Privacy information
AllAuth provides sign-in, account security and organization access for connected applications.
Information used for authentication
AllAuth stores your account name, email address and profile image, connected login-provider identifiers, organization memberships and roles. Passwords are stored as hashes. Depending on the security features you enable, the service also stores passkey public credentials and two-factor authentication settings. Session records include security information such as timestamps, IP addresses and browser details.
Google and other login providers
When you choose a social login provider, AllAuth requests your basic profile and email address to authenticate your account and link the chosen login method. Google login requests only OpenID, profile and email permissions. This login does not request access to your Gmail messages, Drive files or Calendar.
Connected applications and organizations
Registered applications receive the identity information you authorize during sign-in. Organization owners and authorized administrators can manage membership and access. Administrative actions, including support impersonation, are recorded for security and accountability. Each connected application provides its own information about its use of your data.
Hosting and security
The service uses hosting, database and transactional email providers to operate authentication and deliver account-security messages. Access to account-management functions is controlled by authentication and role permissions. Account information is retained to provide access and meet operational and security needs.
Account access and requests
You can review your profile and active sessions in account settings. For questions about account information, deletion requests or this service, contact tom@onsavii.com.