1.2 Scope. This privacy policy (the "Policy") explains how personal data is handled when you use the Services described in our Terms of Service (the "Terms"): all websites, web applications, APIs, documentation, developer tools, sandboxes and other online services that we make available under triauth.org and its subdomains, such as www.triauth.org, auth.triauth.org and play.triauth.org, under any other domain that we operate and that links to or refers to this Policy, and under your own hostname where you point it at our infrastructure. It also applies when you contact us or otherwise interact with us. Capitalized terms that are not defined here have the meaning given to them in the Terms.
1.3 What this Policy does not cover. This Policy does not apply to: (a) Self-hosted Instances of our Software, or the Software itself when you run it yourself, for which the operator of that instance is responsible; (b) Relying Parties, Domain Administrators, DNS providers, verification providers and other third parties that you interact with through the Protocol, each of which is an independent controller of the personal data it processes and is governed by its own privacy policy; (c) third-party platforms on which we publish code or interact with the community, such as source code repositories and package registries, which are governed by their own privacy policies; and (d) your device, browser, operating system and platform authenticator, and the vendors behind them.
1.4 Personal data. "Personal data" means any information relating to an identified or identifiable natural person, and includes what United States privacy laws call "personal information". This Policy is an information notice. It does not replace the Terms, which govern your use of the Services.
2. What we process, why, and on what legal basis
We process only the personal data described in this Section, and only for the purposes stated. We obtain it from you, from your browser and device when you use the Services, from the security systems of our providers, and from public sources such as the DNS and the platforms on which you interact with us. You are not obliged to provide personal data, but the Services cannot be delivered without connection and security data, and we cannot reply without your contact details. Where we rely on legitimate interests, you can object as described in Section 11, and you can ask us for a summary of how we balanced our interests against your rights.
2.1 Connection and security data. Whenever your browser contacts a Service, we, and our hosting and security providers acting on our behalf, process the data that your browser sends with each request, including: your IP address, the approximate location derived from it, your browser and device type, the addresses you request and the address of the page that referred you, dates and times, other data that your browser includes in its requests, such as HTTP headers, and the signals used to detect bots, attacks and abuse. We use connection data to deliver the Services, to keep them secure and available, to prevent and investigate abuse and breaches of the Terms, to troubleshoot problems, and to produce aggregate statistics. Legal basis: performance of our contract with you under the Terms (Art. 6(1)(b) GDPR) and our legitimate interests in operating, securing and improving the Services (Art. 6(1)(f) GDPR).
2.2 Usage statistics. We may measure how the Services are used, using aggregated statistics provided by our hosting provider and analytics tools designed to respect privacy, which are not used for advertising or to follow you across other websites. If we use a tool that requires your consent under applicable law, we will ask for it first (see Section 6). Legal basis: our legitimate interest in understanding and improving the Services (Art. 6(1)(f) GDPR), or your consent where required (Art. 6(1)(a) GDPR).
2.3 When you contact us. If you write to any of our addresses, submit a complaint, report a security vulnerability, exercise your rights, or otherwise contact us, we process the contact details you provide, the content of your message and our reply, in order to respond, handle the matter, keep a record of it, and meet our obligations under the Terms and the law. Please do not send us data that you do not want us to have, and never send us private keys or passwords. Legal basis: performance of our contract with you or steps taken at your request (Art. 6(1)(b) GDPR), compliance with legal obligations, such as handling complaints and requests under data protection law (Art. 6(1)(c) GDPR), and our legitimate interests in communicating with you and in establishing, exercising and defending legal claims (Art. 6(1)(f) GDPR).
2.4 Updates and newsletters. If we offer a newsletter or other updates and you subscribe, we process your email address and your subscription preferences to send them to you, and we may measure whether messages are delivered and opened. You can unsubscribe at any time using the link in each message or by contacting us. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time without affecting the lawfulness of earlier processing.
2.5 Business relationships. If you represent a Relying Party listed on the Website, a partner, a contributor, or another organization that works with us or that we contact to present our offering, we process your business contact details and the history of our dealings to manage that relationship. Legal basis: our legitimate interest in running the Triauth project and its relationships (Art. 6(1)(f) GDPR), or performance of a contract with you (Art. 6(1)(b) GDPR).
