01Who we are
The controller responsible for processing under Art. 4(7) GDPR is Sebastian Junginger, operating one-auth.net. Reach us at [email protected] for anything covered by this policy — postal address on request — placeholder, add if an Impressum is required. No data protection officer is appointed; a service this size isn't required to have one, so requests go straight to the address above.
02What we collect
Only what account creation and two-factor sign-in need. We don't collect payment details, we run no advertising or analytics trackers, and we don't profile visitors who never sign up.
- Account data — your email address and password. The password is never stored in plain text, only as a salted hash. Full name and company are optional and only stored if you provide them.
- Two-factor data — a unique TOTP secret generated for your account so an authenticator app can produce login codes, and whether setup has been confirmed.
- Session data — a signed, HTTP-only session cookie that keeps you signed in between requests. See the cookie policy for details.
- Local device storage — one entry, oa-theme, holding your light/dark preference. Kept only in your browser; never sent to the server.
- Technical data — your IP address is checked briefly to rate-limit repeated 2FA verification attempts and is not stored permanently by the application. The hosting environment may keep standard technical access logs (IP address, requested URL, timestamp, user agent) for a limited period for security purposes.
03How it's used
- Providing your account and the 2FA/OTP functionality you signed up for — Art. 6(1)(b) GDPR, performance of a contract.
- Keeping you signed in and protecting login/verification against automated abuse (rate limiting) — Art. 6(1)(f) GDPR, legitimate interest in a secure service.
- Setting the strictly necessary session cookie — exempt from consent under § 25(2) No. 2 TTDSG, because it's technically required to deliver the service you asked for.
- Remembering your light/dark preference — stored client-side only; we never see or process this value.
We never use your email, name, or company for marketing, and no automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
05Retention and security
- Account data is kept for as long as your account exists. You can delete your own account at any time from account settings, which removes your data immediately and permanently.
- If an account is suspended, the underlying data is kept only as long as needed to resolve the matter — not indefinitely.
- Passwords are stored only as a salted hash and can't be reversed to the original password. Two-factor secrets are stored server-side and used only to verify the codes your authenticator app generates.
- The session cookie is a browser-session cookie: it's deleted automatically when you close your browser. We don't set a long-lived "remember me" cookie.
- The database and cryptographic secret keys are file-permission restricted and are never committed to source control.
06Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you (Art. 15).
- Correct inaccurate data (Art. 16) — most account fields can be edited directly in account settings.
- Erase your data, the "right to be forgotten" (Art. 17) — delete your own account any time, or ask us to do it for you.
- Restrict processing (Art. 18) or object to it where based on legitimate interest (Art. 21).
- Port your data to another provider in a structured, machine-readable format (Art. 20).
To exercise any of these rights, email [email protected]; we respond within one month, as required by Art. 12(3) GDPR.
07Changes to this policy
We'll update this page whenever what we collect or how we use it changes, and update the "Last updated" date above. Material changes affecting your rights will also be communicated to registered users directly — by email or an in-app notice — where feasible.