Skip to content

Privacy Policy

What personal data Quathos Auth and the Quathos Account handle, on whose behalf, for how long, and what you can demand of us.

Version 1.0 In force since September 2, 2026 Updated September 2, 2026

Quathos LLC, a limited liability company organized under the laws of the State of Texas, United States, operates Quathos Auth, a multi-tenant identity platform, and the Quathos Account, the account used across Quathos products. This policy explains what we do with personal data, and it is written to be read — not to be survived.

1. Two roles, and why the difference matters

Almost every complaint about an identity service starts with someone asking the wrong company to delete their data. So, before anything else:

  • We are the controller for two groups of people: holders of a Quathos Account (the account for Quathos products, at accounts.quathos.com) and the administrators who use the Quathos Auth console at auth.quathos.com to run their own tenant. We decide why and how that data is processed, and this policy is our promise about it.
  • We are the processor (an operator, under Brazilian law) for the end users of our customers’ tenants — the people who sign in to a customer’s application through a page we host at auth.quathos.com or at the customer’s own domain. That sign-in page is operated by us on the customer’s behalf: the customer is the controller, decides everything, and we only execute. We do not mine that data, we do not sell it, we do not use it to train anything, and we do not use it to build any product. The Data Processing Addendum governs this case.

2. Who we are

  • Controller: Quathos LLC, a limited liability company organized under the laws of the State of Texas, United States, at 3008 Ross Ave, Suite 100, Office 210, Dallas, TX 75204, United States.
  • Data protection contact: privacy@quathos.com. That address reaches the people responsible for privacy requests.
  • Data Protection Officer / Encarregado (GDPR art. 37, LGPD art. 41): [dpo].
  • We are established in the United States. Representative in the European Union or the United Kingdom (GDPR art. 27): [euRepresentative].
  • Security reports and incident notices: security@quathos.com.

3. What we collect

As controller, about a Quathos Account or a console administrator:

  • Account: name, email address, preferred language and a password stored only as an argon2id hash. We never store your password in a readable form and we cannot recover it — only reset it.
  • Second factor: the TOTP secret of your authenticator app, encrypted at rest; recovery codes, stored only as hashes; and, when passkeys are available and you enrol one, the public key and credential identifier your device gives us — never the private key, which never leaves your device.
  • Sessions: creation, last activity and expiry, the IP address and the browser user agent of the sign-in, and which authentication methods were used. This is what lets you — and us — tell a legitimate session from a stolen one, and it is what the Sessions page shows you.
  • Organisations and members: which organisations you belong to, with what role, and the invitations you sent or received.
  • Applications: the OAuth clients you register — name, redirect URIs, allowed scopes and settings. Client secrets are stored only as hashes.
  • Tokens: authorisation codes, refresh tokens and device codes exist in our database only as hashes, tied to the session and the application that received them. Access tokens are short-lived signed JWTs that we do not store at all. Consent grants record which scopes you allowed to which third-party application.
  • Audit trail and authentication logs: an append-only record of what happened — the action, who did it, when, from which IP address and browser, and a minimal payload that never contains secrets, passwords or tokens.
  • Marketing consent: whether you opted in to product news, and the append-only history of every grant and revocation with the version of the text you saw. Opt-in only; the default is off.
  • Billing: plan, subscription status, invoices and the customer identifier issued by Stripe. Card numbers never reach us — the payment page is Stripe’s.
  • Support and contact: what you write to us, so that we can answer it.
  • Technical cookies, described in the Cookie Policy, and request metadata needed to run and defend the service. Tokens, passwords, one-time codes and secrets are never written to logs — that is a rule enforced in the codebase, not an aspiration.

As processor, on our customers’ instructions, a tenant holds the same categories about the customer’s own end users — account, second factor, sessions, organisations, consent grants, tokens and logs — plus whatever profile attributes the customer chooses to collect on its sign-up form. The customer decides which of those exist, for how long, and why.

