Privacy Policy

The short version: we run a login service designed so that we store as little about you as possible — and most of what we do store, we cannot read ourselves. We don't sell data, we don't show ads, and we don't track you across the web.

Who we are

Promise (promiseauthentication.org) is a login service: instead of creating a separate account for every app or website, you sign in once with Promise and we confirm to the app who you are — without telling it anything else about you.

The service is operated by Foreningen Promise (CVR 45656438), Præstegårds Allé 50, 2700 Brønshøj, Denmark — a non-profit association under Danish law. We are the independent data controller for the personal data described on this page — the data processed to make the login service itself work.

The apps and websites you sign in to (we call them relying parties) are separate, independent data controllers for whatever data you share with them. This policy covers Promise only; each relying party has its own privacy policy.

Questions or requests about your data: privacy@promiseauthentication.org.

Designed so we can't read your data

Three design choices carry most of this policy:

You can see all of this demonstrated with real production data on our security page.

What the services you sign in to receive

When you log in to a relying party, it receives a signed token containing a random ID created just for that service, the service's own name, and the time of issue. Every service gets a different random ID for you, so two services cannot compare notes to work out that you are the same person. The token does not contain your e-mail address or anything else about you.

A relying party that already knows your e-mail address (because you gave it to them directly) can register it with us so we can recognise their existing users. We store what they send only as a hashed fingerprint, tied to that one service.

The data we process

We process the following, all to provide the login service (legal basis: performance of our agreement with you, GDPR art. 6(1)(b)) unless noted otherwise:

How long we keep data

Who we share data with

We never sell personal data and never share it for advertising. We use a small number of suppliers (data processors) to run the service:

Our own key service, which holds the recovery keys described above, runs on separate infrastructure at a different location and stores no personal data — only key pairs.

Our servers and database are in the EU, and e-mails are sent from the EU. Two suppliers involve transfers to the United States: Heroku's US operations, covered by Heroku's certification under the EU-U.S. Data Privacy Framework and Salesforce's Binding Corporate Rules for processors, and Airbrake's filtered error reports, covered by the EU Standard Contractual Clauses (2021/914) incorporated in our data-processing agreement with Airbrake.

Cookies

We use only cookies that are necessary for the service to work — no analytics cookies and no third-party tracking cookies:

Your rights

Under the GDPR you can ask us for access to, correction of, deletion of, or a copy of your personal data; ask us to restrict processing; and object to processing based on legitimate interest. Write to privacy@promiseauthentication.org and we will respond within a month.

One practical note: because we store your e-mail address only as a fingerprint, we cannot browse our records for it. Please include the e-mail address you use with Promise in your request, so we can compute the fingerprint and locate your data.

If you are unhappy with how we handle your data, you can complain to the Danish Data Protection Agency (Datatilsynet), datatilsynet.dk.

Changes to this policy

When we change this policy, we update this page and the date below. If a change meaningfully affects how your data is handled, we will make that clear on the site before it takes effect.

Last updated: 27 August 2026 (removed our log-management provider)


Log ind
English Dansk