AuthFlow
Sign in

Privacy

What AuthFlow stores, why it stores it, and what it does not do. Last updated 17 September 2026.

What this covers

This page covers this website: the documentation, the developer dashboard where you create an app, and the live demo.

It does not cover apps other people build with the AuthFlow packages. If you signed in to somebody else’s app and it uses AuthFlow, that developer decides what is collected and why, and their own privacy notice applies.

If you create a developer account

AuthFlow stores:

  • your email address
  • a hash of your password — bcrypt, never the password itself, and it cannot be reversed
  • when the account was created
  • a row for each active session, so you can be signed in
  • the apps you create: their name and the app URL you enter

An app’s secret key is shown once and stored only as a hash. Nobody, including AuthFlow, can read it back to you.

If you use the demo

The demo creates a real account in a sandbox app so that the sign-in you see is a real one. It stores the same things as above: your email, a hash of your password, whether the address was confirmed, and a session row.

The demo is for trying the product. Use an address you do not mind using there, and a password you do not use anywhere else. Its data may be cleared at any time without notice.

Sign-in attempts and IP addresses

Anywhere you type a password, AuthFlow limits how many tries are allowed — and to do that, it has to count them. So it keeps a count against your email address and against the IP address the request came from, with the time of each try. This is what stops someone guessing their way into an account. The count is deleted once that stretch of time has passed.

Cookies

One cookie, and the site cannot work without it. It is what keeps you signed in. It is httpOnly, so no code running on the page can read it. It is Secure, so it is only ever sent over HTTPS. And it is SameSite=Lax, so other websites cannot make your browser send it.

Your light or dark preference is kept in your own browser’s local storage. It never leaves your device and is not sent to any server.

What AuthFlow does not do

  • No analytics, no tracking pixels and no advertising.
  • No selling or sharing of personal data with anyone.
  • No third-party fonts. Typefaces are served from this domain, so no request leaves for another company when you open a page.
  • No profile is built about you, and no software makes decisions about you.

Who else handles the data

AuthFlow runs on other companies’ services, and each of them sees some of this data because it has to in order to do its job:

  • a hosting provider for this website, and another for the API
  • a database provider, which stores the records described above
  • an email provider, which sends the confirmation and password-reset messages

None of them use it for anything else, and each has its own privacy policy. If you want to know which companies these are, write to contact@wewiselabs.com and ask.

How long it is kept

  • A session lasts 30 days. Once it expires, a clean-up job deletes it.
  • Confirmation and password-reset links work once, then expire. Asking for a new link switches the old one off.
  • Account records are kept while the account exists. Delete the account and they go with it, along with the apps and sessions attached to it.

Your choices

You can ask for a copy of what is stored about you, ask for it to be corrected, or ask for the account and its data to be deleted. Write to contact@wewiselabs.com and say which. Deleting an account removes its apps, its sessions and its records.

Changes

If this page changes, the date at the top changes with it. There is no mailing list to notify, so the date is the honest signal.