Privacy Policy Privacy & Terms

Effective August 20, 2026

Suloro Privacy Policy

When you use our services, you’re trusting us with your information. We understand this is a big responsibility and work hard to protect your information and put you in control.

1. Introduction

This Privacy Policy is meant to help you understand what information we collect, why we collect it, and how you can update, manage, export, and delete your information. Suloro is dedicated to providing privacy-first digital identity, Single Sign-On (SSO) infrastructure, authentication gateways, developer consoles, and productivity platforms across the web, desktop, and mobile devices.

You can use our services in a variety of ways to manage your privacy. For example, you can sign up for a Suloro Account if you want to store and synchronize your digital identity across authorized platforms, configure fine-grained OAuth 2.0 PKCE permissions for third-party developer applications, and take control of your profile claims. You can also interact with public Suloro resources and technical documentation without signing in. Across all our services, you have direct, real-time control over whether we store certain types of information and how that data is utilized.

2. Our Privacy & Security Principles

Suloro was engineered from the first line of code around six immutable principles designed to protect your digital sovereignty:

1. Zero Data Sales & Zero Ads

We never sell, rent, or trade your personal data to advertisers, brokers, or third parties. We do not build commercial advertising profiles or monetize your attention.

2. Privacy by Design & Default

Privacy protections are active automatically. We enforce least-privilege data collection, meaning we only request the absolute minimum data required to deliver authentication.

3. End-to-End Cryptographic Security

Your credentials are encrypted with TLS 1.3 in transit, AES-256 at rest, and salted memory-hard key derivation functions. Passwords are never visible or reversible.

4. Total User Sovereignty

You own your data. You can view, audit, export into standard JSON, or permanently erase your account and all associated tokens with complete independence.

5. Granular Delegated Consent

Third-party apps connecting via Sign in with Suloro never receive data without your active consent on a clear prompt, and never see your account password.

6. Universal Global Compliance

We apply the highest international standards of GDPR, CCPA/CPRA, and child privacy protections to all users globally, regardless of jurisdiction.

3. Information Suloro Collects

We want you to understand the types of information we collect as you interact with our services. We collect information to deliver reliable Single Sign-On, protect your credentials against unauthorized access, mitigate brute-force cyber threats, and facilitate delegated developer integrations.

A. Things You Create or Provide to Us

When you create a Suloro Account, you provide us with essential identity claims and credentials necessary to authenticate and maintain your profile:

  • Primary Display Name & Profile Identifier: Your chosen legal name or preferred display name used to identify your account across authenticated services and during OAuth consent prompts.
  • Email Address & Recovery Contact: Your primary email address used as your unique login identifier, for cryptographic password reset workflows, and for essential security incident alerts.
  • Cryptographic Password & Credential Hashes: High-entropy user passwords, which are immediately processed using memory-hard salted key derivation algorithms before storage. We never store or transmit your password in plaintext.
  • Date of Birth & Age Verification: Collected strictly for international age verification and child safety compliance. Setting your date of birth ensures appropriate privacy guardrails are applied. Once verified, this date cannot be altered without identity verification, preventing age falsification or unauthorized account transfer.
  • Profile Avatar & Custom Handle: An optional image or custom handle you upload to personalize your identity across connected Suloro services and authorized applications.
  • Developer Application Configurations: If you utilize the Suloro Developer Console, you provide technical metadata including application names, 1:1 square brand icons, authorized OAuth 2.0 redirect URIs, and delegated scope definitions.

B. Information We Collect as You Use Our Services

When you access Suloro portals or authenticate via Single Sign-On, our systems automatically collect technical operational diagnostics to preserve session integrity and detect malicious intrusion:

  • Device & Hardware Signatures: Device model, operating system architecture, screen resolution, browser rendering engine, and language preferences to deliver optimized rendering and detect anomalous device switching.
  • Network & Routing Telemetry: IP addresses, network autonomous system numbers (ASNs), and coarse geographic region data used to detect credential stuffing attacks from compromised proxy networks.
  • Session Lifecycles & Token Exchanges: Timestamps of sign-in events, token refresh handshakes, OAuth code exchange verifiers, and session invalidation requests.
  • Security Event Logs: Failed password counters, exponential backoff locks, anomalous token requests, and rate-limiting triggers.

C. Client-Side Storage Technologies

To eliminate sluggish server roundtrips and enable lightning-fast multi-account switching on a single device, Suloro uses modern client-side storage mechanisms:

  • IndexedDB Storage: Encrypted client-side storage used to maintain sandboxed account profiles in the Suloro Account Chooser without sharing token contexts between different signed-in users.
  • Session Storage & Web Crypto API: Temporary in-memory cryptographic state used to generate SHA-256 PKCE code challenges during OAuth authorization flows.
  • Zero Commercial Ad Tracking: We do not deploy third-party advertising cookies, cross-site behavioral tracking scripts, or commercial pixel tags.

