Privacy Policy
Last updated: 2026-07-06
What we collect
- Client accounts (you, the developer): your email address, app name, authorized domains, and hashed credentials.
- End users of your app: email address, a user ID, and sign-in timestamps. Phuze is passwordless — we never store passwords.
- Usage metrics: monthly active user counts and daily login counts per client, used for quota enforcement and billing.
- Waitlist / alpha requests: the email address you submit.
What we use it for
Providing the authentication service, enforcing quotas, sending transactional email (sign-in links, activation codes), and contacting you about your account. We do not sell personal data or use it for advertising.
Where it lives
Data is stored on Google Cloud (Firebase Firestore, hosted in the United States). Transactional email is delivered via Resend. These are our only subprocessors.
Your users are yours
End-user records created through your integration belong to you and are processed on your behalf. You can export them at any time and delete them via the API.
Retention and deletion
Account and end-user data is kept while your client is active. When you delete your client (via the API's delete flow or by emailing us), the client record, its users, sessions, and quota data are permanently removed. Sign-in links and activation codes expire automatically.
Your rights
You can request access to, correction of, or deletion of your personal data at any time by email. If you are in a jurisdiction with statutory privacy rights (e.g. GDPR), we honor those requests within the required timeframes.
Changes
We will announce material changes to this policy by email to registered clients.
Questions? Contact us at phuze-alpha@edato.me.
Operated by 沐聿有限公司 (統一編號 00017890).