PRIVACY
Privacy Policy
Plain language. No boilerplate. Just what we actually do.
Last updated: June 2026
What we collect
| Data |
Details |
| Builder account |
Name, email address, and username provided at registration. |
| End-user email |
Optional. Only stored if you explicitly pass it in the API request. We recommend using a non-PII internal ID instead. |
| Consent metadata |
Scope keys, consent status (pending / approved / declined / revoked), and timestamps. |
| Audit events |
Event type, agent, actor, IP address, user-agent string, and timestamp — for the compliance record and activity feed. |
| API key hash |
A bcrypt hash of your API key. The key itself is never stored. |
What we do not collect
-
✗
Passwords
— End users have no Permitly account. Nothing to store.
-
✗
Payment data
— Billing is handled by Stripe. We never see card numbers or banking details.
-
✗
OAuth tokens
— We do not proxy OAuth flows. We store consent metadata, not access tokens.
-
✗
Plaintext API keys
— Only a bcrypt hash is stored. The raw key cannot be recovered from it.
-
✗
Private keys
— ECDSA signing keys are stored encrypted at rest. We cannot extract the plaintext.
How we use it
- →To deliver the service — consent requests, approvals, webhook delivery, token verification.
- →To respond to support inquiries sent to us directly.
- →To send administrative notifications — billing events, account alerts, audit export emails.
We do not sell data. We do not use it for advertising.
Data retention
| Plan |
Audit log retention |
| Free |
30 days |
| Starter |
1 year |
| Pro |
3 years |
Active consent records are retained until revoked or the account is deleted. Builder account data is deleted within 12 months of account termination on request.
Cookies
- →Session cookies are used for dashboard authentication only. They expire when you close your browser or log out.
- →No tracking cookies. No advertising cookies. No third-party analytics cookies.
Security
- →API keys hashed with bcrypt — the raw key is never stored.
- →ECDSA P-256 signing keys encrypted at rest — we cannot extract plaintext private keys.
- →Webhook payloads signed with HMAC-SHA256 so your server can verify they came from Permitly.
More detail on the security model: permitly.dev/trust
International transfers
- →Data is stored on US servers (DigitalOcean).
- →Billing is processed by Stripe, a US company.
- →If you are in the EU or UK, your data is transferred to US infrastructure when you use Permitly.
Your rights
You can request access to, correction of, or deletion of your data at any time.
Email security@permitly.dev with your request. We will respond within 30 days.