4. Why Suloro Collects Data

We process personal and technical data strictly for specific, legitimate purposes that are directly tied to delivering, securing, and maintaining the Suloro ecosystem:

Authentication & SSO

Verifying identity claims securely across first-party services and authorized third-party applications via OAuth 2.0 PKCE.

Platform Threat Defense

Detecting credential stuffing, mitigating automated brute-force attacks, and stopping unauthorized session hijacking.

Developer Integrations

Issuing cryptographic access tokens and managing delegated scopes for verified third-party developer applications.

Direct Communication

Sending vital security notifications, password reset links, suspicious sign-in alerts, and statutory policy announcements.

Operational Commitments

We will never process your personal data for automated commercial profiling, behavioral ad targeting, or commercial resale. Any new use of data outside the scope of this Privacy Policy will require your explicit, affirmative prior consent.

5. Your Privacy Controls

You maintain complete sovereignty over your information. Within your Suloro Account, you have access to self-service privacy controls:

  • Profile Information Management: Update your display name, profile avatar, and account credentials directly from your dashboard at any time.
  • Active Session Management: View all active devices, browsers, and IP locations signed into your account. You can terminate individual sessions or execute a global sign-out that revokes all refresh tokens simultaneously across all devices.
  • Linked Application Audit: Review all third-party developer applications that have been granted access to your profile claims, inspect their approved scopes, and revoke their permissions instantly with a single click.
  • Authentication Security Review: Audit recent sign-in history, rate-limiting triggers, and password update events to verify account integrity.

6. Sign in with Suloro & Third-Party Applications

When you choose to use "Sign in with Suloro" on third-party web apps, games, mobile applications, or developer platforms, Suloro serves as your secure cryptographic identity provider. We ensure data shared with external parties is governed by strict safeguards:

Granular User Consent Protocol

Third-party applications never receive automatic access to your information. Before any data is shared, Suloro displays a transparent consent screen detailing the exact claims requested by the developer (such as Display Name, Email Address, or Date of Birth). Data is only released upon your explicit click of "Allow".

Strict Protections for Third-Party Logins:

  • Zero Password Sharing: Third-party applications never see, handle, or store your Suloro account password. Authentication is validated purely through cryptographically signed OAuth 2.0 PKCE tokens.
  • Scope Minimization: Developers are restricted to least-privilege scoping. Applications cannot request or access unapproved profile attributes, other linked applications, or private security logs.
  • Real-Time Permission Revocation: You can revoke an application's access at any time through the Linked Apps tab in your Suloro Account. Revocation immediately invalidates existing access and refresh tokens, preventing any further data requests.
  • Mandatory Developer Compliance: Every application registered on the Suloro Developer Console is legally bound by our Developer Platform Terms to maintain accessible Privacy Policy and Terms of Service URLs, uphold data security, and never harvest user credentials.

7. Sharing Your Information

Suloro does not sell, rent, trade, or share your personal information with third-party companies, organizations, or individuals, except under the following strictly defined conditions:

  • With Your Explicit Affirmative Consent: When you authorize a third-party application via "Sign in with Suloro", we share only the specific claims you explicitly approved on the consent screen.
  • With Enterprise Domain Administrators: If your Suloro Account is provided or managed by your employer, school, or organization, your domain administrator may have administrative access to review security logs, reset passwords, or manage organization-wide access.
  • With Cloud Infrastructure Service Providers: We partner with enterprise datastore, compute, and Anycast network edge providers strictly to host infrastructure, maintain database clusters, mitigate DDoS attacks, and deliver sub-50ms latency globally. These providers process information exclusively under our instructions and are bound by strict non-disclosure agreements and industry-standard security certifications.
  • For Legal & Safety Compliance: We will disclose information if required by applicable statutory law, valid subpoena, enforceable court order, or governmental mandate, or to protect the safety, rights, and property of Suloro, our users, and the public.