4. Why we process it, and on what legal basis

PurposeDataLegal basis
Provide the service: sign-in, tokens, organisations, consoleAccount, membership, applications, tokensPerformance of a contract (GDPR 6(1)(b); LGPD art. 7, V)
Authenticate and keep accounts secureCredentials, second factor, sessions, IP, user agentContract and legitimate interests in security (GDPR 6(1)(b) and (f); LGPD art. 7, V and IX)
Audit trail, abuse and fraud preventionActions, actor, timestamp, IP, user agentLegitimate interests and legal obligations (GDPR 6(1)(f) and (c); LGPD art. 7, II and IX)
Billing, tax and accountingPlan, invoices, Stripe identifiersContract and legal obligation (GDPR 6(1)(b) and (c); LGPD art. 7, V and II)
Service notices and supportName, email, messageContract and legitimate interests (GDPR 6(1)(b) and (f); LGPD art. 7, V and IX)
Product news by emailEmail, consent historyConsent, opt-in and withdrawable at any time (GDPR 6(1)(a); LGPD art. 7, I)
Optional cookies, if we ever use anyUsage measurementConsent, freely given and withdrawable (GDPR 6(1)(a); LGPD art. 7, I)

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not profile you to make decisions about you by automated means. Rate limiting and brute-force protection look at request counts, not at who you are. No part of your data trains any model.

5. Who else touches the data

Only the parties needed to run the product, each under a written agreement and only for the purpose we set. The current list, with roles and locations, is published and kept up to date on our Subprocessors page. In summary:

  • Our hosting provider, Hetzner Online GmbH, which holds the database, the cache and the backups in Germany (Falkenstein and Nuremberg).
  • Quathos Mailer, the sibling product that delivers every email. No transactional email leaves through any other route, in any environment.
  • Stripe, for checkout, subscription and invoices of the product.
  • Cloudflare, which serves the DNS of the quathos.com zone and issues the TLS certificates for tenant subdomains. It sees hostnames, not people.
  • An SMS provider, only for tenants whose administrators turn on one-time codes by SMS.
  • The applications you sign in to. When you authorise an application, it receives the identity claims and scopes you approved — your name, your email, your organisation — and from then on that application is responsible for them under its own policy. This is your instruction, given on the consent screen, or your customer’s instruction when the application is theirs.

Beyond those, we disclose data only when the law compels it. When we are legally allowed to tell you first, we do — a demand we are permitted to disclose is a demand you deserve to know about. If the business is ever sold or merged, data follows the service, and this policy binds whoever takes it over until they publish their own and tell you.

6. International transfers

Your data is stored at rest in the European Union, on infrastructure operated by Hetzner Online GmbH in Germany (Falkenstein and Nuremberg). We are established in the United States, Stripe and Cloudflare operate from the United States, and our team reaches the systems from where it is — so personal data crosses borders even though it rests in one place. Where the law requires a transfer mechanism, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant) and, for Brazilian data, on the equivalent instruments recognised by the ANPD, plus the safeguards described in the next two sections.

7. How long we keep things

DataKept forWhy
Sign-in sessionUp to 14 days; ends after 24 hours without activity, or when you sign out or revoke itExpiry is enforced server-side, not only by the cookie
Second-factor challenge5 minutesLong enough to open the authenticator app, too short to be worth stealing
Email confirmation link24 hours, single useA link that outlives its purpose is a spare key
Password reset link1 hour, single useIt grants access to an account; the shorter, the better
Organisation invitation7 daysAfter that, the inviter sends a new one
Authorisation code60 seconds, single useIt only has to survive one redirect
Access token15 minutes by default; not storedSigned, self-contained, and gone before it matters
Refresh token30 days since last use, never more than 1 year; only its hash is storedRotated on every use; reuse of an old one revokes the whole family
Audit trail and authentication logsWhile the tenant exists, or the shorter period set by your planAppend-only by database trigger; erasing one event would leave a hole where the evidence was
Marketing consent historyWhile the account exists, and afterwards for as long as we may need to prove your choiceIt is the record that you asked — or asked us to stop
Invoices and billing recordsAs tax and accounting law requiresWe cannot delete these on request, and we say so plainly
Idempotency keys24 hoursLong enough to stop a duplicate write, short enough to forget
BackupsUp to 30 days after deletionDeleted data disappears from backups as they rotate; we do not restore a backup to resurrect it
Closed account or tenantDeleted within 30 days of the requestDeletion is requested, not instant: the 30 days are the last chance to change your mind, and the window to have your data returned

