Legal
Privacy Policy
What we collect, why we collect it, and the choices you have.
Last updated 9 August 2026
Who we are
Auth Licenses is a license management platform for software developers. Developers create applications, issue license keys, and validate those keys from their own products.
This policy covers two groups: developers who use the console, and end users whose license activity is processed on a developer's behalf.
Data we collect
- Account data: name, email address, password hash, and — if you sign in with Discord or Google — the account ID and profile basics returned by that provider.
- Application data: applications, license keys, customer names and emails you enter, notes, and integration settings.
- Validation data: hardware identifiers (HWID), IP addresses, activation counts, and session timestamps sent when a license is validated.
- Discord data: server (guild) ID, channel IDs, role IDs, and the Discord user ID of anyone who links or claims a license through the bot.
- Billing data: subscription plan, status, and customer/subscription identifiers from Stripe. Card details are handled by Stripe and never reach our servers.
- Operational data: audit logs, request metadata, and error logs used to secure and debug the service.
How we use data
We do not sell personal data, and we do not use your license or customer data to train models or build advertising profiles.
- Provide the service: authenticate accounts, issue and validate licenses, and enforce activation limits.
- Protect the service: detect abuse, rate-limit requests, and investigate security incidents.
- Billing: manage subscriptions and plan limits through Stripe.
- Communication: transactional email such as verification, password resets, and important service notices.
Developers as data controllers
When a developer issues licenses, they decide what customer information to store. For that data the developer is the controller and Auth Licenses acts as a processor, handling it only to run the service.
End users should contact the developer who sold them the license for questions about their own records.
Sub-processors
- Railway — application and database hosting.
- Vercel — frontend hosting and delivery.
- Stripe — subscription billing and payment processing.
- Resend — transactional email delivery.
- Discord and Google — optional sign-in, and the Discord bot integration when enabled.
Retention
Account and application data is kept while your account is active. Status samples are retained for roughly 100 days, and activation records are kept for as long as the related license exists.
Deleting an application removes its licenses, integrations, and related records. Deleting your account removes your workspace data, except where we must keep records for legal or accounting reasons.
Security
- Passwords are hashed with bcrypt; API keys and status keys are stored as SHA-256 hashes.
- All traffic is served over HTTPS, with security headers and per-endpoint rate limiting.
- Access to production data is limited to what is required to operate the service.
Your rights
You can access, correct, export, or delete your data. Most of this is available directly in the console under Settings; for anything else, contact us and we will respond within a reasonable timeframe.
Cookies
We use a refresh-token cookie to keep you signed in and local storage for preferences such as theme and selected application. We do not use advertising or third-party tracking cookies.
Changes
If this policy changes materially, we will update the date above and notify account holders by email where appropriate.
Questions? Contact support@authlicenses.com.