Privacy Policy

Effective April 12, 2026 · Last updated April 12, 2026

1. Introduction

YouSeemLegit operates an authentication platform accessible at youseemlegit.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service, either as a business customer ("Client") or as an end user authenticating through a Client's application ("End User").

2. Information We Collect

From End Users

When an End User authenticates through our Service, we collect: email address, authentication provider used (Google, LinkedIn, or email/password), provider ID, session data, IP address (for security purposes), failed login attempt counts, and timestamps.

We do not collect payment information, browsing history, or device fingerprints beyond what is strictly necessary for security.

From Clients

When a business registers as a Client, we collect company name, contact information, branding configuration, redirect URIs, API credentials, and usage data.

3. How We Use Information

We use End User data solely to authenticate users on behalf of Clients, maintain secure sessions, detect and prevent fraud, and comply with legal obligations. We do not sell End User data, use it for advertising, or share it across different Clients.

4. Legal Basis for Processing (GDPR)

For users in the EEA, we process personal data on the basis of contract performance, legitimate interests (security, fraud prevention), legal obligation, and consent where explicitly obtained.

5. Data Retention

Data TypeRetention
Active session dataUntil session expires (1 hour default)
User account dataUntil deletion requested or 2 years inactive
Authentication logs90 days
Security logs1 year
Password reset tokens1 hour (auto-expired)
Email verification tokens24 hours (auto-expired)

6. Data Sharing

We do not sell personal data. We share data only with service providers necessary to operate the Service: Microsoft Azure (infrastructure), Upstash (rate limiting, IP addresses only), and Resend (transactional email). All providers are contractually bound to protect data.

7. Security

We implement industry-standard security measures including bcrypt password hashing, HTTPS/TLS encryption, signed JWT tokens, PKCE on OAuth flows, rate limiting, account lockout, and HTTP security headers. No system is completely secure — in the event of a breach we will notify affected parties as required by law.

8. Your Rights

Depending on your location, you may have the right to access, correct, delete, port, restrict, or object to processing of your personal data. To exercise these rights, contact privacy@youseemlegit.com. We will respond within 30 days.

9. Cookies

We use one session cookie (admin_session) for admin dashboard authentication (8-hour duration) and one session cookie (ca_session) for client account dashboard authentication (7-day duration). We do not use tracking, advertising, or analytics cookies.

10. Children's Privacy

Our Service is not directed to children under 13. We do not knowingly collect data from children under 13. Contact us immediately if you believe we have done so.

11. Changes

We may update this policy periodically. We will notify Clients of material changes via email. Continued use after changes constitutes acceptance.

12. Contact

Email: privacy@youseemlegit.com
Website: youseemlegit.com

© 2026 YouSeemLegit · Terms · DPA