Privacy Policy
The short version: we run a login service designed so that we store as little
about you as possible — and most of what we do store, we cannot read ourselves.
We don't sell data, we don't show ads, and we don't track you across the web.
Who we are
Promise (promiseauthentication.org) is a login service: instead of creating
a separate account for every app or website, you sign in once with
Promise and we confirm to the app who you are — without telling it anything
else about you.
The service is operated by Foreningen Promise
(CVR 45656438), Præstegårds Allé 50, 2700 Brønshøj, Denmark — a
non-profit association under Danish law. We are the independent data
controller for the personal data described on this page — the data processed
to make the login service itself work.
The apps and websites you sign in to (we call them relying parties)
are separate, independent data controllers for whatever data you share with
them. This policy covers Promise only; each relying party has its own
privacy policy.
Questions or requests about your data:
privacy@promiseauthentication.org.
Designed so we can't read your data
Three design choices carry most of this policy:
-
Your e-mail address is stored only as a fingerprint.
When you sign up, we compute a one-way cryptographic hash of your e-mail
address (two independent algorithms, SHA-256 and BLAKE2b, combined) and
store only that. The fingerprint lets us recognise you when you type your
e-mail at login, but it cannot be turned back into your address. Our
database does not contain a readable list of e-mail addresses.
-
Your password is never stored. We keep only an Argon2
hash of it, which lets us check the password you type without knowing it.
-
Your identifiers live in a vault only you can open.
The list of IDs connecting you to the services you use is encrypted with a
key derived from your password. That key is held in an encrypted cookie in
your own browser — it is not stored on our servers. Without your password,
we cannot open your vault.
You can see all of this demonstrated with real production data on our
security page.
What the services you sign in to receive
When you log in to a relying party, it receives a signed token containing a
random ID created just for that service, the service's own
name, and the time of issue. Every service gets a different random ID for
you, so two services cannot compare notes to work out that you are the same
person. The token does not contain your e-mail address or anything else
about you.
A relying party that already knows your e-mail address (because you gave it
to them directly) can register it with us so we can recognise their existing
users. We store what they send only as a hashed fingerprint, tied to that
one service.
The data we process
We process the following, all to provide the login service (legal basis:
performance of our agreement with you, GDPR art. 6(1)(b)) unless noted
otherwise:
-
E-mail address. Stored only as the hashed fingerprint
described above, together with the time it was verified. We use the
readable address transiently — while you type it during login and to send
you the e-mails below — but do not keep it in readable form.
-
Verification codes and magic links. When you sign up or
change your e-mail, we send a short code and a one-click link. Both expire
after 1 hour and expired ones are deleted. The magic
link's content is encrypted with a secret that exists only inside the
e-mailed link itself — the copy in our database is unreadable on its own.
-
Password recovery. If you ask to reset your password, we
e-mail you a single-use recovery link, which is deleted once used. To make
recovery possible at all, we keep an encrypted spare copy of your vault
key. Opening it requires a private key held by our separate key service at
a different physical location — so no single system holds everything
needed to read your vault.
-
Login session. Kept in encrypted cookies in your browser
— see Cookies below.
-
Usage statistics (legal basis: our legitimate interest in
understanding and improving the service, art. 6(1)(f)). We count visits
and sign-ins without cookies and without linking them to your account.
Your IP address is masked (the last part removed) before anything is
stored; alongside it we record browser and operating system type and the
referring page. Visit statistics are deleted after 6 months.
Sign-in statistics — which service was signed in to, and when — use the
random per-service ID, not your e-mail, and are kept so we can follow
each service's usage over time.
Registration-flow events record only which step was reached and for which
service — never your e-mail or other personal details.
-
Error reports (art. 6(1)(f)). When something breaks, a
technical error report is sent to our error-tracking tool. E-mail
addresses, passwords, codes and tokens are filtered out before the report
is sent.
-
Abuse prevention (art. 6(1)(f)). Registration includes a
Cloudflare Turnstile check to keep bots from abusing the e-mail
verification flow. Cloudflare processes technical signals from your
browser (including your IP address) to tell humans from bots.
-
Account history. We keep an append-only log of account
events (e-mail claimed, password set, and so on) for integrity and
troubleshooting. It contains the same hashed and encrypted forms described
above — never your readable e-mail or password.
How long we keep data
- Verification codes and magic links: 1 hour.
- Recovery links: single-use, deleted when used.
-
Login session: until you log out or close your browser. If you chose
"Remember me", the encrypted cookies in your browser persist until you log
out.
-
Account records (hashed e-mail, password hash, encrypted vault, account
history): for as long as your account exists. Write to us to have your
account deleted.
- Visit statistics: 6 months.
-
Per-service sign-in statistics: kept while the service operates — they
contain only the random per-service ID, never your e-mail.
-
Error reports: held by our error-tracking provider, not stored on our own
systems.
-
Server logs: not stored beyond our hosting platform's short rolling
buffer. Our own log lines mask IP addresses and never contain your
e-mail address.
Who we share data with
We never sell personal data and never share it for advertising. We use a
small number of suppliers (data processors) to run the service:
-
Hosting: Heroku (Salesforce, Inc.) — the service and its
database run in Heroku's EU region
-
E-mail delivery: Scaleway (France) — delivers
verification and recovery e-mails, and therefore processes your e-mail
address
-
Error tracking: Airbrake (US) — receives technical error
reports with e-mail addresses, passwords and tokens filtered out
-
Bot protection: Cloudflare (the Turnstile check described
above; the Turnstile script is loaded from Cloudflare when our pages load)
Our own key service, which holds the recovery keys described above, runs on
separate infrastructure at a different location and stores no personal data
— only key pairs.
Our servers and database are in the EU, and e-mails are sent from the EU.
Two suppliers involve transfers to the United States: Heroku's US
operations, covered by Heroku's certification under the EU-U.S. Data
Privacy Framework and Salesforce's Binding Corporate Rules for processors,
and Airbrake's filtered error reports, covered by the EU Standard
Contractual Clauses (2021/914) incorporated in our data-processing
agreement with Airbrake.
Cookies
We use only cookies that are necessary for the service to work — no
analytics cookies and no third-party tracking cookies:
-
Session cookie (encrypted): keeps you logged in during a
visit. It expires when you close your browser, and we clear the session
when we hand you back to a website you signed in to.
-
"Remember me" cookies (encrypted): set only if you tick
"Remember me", so you stay signed in across visits. Removed when you log
out. These hold your e-mail, user ID and vault key — which is also why
your vault key never needs to be stored on our servers.
-
Language cookie: set only if you switch language,
remembering your choice.
Your rights
Under the GDPR you can ask us for access to, correction of, deletion of, or
a copy of your personal data; ask us to restrict processing; and object to
processing based on legitimate interest. Write to
privacy@promiseauthentication.org and we will respond
within a month.
One practical note: because we store your e-mail address only as a
fingerprint, we cannot browse our records for it. Please include the e-mail
address you use with Promise in your request, so we can compute the
fingerprint and locate your data.
If you are unhappy with how we handle your data, you can complain to the
Danish Data Protection Agency (Datatilsynet),
datatilsynet.dk.
Changes to this policy
When we change this policy, we update this page and the date below. If a
change meaningfully affects how your data is handled, we will make that
clear on the site before it takes effect.
Last updated: 27 August 2026 (removed our log-management provider)