RudeAuth Privacy Policy
Last updated: 2026-08-15
1. Who we are
RudeAuth is a hosted software licensing and authentication service, operated by an individual based in the Philippines. In this policy, "RudeAuth", "we", "us" and "our" refer to that operator.
You can reach us at privacy@rudeauth.com for anything about this policy or your data.
Two data protection laws apply to how we handle personal data:
- the Data Privacy Act of 2012 of the Philippines (Republic Act No. 10173), overseen by the National Privacy Commission; and
- for people in the European Union and European Economic Area, the General Data Protection Regulation (GDPR), because we offer our service to users there.
Where a stricter rule applies to you, we follow it.
2. Who this policy covers
RudeAuth sits between two kinds of people:
- Account holders. Developers and businesses who sign up for RudeAuth, create applications, and issue licenses to their own customers.
- End users. The people who run an account holder's software, which contacts RudeAuth to check a license.
For the personal data of end users, RudeAuth mostly acts on the account holder's behalf. In data protection terms the account holder is the "controller" who decides what is collected and why, and RudeAuth is a "processor" acting on their instructions. If you are an end user with a question about your data, the developer whose software you use is usually the right first point of contact; we will support them in answering you.
For an account holder's own account data, RudeAuth is the controller.
3. What we collect, and why
We collect only what the service needs. Where the GDPR applies, the "legal basis" is the lawful ground we rely on.
Account holder data (RudeAuth is the controller):
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Sign-in identity from your provider (for Discord: user id, username, and email if you share it; other providers may be added) | To create and secure your account | Performance of a contract |
| Your applications and their configuration, and each application's signing keys (held encrypted) | To run the service you asked for | Performance of a contract |
| License keys you create, stored only as a keyed hash (a peppered HMAC) plus a short prefix, never in the clear | To validate licenses without holding the secret | Performance of a contract |
| Billing status, plan, and a customer id from Paddle. We do not receive or store your card details; Paddle does | To manage your subscription | Performance of a contract |
| Access logs and IP address | Security, abuse prevention, and rate limiting | Legitimate interests |
End user data (RudeAuth is the processor for the account holder):
| Data | Why | Legal basis |
|---|---|---|
| Device fingerprint components, stored only as keyed hashes (peppered HMACs), never as raw hardware identifiers | To bind a license to a device and detect sharing | Legitimate interests, or the account holder's own basis |
| IP address, stored as a keyed hash | Rate limiting and blocking abuse | Legitimate interests |
| License and session activity, and audit log entries | To operate and account for licensing decisions | Performance of a contract, or legitimate interests |
4. Data minimization
We are deliberate about not holding sensitive raw values. Raw hardware identifiers and raw license keys are never stored. They are hashed with a secret "pepper" that is kept outside the database, so a copy of the database on its own does not reveal them. Application signing keys are stored encrypted.
5. Who else processes data (sub-processors)
We use a small number of trusted providers to run the service. We keep this list current and update it before adding a new sub-processor.
| Provider | Role | Region |
|---|---|---|
| Paddle | Payments and billing, as merchant of record. Paddle holds card data; we do not | Global |
| Hetzner | Application and database hosting | European Union (Finland) |
| Cloudflare | DNS, content delivery, hosting for our public website and documentation, and cookieless website analytics | Global edge network |
| Discord | Sign-in (OAuth). Google and other providers may be added | Global |
| Resend | Sending transactional email | Global |
| Anthropic | Generates plain-language explanations of sharing-risk flags from anonymous usage statistics only | United States |
6. Where data is stored, and international transfers
Application and account data is hosted with Hetzner in the European Union (Finland). Our public website and request routing use Cloudflare's global edge network so the site loads quickly worldwide, including in Southeast Asia. When personal data is transferred out of the EEA to a provider, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, where they are required.
7. How long we keep data
We keep personal data only as long as it is needed:
- Account and application data: while your account is active, and deleted within 30 days of account closure to allow for backups. Sooner if you ask.
- Security and access logs: 30 days.
- End user device and session records: while the associated license or device is active, then pruned.
- Audit log entries: kept for the life of the application, because the log's integrity is part of the product, subject to a valid deletion request where the law requires us to act on it.
8. Your rights
Depending on where you are, you have rights over your personal data. Under both the Philippine Data Privacy Act and the GDPR these include the right to be informed and to access, correct, and delete your data, and to object to or restrict certain processing. Under the GDPR you also have the right to data portability.
To exercise any of these, email privacy@rudeauth.com. We will respond within the time the applicable law requires.
If you believe we have mishandled your data, you can complain to a regulator:
- in the Philippines, the National Privacy Commission;
- in the EU/EEA, your local supervisory authority.
If you are an end user, you may also contact the developer whose software you use, since they decide what data is collected.
9. Cookies
We keep cookies to the minimum:
- Dashboard: one strictly necessary cookie that keeps you signed in. Without it the dashboard cannot work, so no consent is required for it.
- Public website: no cookies. Our website analytics (Cloudflare Web Analytics) are cookieless and do not track you across sites, so there is no consent banner to click.
10. Children
RudeAuth is a developer tool and is not directed at children. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy as the service or the law changes. When we do, we update the "Last updated" date above, and we announce material changes to account holders.