8. Keeping Your Information Secure

We deploy defense-in-depth security architectures to ensure that every layer of the Suloro ecosystem is protected against unauthorized access, data alteration, and cyber threats:

  • TLS 1.3 Transport Encryption: All data in transit is encrypted using modern TLS 1.3 protocols with Perfect Forward Secrecy (PFS) and HTTP Strict Transport Security (HSTS).
  • AES-256 Storage Encryption: All user records, session caches, and cryptographic signing keys are encrypted at rest using AES-256 encryption across isolated, multi-region datastores.
  • Memory-Hard Password Hashing: User passwords are never stored in plaintext or reversible formats. Passwords are salted with cryptographically secure random salts and hashed using memory-hard algorithms designed to defeat GPU and ASIC dictionary attacks.
  • Adaptive Exponential Rate Limiting: Our authentication endpoints enforce progressive cooldown locks (30s, 60s, 120s, 300s, up to 900s) upon repeated failed login attempts, rendering automated credential stuffing ineffective.
  • Cryptographic Multi-Session Isolation: Each account session stored on the client device is sandboxed in its own isolated cryptographic context, preventing session leakage between multiple active accounts.

9. Exporting & Deleting Your Information

We believe in total data portability and the absolute right to erasure. You can export your data or permanently delete your account at any time.

A. Exporting Your Data Archive

You can generate a comprehensive, machine-readable JSON archive of your personal profile attributes, authentication records, active session logs, and registered developer OAuth applications through your account settings.

B. Permanently Deleting Your Suloro Account

How to Delete Your Account (Step-by-Step):

To permanently delete your Suloro Account and all associated data records:

  1. Sign in to your Suloro Account dashboard.
  2. Navigate to the Data & Privacy section in the navigation menu.
  3. Scroll down to the bottom of the page.
  4. Click on the Delete Account button.
  5. Enter your account password when prompted to confirm your identity.

Upon password confirmation, the deletion process executes immediately. Your account credentials, profile attributes, active session tokens, and registered OAuth applications are permanently and irreversibly purged from our active datastores.

10. Retaining Your Information & Erasure Cycles

We retain personal data only as long as necessary to maintain your active account and fulfill the security purposes set forth in this policy:

  • Active Account Profile Data: Retained in active datastores for the lifetime of your account until modified or deleted by you.
  • Ephemeral Security Telemetry: Network logs, IP addresses, rate-limiting counters, and session diagnostics are automatically cycled and purged after rolling 90-day retention windows.
  • Deleted Account Records: Once you complete account deletion, your primary records are purged immediately. Ephemeral backup snapshots are permanently overwritten in standard rotational cycles.

11. All Ages, Children Safety & Global Regional Laws

Suloro is designed for users worldwide across all age groups and geographies, adhering strictly to regional data protection frameworks:

A. Minor & Children Privacy Safeguards

We take the protection of minors extremely seriously. In compliance with the U.S. Children's Online Privacy Protection Act (COPPA), EU GDPR Age of Digital Consent rules, and global child safety statutes:

  • We do not knowingly collect personal information from children under 13 (or under 16 in certain European jurisdictions) without verifiable parental consent.
  • Date of birth is strictly verified during registration to ensure age-appropriate safeguards and prevent deceptive account creation.
  • Accounts belonging to minor users are never subject to commercial targeting, profiling, or public indexation.

B. European Union, EEA & United Kingdom (GDPR & UK GDPR)

If you reside in the European Economic Area or the United Kingdom, you possess statutory rights under Articles 15–22 of the GDPR, including the Right of Access, Right to Rectification, Right to Erasure, Right to Restriction of Processing, Right to Data Portability, and Right to Object. Our legal bases for processing data include Contractual Necessity (Art. 6(1)(b)), Legitimate Interests for threat defense (Art. 6(1)(f)), and Affirmative Consent for OAuth delegations (Art. 6(1)(a)).

C. United States Privacy Frameworks (California CCPA/CPRA & State Laws)

Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), as well as privacy statutes in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states, residents have the right to know, access, correct, and delete personal data. Suloro does not sell personal information or share personal data for cross-context behavioral advertising.

D. Asia-Pacific, India & Global Frameworks

We uphold data sovereignty and privacy legislation across all regions, including the Digital Personal Data Protection Act 2023 (India DPDP Act), Singapore Personal Data Protection Act (PDPA), Australia Privacy Act 1988 (Australian Privacy Principles), Japan Act on the Protection of Personal Information (APPI), Brazil Lei Geral de Proteção de Dados (LGPD), and Canada Personal Information Protection and Electronic Documents Act (PIPEDA).

12. About This Policy, Amendments & Contact

We may periodically update this Privacy Policy to reflect technological improvements, security enhancements, or legal requirements. We will never reduce your rights under this Privacy Policy without your explicit consent. Significant amendments will be announced with prominent notices on our website and within your dashboard.

Suloro Support & Privacy Contact

If you have any questions, feedback, or privacy inquiries regarding this policy, please contact our support team:

Email: support@suloro.com

Account Portal: https://accounts.suloro.com/