Authany
Privacy Policy隐私政策
Last updated: 30 September 2026最后更新:2026 年 9 月 30 日
Who this covers适用范围
Authany (“we”) runs authany.com and docs.authany.com, the console at manage.authany.com, the platform sign-in at id.authany.com, and each project’s sign-in page at {project}.authanyid.com or, where we have enabled it, on the project’s own domain. This policy explains how we handle personal information in these services.Authany(下称“我们”)运营 authany.com 和 docs.authany.com、管理台 manage.authany.com、平台登录页 id.authany.com,以及每个项目在 {项目}.authanyid.com 上(或经我们开通、在项目自有域名上)的登录页。这份政策说明我们在这些服务中如何处理个人信息。
We handle two kinds of information, in two different roles:我们处理的信息分两类,角色不同:
- Your Authany account (the developer account). We decide how it is handled, so we are responsible for it.你的 Authany 账号(开发者账号):由我们决定如何处理,我们对这部分信息负责。
- The users of your project (end users). You decide what is collected and how it is used, so you are responsible for it, and we process it on your behalf, as you configure it. Your users should contact you first about their information, and you need to give them your own privacy notice.你项目里的用户(终端用户):收集和使用哪些信息由你决定,由你负责;我们受你委托,按你的配置处理。你的用户对自己的信息有疑问,应先联系你;你需要向他们提供你自己的隐私说明。
What we process我们处理哪些信息
Your Authany account你的 Authany 账号
- Your email address, your name if you give one, and your account settings.邮箱地址、姓名(如果你填写)和账号设置。
- Your password, stored only as a one-way bcrypt hash that we cannot read back, and your two-step verification settings if you turn it on.密码:只保存 bcrypt 单向哈希,我们无法还原出原文;开启两步验证时,还有相应的设置。
- The projects you create, their configuration and collaborators, and any email you send us.你创建的项目、项目配置和协作者,以及你写给我们的邮件。
Your project’s user data, on your behalf你项目里的用户数据(受你委托)
Whatever your project collects: for example email addresses, password hashes, passkeys, identifiers and profile data returned by social sign-in (WeChat, Google, Apple and others), two-step verification settings, sessions and devices, and any data you write through the console.你的项目收集的内容,例如邮箱、密码哈希、通行密钥、第三方登录(微信、Google、Apple 等)返回的标识和资料、两步验证设置、会话和设备信息,以及你通过管理台写入的资料。
Usage and security information使用和安全信息
- Audit logs: events such as sign-ins and profile changes, with the time, the IP address and the country derived from it, and browser details.审计日志:登录、资料变更等事件,包括时间、IP 地址及据此推断的国家或地区,以及浏览器信息。
- Usage counters, such as the number of emails each project sends, used to enforce the free plan’s limits.用量计数,例如每个项目发出的邮件数,用来执行免费版的额度。
- Server logs, used to diagnose problems.服务器运行日志,用于排查故障。
CookiesCookie
authany.com sets one cookie, authany_lang, and only when you switch language; it remembers your choice for a year and is shared with docs.authany.com and the console. The sign-in pages use cookies to keep you signed in (by default until 30 days without use, and at most a year), to carry a sign-in in progress, to remember your language and colour scheme, to remember that you have signed in on this browser before (90 days) and, if you choose, to skip two-step verification on this device (30 days by default). They also set a visitor ID that lasts 20 minutes and is used only to count sign-in page views. If a project turns on Turnstile or reCAPTCHA, that provider may set its own cookies. The console keeps you signed in with a token stored in your browser’s local storage. We use no advertising cookies and no third-party analytics.authany.com 只在你切换语言时设置一个 Cookie:authany_lang,记住你的选择一年,文档站和管理台共用。登录页用 Cookie 维持登录状态(默认连续 30 天未使用或满一年即失效)、保存进行中的登录步骤、记住语言和深浅色、记住你曾在这个浏览器登录过(90 天),以及在你选择后让这台设备暂时免去两步验证(默认 30 天);另有一个 20 分钟有效的访客 ID,只用于统计登录页的浏览量。项目开启 Turnstile 或 reCAPTCHA 时,服务商可能设置它自己的 Cookie。管理台用保存在浏览器本地存储中的令牌维持登录。我们不使用广告 Cookie,也不使用第三方统计。
How we use it我们怎么使用这些信息
- To run the service: sign-in, sessions, sending codes and notification emails, and the console’s features.提供服务:登录、会话、发送验证码和通知邮件,以及管理台的各项功能。
- For security and abuse prevention: spotting unusual sign-ins, brute-force attempts and bots, and enforcing the free plan’s limits.安全和防滥用:识别异常登录、暴力破解和机器人,执行免费版的额度。
- To contact you: replying to your emails and telling you about important changes to the service or this policy.与你联系:回复你的邮件,通知服务或本政策的重要变化。
We do not sell personal information or use it for advertising or marketing profiles. End users’ data is used only for the purposes you have entrusted to us.我们不出售个人信息,也不用于广告或营销画像;终端用户的数据只用于你委托的目的。
Where data is stored and cross-border transfers存放地点和跨境