8. How we protect it

  • Isolation between tenants is enforced by the database itself, through row-level security on every identity table, and the application connects with a role that cannot bypass it. The tenant is derived from the host that received the request, never from anything the client sends; without a tenant in context, the database returns nothing.
  • Passwords are hashed with argon2id. TOTP secrets and the private signing keys of each tenant are encrypted at rest with keys held outside the database. Session tokens, refresh tokens, authorisation codes, recovery codes and client secrets are stored only as hashes: we cannot show you your own secret twice, and we consider that a feature.
  • Each tenant signs its tokens with its own key pair, rotated automatically. A key that leaks in one tenant proves nothing about another.
  • The audit trail is append-only by database trigger, and the application role has no permission to update or delete it — two independent layers, so a bug in application code cannot become a rewrite of history.
  • The session cookie is HttpOnly and never reaches page JavaScript; the browser never talks to the API directly. State-changing requests carry a double-submit CSRF token, and a strict Content Security Policy allows no script from any other host.
  • Our own operators must sign in with a second factor before they can touch anything across tenants, and every such action is audited.
  • The Security page describes these controls in detail — and, first, what we do not yet claim. No security measure is perfect. If a breach ever affects your personal data, we notify the people and authorities the law requires, without undue delay, and we tell you what we know rather than what sounds best.

9. Your rights

Wherever you live, and regardless of which law applies to you, we offer the same set of rights over the data we control:

  • Know what we hold about you and why, and get a copy of it.
  • Correct what is wrong or incomplete — most of it from the Profile page, without asking anyone.
  • Delete it, within the limits of the retention table above.
  • Take it elsewhere, in a machine-readable format.
  • Object to processing based on legitimate interests, or ask us to restrict it.
  • Withdraw consent at any time, as easily as you gave it — marketing from the Profile page or from the link in any message, cookies from the preference panel linked on every page.
  • See and revoke the sessions and the applications connected to your account, from the Sessions page.
  • Know who we shared data with, and ask us to confirm the anonymised or public status of anything we hold.
  • Be free from discrimination for exercising any of this: the price and the product do not change because you asked.

Californians: we do not sell or share personal information, and we do not use or disclose sensitive personal information beyond what is necessary to provide the service, so the "Do Not Sell or Share" and "Limit the Use of Sensitive Personal Information" rights have nothing to act upon here. We still honour Global Privacy Control signals as a refusal of all non-essential cookies. If we deny a request, you may appeal by replying to our answer; if the appeal fails, you may complain to your state Attorney General.

To exercise any of this, write to privacy@quathos.com. We answer within 30 days — the shortest deadline among the laws that reach us — and we may need to confirm your identity first, which we do with the data we already have, never by asking for a new document. An authorised agent may act for you with proof of authority. If our answer does not satisfy you, you may complain to the ANPD in Brazil, to your supervisory authority in the EU or the UK, or to your state Attorney General in the United States.

10. Children

The Quathos Account and the Quathos Auth console are tools for work and are not directed to children. We do not knowingly create such accounts for anyone under 16, and if we learn that we hold a child’s personal data without a lawful basis, we delete it. Whether a customer’s application admits minors is that customer’s decision and responsibility, as controller.

11. Changes to this policy

When something material changes — a new purpose, a new category of data, a new party — we update the version and the date at the top of this page and tell account holders and tenant administrators by email before it takes effect. Quiet edits to a privacy policy are how trust is spent.

12. Contact

Privacy: privacy@quathos.com. Security: security@quathos.com. Contracts: legal@quathos.com. Everything else: contact@quathos.com.