Privacy notice for the hosted gateway
Last updated: 24 September 2026.
This notice covers the free sign-in service RESOAuth Ltd runs at
auth.resoauth.cloud. The application you sign in to has its own privacy
notice for what it does with your information afterwards.
What we use
To sign you in, we use your email address and, if your sign-in provider gives us one, your name and other basic profile details. We use them to complete the sign-in you requested. We do not create a RESOAuth account or keep a database of people's names and email addresses.
An application can ask for your email address and basic profile details. When you choose to continue signing in to that application, we send it only the details it asked for and that we have. You can stop the sign-in if you do not want to share them. If you are already signed in, the application may be able to sign you in again without showing another prompt. See Tokens and claims for the details an application can request.
When you connect, we and our hosting providers also handle information such as your IP address, browser type, the time, and the pages or sign-in endpoints requested. We use this to keep the service working, spot attacks, and limit abuse. We do not use it for advertising.
Our lawful basis for providing and protecting the service is our legitimate interest in running a secure sign-in service for you and the application. You choose whether to continue a sign-in and share the requested details with that application.
Where the information goes
We send sign-in details to the application you choose. Your Microsoft, Google, or other sign-in provider handles your sign-in under its own privacy notice. If you use an email code, our email provider sends it to your address. Cloudflare and Amazon Web Services help us host, deliver, and protect the service. They may handle connection information on our behalf.
The service can run in the UK, Europe, Canada, Australia, and through a global delivery network, so information may be handled outside the UK. Contact us if you want details of the safeguards used for an international transfer.
How long we keep it
Sign-in details pass through the service rather than going into a user directory. Encrypted values in your browser hold an unfinished sign-in or an active session until they expire. A session ends after 12 hours without use or seven days in total. If you tick Remember me, a separate encrypted cookie can keep your email address for up to one year; you can untick it at your next sign-in or clear your browser cookies. Short-lived security counters help prevent repeated use of codes and excessive requests.
Our AWS application logs are set to expire after 30 days. We may keep records needed for a specific security incident until it is resolved. Hosting and email providers may also keep their own service records under their policies.
Your choices and rights
You can stop a sign-in, untick Remember me, and clear the gateway's cookies in your browser. You can ask us about information we hold about you, or ask us to correct, delete, or restrict it. You can object to our use of your information for our legitimate interests. Some rights depend on the circumstances and the information still held. For information an application received from us, contact that application too.
Email sag@resoauth.email for a privacy request. You can also write to RESOAuth Ltd, Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom. Our ICO registration is ZB604307. You can complain to the ICO if you are unhappy with how we use your information.
See also the terms of service.