2.6 Hosted Services that store data for you. Some Hosted Services, now or in the future, may need to keep data on our side, such as for example your account, your settings, or content that you enter. We process this data to provide the Service to you, to secure it, and as described in any Service-Specific Privacy Notice published with the Service (Section 15.2). Where such a Service lets you manage personal data of other people, for example the Identifiers or Identity Records of the members of your organization, you are the controller of that data and we process it as your processor, under the data processing terms that we make available with the Service. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR) and our legitimate interests in securing the Service (Art. 6(1)(f) GDPR); for data that we process on your behalf, your instructions.
2.7 Payments. If we introduce paid Services, payments will be handled by a payment provider that processes your payment details under its own privacy policy. We will receive confirmation of payment and the details needed for invoicing and accounting. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR) and compliance with tax and accounting obligations (Art. 6(1)(c) GDPR).
2.8 Legal compliance and protection. We may process any of the data above where necessary to comply with the law, to respond to lawful requests from courts and authorities, to enforce the Terms, and to protect the rights, property and safety of the Triauth project, our users and others. Legal basis: compliance with legal obligations (Art. 6(1)(c) GDPR) and our legitimate interests in protecting the Services and defending legal claims (Art. 6(1)(f) GDPR).
2.9 No sensitive data. We do not ask for, and do not want, special categories of personal data such as health, biometric or political data. Biometric verification with a platform authenticator or security key happens entirely on your device, and we do not receive your biometric data.
3. Data that stays on your device
3.1 Client-side Services. Some of our Services work inside your browser and store there the data they need to function, such as your authentication Keys. They may also cache their own files so that they load faster or offline. We do not receive, store or back up this data. It stays on your device until you delete it through the application or your browser settings, or until your browser removes it.
3.2 Our role. Because this data never reaches us, we do not process it, and we cannot access, correct, recover or delete it for you. You control it through the application and your browser. If you share any of it with a Relying Party, for example by approving a request or by choosing to share your profile, the Relying Party processes it under its own privacy policy.
4. Data that your browser sends to others
Some Services work by having your browser communicate directly with third parties, on your instruction or as part of an operation that you start. For example, the Hosted Authenticator may read Identity Records through public third-party DNS-over-HTTPS resolvers, such as those operated by Cloudflare and Google, which receive the content of the web request, including the names they are asked to resolve and your IP address; when you approve or decline a request, your browser may deliver the result to the Relying Party that made it, and may retrieve resources that the Relying Party referred to, such as its icon or a document to be signed; when a Relying Party asks for an attestation, your browser may take you to a verification provider that you select; and your operating system, browser or password manager may store or synchronize credentials created with the Services. These parties act under their own privacy policies, which we encourage you to read.
5. Identity Records and the public DNS
Anything published in the Domain Name System (DNS) is public: it can be read by anyone, anywhere, and it may be cached and archived by third parties beyond your control, even after it is deleted. We do not control the DNS records of domains that we do not operate, and we are not responsible for what is published in them. Where a Hosted Service publishes or changes Identity Records for you, using credentials that you have given it, it does so on your instructions. The Protocol's private mode reduces what the records reveal, and the documentation explains how. Do not publish data in the DNS that you do not want to be public.
6. Cookies and similar technologies
6.1 What we use. The Services use browser storage, such as cookies, local storage, IndexedDB and service worker caches, where it is needed to run a Service or for a function that you request. Our hosting and security providers may set their own strictly necessary cookies for security, bot detection and load management. Such storage does not require your consent under applicable law.
6.2 What we do not do. We do not use cookies or similar technologies to track you across other websites or for advertising. If we ever introduce storage that requires your consent, such as certain analytics, we will ask for it before using it, and you will be able to refuse or withdraw it as easily as you gave it.
6.3 Your controls. You can view, block and delete cookies and other stored data through your browser settings. Blocking or deleting storage for a client-side Service removes the data described in Section 3, including your Keys.
