- Account
- E-mail address, name when given, role, organization, password as an Argon2id hash, last sign-in. Kept while the account exists.
- Devices and session
- Browser and system family of each trusted device (“Chrome on Windows”), when it was trusted and last used; the browser keeps a random secret in a cookie, the server its hash. 90 days after last use. One session per account, 30 days.
- Sign-in records
- Keyed hashes of the e-mail and network addresses, the outcome and the country when the network states it. 90 days. A network address is kept in clear only after a wrong password, to block abuse: 24 hours.
- Credential-sharing signals
- Daily counts per account and organization over 30 days: devices, countries, sessions ended by another sign-in, API requests per hour. Identified by a keyed hash. 90 days.
- API usage
- Requests per day per account and organization: 13 months. The per-request log: 90 days. After an account or its organization is deleted, these counts stay without the account, key or organization, until the same limits.
- Access requests
- Name, company, e-mail and purpose: 12 months after the request is handled.
- Why
- To give access to the service and apply the plan of each organization, to secure accounts and detect shared or stolen credentials, and to bill.
- Cookies
- The session cookie (30 days) and the device cookie (90 days), both needed to sign in. No advertising or analytics cookie, no third-party tracking, no sale of data.
- Recipients
- The mail provider that delivers sign-in, reset and device links; Stripe, for payments, once billing is on. A new password is checked against known data breaches (Have I Been Pwned) with the first 5 characters of its SHA-1 hash only.
- Rights
- Access, rectification, erasure, portability and objection: ask at the address below; an answer within one month. A complaint can go to the data protection authority (in France, the CNIL).