Data is stored on servers in Hong Kong, and an off-site backup copy is kept on a computer we operate. Emails are sent through Resend in the United States. If your users are in mainland China, having us process their personal information in Hong Kong and send their emails through the United States may count as a cross-border transfer; you are responsible for assessing that and for meeting requirements such as notice and separate consent.数据存放在香港的服务器上,另有一份异地备份存放在我们自己管理的电脑上;邮件经美国的 Resend 发送。如果你的用户在中国内地,你把他们的个人信息交由我们在香港处理、经美国发送邮件,可能构成个人信息出境;你需要自行评估,并履行告知、取得单独同意等要求。
How long we keep it保存多久
We keep information only as long as needed for the purposes above:我们只在实现上述目的所需的期限内保存信息:
- Account and project data is kept while your account exists. After you ask us to delete it, we delete it from the production database within 30 days; copies in audit logs and backups are removed as described below.账号和项目数据:账号存续期间保存;你要求删除后,我们在 30 天内从生产数据库删除,审计日志和备份中的副本按下文所述清除。
- End-user data is under your control. When you delete a user in the console, their account data is removed from the production database at once. Audit-log entries about them, which can include their email address and the IP addresses they used, stay in the project’s audit log (below), and copies in backups expire with the backups.终端用户数据:由你控制;你在管理台删除用户后,其账号数据立即从生产数据库删除。与该用户有关的审计日志(可能含其邮箱和使用过的 IP 地址)留在项目的审计日志里(见下条),备份中的副本随备份到期删除。
- Backups. The server takes a backup every day and keeps each one for about two weeks. A separate off-site copy keeps every backup from the last 30 days and the first one of each month for 12 months, so deleted data can remain in backups for up to about 13 months before it is removed automatically. Backups are used to recover from a disaster and to rehearse upgrades before they go live; copies made for a rehearsal are deleted after 30 days.备份:服务器每天备份一次,每份保留约两周;另有一份异地副本,保留最近 30 天的全部备份,更早的每月保留第一份、保留 12 个月。所以已删除的数据最长可能在备份中留存约 13 个月,之后自动删除。备份用于灾难恢复,以及升级上线前的演练;演练用的副本 30 天后删除。
- Audit logs are kept for as long as the project exists. On the free plan, the console shows the last 30 days.审计日志:在项目存续期间保存;免费版可以在管理台查看最近 30 天的记录。
- Server logs, which include IP addresses and details of the requests we handle, are used to diagnose problems and protect the service. They are deleted automatically as they rotate; how long an entry lasts depends on how busy the service is, and some can stay for several months.服务器运行日志:包含 IP 地址和请求的相关信息,用于排查故障和保护服务。日志滚动时自动删除,一条记录能留多久取决于服务的繁忙程度,个别可能保留几个月。
Security安全
- All traffic is encrypted with HTTPS.全站使用 HTTPS 加密传输。
- Passwords are stored only as bcrypt hashes.密码只保存 bcrypt 哈希。
- Each project’s user pool is kept separate from every other project’s.每个项目的用户池相互隔离。
- The administrative API we use to run the platform can only be reached from our internal network.我们运营平台用的管理接口只能从内部网络访问。
- Data is backed up daily, with an off-site copy.数据每天备份,并保存异地副本。
No system is perfectly secure. If we become aware of a security incident that may affect you, we will tell you by email without undue delay.没有任何系统能保证绝对安全。如果我们发现可能影响你的安全事件,会及时通过邮件通知你。
Your rights你的权利
- Access and correction in the console and your account settings.查阅和更正:在管理台和账号设置里进行。
- Deletion and export of your account and project data, including an export of your project’s users: email hello@authany.com.删除和导出账号与项目数据(包括导出项目的用户):发邮件到 hello@authany.com。
- Withdrawing consent or closing your account: email us as well.撤回同意、注销账号:同样发邮件给我们。
We reply within 30 days. Requests from your end users are yours to handle: you can find, edit and delete users in the console, and we will export your users for you and help in other ways where needed.我们会在 30 天内答复。终端用户向你提出的请求由你处理:你可以在管理台查找、修改和删除用户;需要导出用户时由我们代为导出,其他需要时我们也会协助你。
Children未成年人
The service is for developers and businesses, not for children under 14. If your app is for minors, you are responsible for obtaining guardian consent and meeting the applicable legal requirements.我们的服务面向开发者和企业,不面向 14 周岁以下的儿童。如果你的应用面向未成年人,你需要取得监护人同意,并遵守相应的法律要求。
Changes to this policy政策变更
When we update this policy we publish it here with a new date. We tell you about significant changes in advance, by email to your account address.我们更新这份政策时,会在本页公布并更新日期;重大变更会提前通过你的账号邮箱通知你。
Contact联系我们
For any privacy question, email hello@authany.com.关于隐私的任何问题,请发邮件到 hello@authany.com。
This policy is published in Chinese and English. If the two differ, the Chinese version prevails.本政策有中文和英文两个版本,如有不一致,以中文版为准。