Privacy Policy

Effective date: 15 July 2026

This Privacy Policy explains what personal information Authello collects, how we use it, and the choices you have. It should be read alongside our Terms of Service and Security page.

Summary

Authello provides encrypted access management tools for organisations. We collect account, organisation, billing, support, and usage information needed to run, protect, improve, and support the service. We do not sell customer vault content.

Account data
We use registration and profile details to provide accounts, organisations, invitations, and support.
Security data
We process session, device, audit, and access information to protect users and organisations.
Your rights
You can ask to access, correct, delete, or restrict personal data where applicable law allows.

1. Information We Collect

We collect information you provide when you register, create or join an organisation, manage users, contact support, subscribe to a plan, or otherwise use Authello. This may include your name, email address, organisation name, billing details, role, permissions, and support messages.

We also collect usage and technical information such as IP address, browser type, device information, session activity, approximate location, security events, audit records, and pages or features used.

2. Vault and Security Information

Authello is designed to store shared passwords, OTP records, and related access information in encrypted form. Some metadata, such as record names, group membership, permissions, timestamps, and activity history, may be processed so the service can organise records, enforce access control, and support audit workflows.

More detail about our encryption approach is available on our Security page.

3. How We Use Information

We use personal information to provide and administer Authello, authenticate users, manage organisations, process invitations, deliver support, maintain billing, send service notices, detect abuse, secure accounts, troubleshoot issues, improve product reliability, and comply with legal obligations.

4. Cookies and Similar Technologies

We use cookies and similar technologies for essential functions such as login sessions, security, CSRF protection, preferences, and service reliability. Where optional analytics or marketing technologies are used, they should be handled according to applicable consent requirements.

5. Sharing Information

We do not sell personal information or customer vault content. We may share information with service providers that help us operate Authello, such as hosting, payments, email delivery, analytics, support, security, and infrastructure providers. We may also share information when required by law, to protect rights and safety, or as part of a business transaction such as a merger or acquisition.

6. Data Security

We use technical and organisational measures designed to protect personal information, including encrypted vault storage, access controls, session protections, audit-focused records, and security monitoring. No internet service can be guaranteed to be completely secure, so users should also protect their devices, credentials, MFA methods, recovery keys, and admin permissions.

7. Data Retention

We keep personal information for as long as needed to provide the service, meet legal and accounting requirements, resolve disputes, enforce agreements, maintain security, and support legitimate business operations. Retention periods may vary depending on the type of information and the organisation's configuration.

8. Your Data Protection Rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information. You may also have the right to withdraw consent where processing is based on consent. Some requests may need to be handled through your organisation if your account is managed by an organisation using Authello.

9. International Transfers

Authello and its providers may process information in countries other than your own. Where required, we use appropriate safeguards for international transfers of personal information.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our service, legal requirements, or privacy practices. Material updates will be posted on this page or communicated through reasonable channels.

11. Contact

Questions about this Privacy Policy can be sent to [email protected].