← Back to sign in
Privacy Policy
Last updated: April 2026
This privacy policy is a draft outline. The final version will be
reviewed by legal counsel before the production launch. The data
handling described below is accurate and enforced by the service.
What we collect
-
Identity: Name, email, and profile image from OAuth
providers (GitHub, Google, Discord, X). Only what the provider shares.
-
Wallet addresses: Blockchain addresses you connect.
Public by nature (on-chain).
-
Session data: IP address and browser user-agent,
stored for active session management. Deleted when you sign out or the
session expires (7 days).
-
Sign-in history: Wallet address and timestamp of each
sign-in. Retained for 90 days, then permanently deleted.
Why we collect it
To operate the authentication service: verify your identity, issue
session tokens, and prevent unauthorized access. Legal basis:
contractual necessity (Art. 6(1)(b) GDPR).
Who we share it with
Third-party apps you sign into receive your profile and wallet
information via JWT claims. You control which apps have access via the
Connected Apps page. No data is sold or shared with advertisers.
How long we keep it
- Access tokens: 15 minutes
- Sessions: 7 days
- Sign-in history: 90 days
- Account data: until you delete your account
-
After deletion request: 30-day grace period, then permanent erasure
Your rights
-
Access: View all your data at
/account
-
Export: Download all your data via
GET /auth/me/export
-
Deletion: Request account deletion from
/account. Permanently erased after 30 days.
-
Correction: Update your profile via your linked OAuth
provider
-
Revocation: Revoke app access from
/account
Cookies
We use strictly functional cookies (w3_access,
w3_refresh) for session management. No tracking cookies, no
analytics cookies. These are HttpOnly and Secure.
Contact
For privacy inquiries: privacy@w3.io