Back to sign in

Account Experience

Privacy and Data Protection

How we collect, safeguard, and use information in the IdentityServer account experience. Transparency and user control stay at the center of every decision.

Secure by design
Last updated January 2025

Our commitment

Security first

We only use your data to operate secure authentication, prevent abuse, and deliver the features you enable.

User control

Clear choices

You can access, correct, or delete your data, manage devices, and adjust security preferences at any time.

Clarity

No surprises

We avoid secondary use and never sell personal data. Vendors only receive what they need to provide the service.

What we collect

Account and identity data

  • Name, email address, and optional phone number
  • Profile preferences (language, avatar placeholder)
  • Credential metadata (hashed passwords, passkey descriptors)

Security signals

  • Login timestamps, IP address, device and browser attributes
  • MFA status, trusted devices, recovery method metadata
  • Risk signals (suspicious attempts, lockout counters)

Service usage

  • Feature usage (e.g., passkeys enabled, MFA methods enrolled)
  • Audit trail of key account changes
  • Support interactions you initiate

Optional diagnostics

  • Error traces and performance metrics when troubleshooting
  • Aggregated analytics without identifying individuals
  • Only collected when you opt in or request support

How we use data

  • Authenticate you, enforce MFA, and detect fraudulent activity
  • Send account alerts, device notifications, and security prompts you request
  • Provide recovery flows such as password resets and backup codes
  • Improve reliability and defend against abuse through rate limits and lockouts
  • Comply with legal obligations (audit records, consent logs, regulatory requests)
  • Respond to support requests you open and deliver requested features

We rely on contract necessity to operate the service, legitimate interests for security and improvement, and your consent where required (for example, optional diagnostics or marketing preferences).

Retention and deletion

Authentication logs and security events are kept only as long as necessary to fulfill the purpose or meet legal requirements. You can request deletion of your account, after which we erase or irreversibly de-identify personal data unless retention is required by law.

Sharing

We do not sell personal data. Limited data is shared with vendors who provide infrastructure, email/SMS delivery, logging, or fraud detection, bound by confidentiality and security terms.

  • Legal and safety: we may disclose information if required to comply with law or protect users.
  • Customer admins: if you use an enterprise account, administrators may access activity relevant to their tenant.

Cookies and telemetry

  • Strictly necessary cookies for sessions, CSRF protection, and device trust
  • No third-party advertising trackers
  • Optional analytics is aggregated and can be disabled in your preferences

Security practices

  • Transport Layer Security everywhere and modern cipher suites
  • Credential hashing, key management, and mandatory MFA for administrators
  • Defense-in-depth controls including rate limiting, audit trails, and least-privilege access

Your choices and rights

  • Access or correct your profile data from account settings
  • Review signed-in devices and revoke trusted sessions
  • Export a copy of your data in a portable format on request
  • Request deletion of your account and associated identifiers
  • Withdraw consent where we rely on it (for example, optional analytics)
  • Appeal or ask questions about decisions that affect your account

Depending on your region, you may have additional rights (such as objection or restriction). We respond to all requests in line with applicable law.

Questions or privacy requests?

Reach our security and privacy team and we will respond promptly.