7. Who receives your data
7.1 Providers. We rely on service providers that process personal data on our behalf, on our documented instructions and under contracts that meet the requirements of Art. 28 GDPR: providers of hosting, content delivery, DNS, security and anti-abuse services; providers of email, productivity, collaboration and AI-assisted tools that we use to run the project and to handle correspondence; and, where we offer them, providers of newsletter delivery, payment processing, analytics, customer support and similar services. We may add, replace or remove providers at any time, provided that they offer an appropriate level of protection, and you can ask us at any time which providers we currently use.
7.2 Independent third parties. The parties described in Sections 1.3, 4 and 5 receive data directly from you or your browser and are not our providers.
7.3 Authorities and legal claims. We may disclose personal data to courts, authorities, legal advisers and other parties where the law requires it, or where it is necessary to enforce the Terms, to protect the Services, or to establish, exercise or defend legal claims.
7.4 Business transfers. If the Triauth project, the Services or the assets relating to them are transferred to an Affiliate or to a successor, in connection with a merger, reorganization, change of control, or a sale or transfer of all or substantially all of those assets, personal data may be transferred as part of that transaction, as described in Section 23.4 of the Terms. The successor may continue to process it under this Policy, or under its own policy after giving you notice as described in Section 15.
8. International transfers
We are established in Poland, in the European Economic Area (EEA), and our providers may process personal data in other countries, in particular in the United States, where several of them are based or operate global networks. Where personal data is transferred outside the EEA, the United Kingdom or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards: the provider's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where available, and otherwise standard contractual clauses approved by the European Commission or the competent authority, together with supplementary measures where needed. You can ask us for a copy of the safeguards that apply to a given transfer.
9. How long we keep data
We keep personal data only for as long as it is needed for the purposes described in this Policy, and then delete or anonymize it. In particular: connection and security data is retained by our providers for a limited period under their retention practices, and any copies that we make for security or troubleshooting are kept only as long as that purpose requires; correspondence, complaints and records of your requests are kept while the matter is handled and thereafter for as long as we may need them to demonstrate compliance or to handle claims, generally no longer than the limitation periods under applicable law; newsletter data is kept until you unsubscribe; data held by a Hosted Service for you is kept until you delete it or the Service ends, plus a short period for backups; accounting records are kept for the periods required by tax law; and data on your device stays until you delete it. Data that is needed for a pending legal matter is kept until the matter is closed.
10. Security
We apply technical and organizational measures appropriate to the risk, taking into account the state of the art and the nature of the data, including encryption in transit, access controls, and the design principle of the Protocol that keys and identity data stay on your device rather than on our servers. No system is perfectly secure, and Section 8 of the Terms describes the risks that remain. If a personal data breach occurs, we will notify the competent authority and, where required, you, as the law requires.
11. Your rights
11.1 Rights under the GDPR. You have the right to ask us for access to your personal data, to have it rectified or erased, to restrict its processing, to receive it in a portable format where it is processed by automated means on the basis of consent or contract, and to object to processing based on our legitimate interests, including at any time to direct marketing. Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing before the withdrawal.
11.2 How to exercise them. Contact us at privacy@triauth.org or at the postal address in Section 16. We will respond within one month, which we may extend by two further months for complex or numerous requests, in which case we will tell you. We may ask you for the information needed to confirm your identity and to find your data. Please note that for most of the Services we hold no account and no data that identifies you: connection data cannot be linked to you by us, and the data described in Section 3 never reaches us. In such cases, as permitted by Art. 11 GDPR, we may not be able to fulfill a request, and we will tell you why. You can manage the data on your device yourself, and you should contact the Domain Administrator of your domain about Identity Records and each Relying Party about the data it holds. For requests sent by email, we respond to the address you write from.
11.3 Complaints. You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work or place of the alleged infringement. Our supervisory authority in Poland is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. We would appreciate the chance to address your concerns first.
11.4 United Kingdom and Switzerland. If you are in the United Kingdom or Switzerland, references to the GDPR include the UK GDPR and the Swiss Federal Act on Data Protection, as applicable, and you may complain to the Information Commissioner's Office or to the Federal Data Protection and Information Commissioner respectively.
12. Children
The Services are not directed to children under 13, and the Terms set out who may use them. We do not knowingly collect personal data from children under 13. If you believe that a child has provided us with personal data, contact us and we will delete it.
13. Automated decisions
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Automated security measures, such as bot detection or rate limiting operated by our providers, may temporarily block or challenge traffic. If you believe you were wrongly affected, contact us.
14. Residents of the United States
14.1 Application. This Section applies to residents of US states with privacy laws that grant rights in relation to personal information, such as the California Consumer Privacy Act (CCPA), to the extent those laws apply to us. It supplements the rest of this Policy, and the limits described in Section 11.2 apply to it as well.
14.2 Notice at collection. In the twelve months before the effective date, and going forward, we collect or may collect the following categories of personal information, from the sources and for the business purposes described in Section 2: identifiers, such as IP addresses, email addresses and names that you give us; internet or other electronic network activity information, such as the connection data described in Section 2.1; approximate geolocation derived from an IP address; professional information about business contacts; and, for Hosted Services that store data for you, the account, settings and content data described in Section 2.6. We disclose these categories to the service providers described in Section 7.1 for business purposes, and to other parties as described in Sections 7.3 and 7.4. We retain them according to the criteria in Section 9.
14.3 No sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information other than as permitted for providing the Services and ensuring their security, and we have no actual knowledge of selling or sharing the personal information of consumers under 16 years of age. Because we do not sell or share personal information, browser-based opt-out signals such as the Global Privacy Control, which we treat as a valid opt-out request where the law gives them that effect, require no further action from us. We do not track you across third-party websites over time, so we do not respond to "Do Not Track" signals differently from other traffic.
14.4 Your rights. Depending on your state, you may have the right to know what personal information we collect, use, disclose and sell or share, and to access it; to delete it; to correct it; to opt out of sale, sharing and targeted advertising, and of certain profiling; to limit the use of sensitive personal information; to obtain it in a portable format; and not to be discriminated against for exercising your rights. You may exercise them by contacting us as described in Section 16. We will confirm receipt where the law requires it and respond within 45 days, which we may extend once by a further 45 days with notice. We will verify your request using the information you provide and, where we hold no data that can be linked to you, we will explain that we cannot act on it. An authorized agent may submit a request on your behalf with proof of authorization. If we deny a request, you may appeal by replying to our decision. We will respond to an appeal within the time limit set by applicable law and, if we deny it, tell you how to contact your state's attorney general or privacy authority.
14.5 California and Nevada. California residents may request, under Civil Code Section 1798.83, information about disclosures of personal information to third parties for their direct marketing purposes. We make no such disclosures. We do not sell covered information within the meaning of Nevada law.
15. Changes to this Policy
15.1 Updates. We may change this Policy at any time, for example when we change the Services, our providers or our practices, or when the law changes. We will publish the amended Policy at https://www.triauth.org/legal/privacy with a new effective date. Changes that materially affect how we handle your personal data will be announced at least 14 days before they take effect, on the Website or in the Service concerned, and by email if we have your address and you have subscribed to such updates, except for changes required by law, which may take effect immediately. Earlier versions are available on request.
15.2 Service-Specific Privacy Notices. A Service may come with a privacy notice that expressly states that it supplements this Policy and describes how that Service handles personal data in more detail (a "Service-Specific Privacy Notice"). Such a notice forms part of this Policy and, for the Service it covers, prevails in case of conflict.
15.3 Language. This Policy is drafted in English. We may provide translations. If a translation conflicts with the English version, the English version prevails, unless the mandatory law of your country requires otherwise.
16. Contact
For questions, requests and complaints about privacy, contact us at privacy@triauth.org, or by post at the address below. Other contact addresses are listed in the Terms.
The Triauth project is currently maintained by Shore Labs Zbigniew Zemła, registered in the Polish Central Register and Information on Economic Activity (CEIDG), with its registered office at ul. Poprzeczna 11, 40-654 Katowice, Poland, tax identification number (NIP) 6772286301. This is the controller of your personal data under this Policy and the provider of the Services under the Terms.