---
type: page
title: Privacy policy
description: "How Falcata handles personal data when you use Falcata ID, the Falcata website, and shared sign-in services."
resource: https://www.falcata.io/privacy
canonical: https://www.falcata.io/privacy
timestamp: "2026-07-27T07:24:34.275Z"
access: public
status: published
nodeId: abf24cd8-1783-41ba-b7ef-80ab707db4d5
---

## 1. Who is responsible for your data

Falcata Oy ("Falcata", "we", "us", or "our") is the controller of the personal data described in this policy.

**Falcata Oy** · PL 22 · 11101 Riihimäki · Finland · [contact@falcata.io](mailto:contact@falcata.io)

## 2. What this policy covers

This policy covers the Falcata website, Falcata ID, and the shared account and authentication services Falcata provides to participating web and mobile applications. A connected application may process additional data for its own purposes. Its privacy notice explains that processing.

## 3. Data we process

### Account and identity data

When you create or use a Falcata ID, we process your email address, display name, a stable account identifier, verification status, account preferences, and the dates associated with account creation and use. We process this data to create and perform our agreement with you, provide sign-in, and keep your identity consistent across participating applications.

### Authentication and session data

Falcata ID uses Convex Auth to provide password and email-link sign-in. We process password authentication data, single-use verification tokens, session identifiers, session status, and authentication timestamps. Passwords are not disclosed to connected applications. A connected application receives the identity and session information needed to sign you in.

### Sign-in handoff data

When an application sends you to Falcata ID, we process the requesting application's name and origin, a security state value, the intended return address, and a short-lived, single-use sign-in assertion. The assertion is bound to the requesting origin and removed from the visible address after the application receives it.

### Security and technical data

We process information needed to deliver and protect the service, including IP address, browser and device information, request and error logs, authentication attempts, and security events. We use this data for service operation, fraud and abuse prevention, troubleshooting, and compliance with legal obligations.

### Website and product analytics

We use first-party analytics to understand page visits, navigation, feature use, performance, and referring pages. When you are signed in, analytics may be associated with your Falcata account identifier. We use this information to operate and improve our services. We do not use third-party advertising trackers or sell this information for targeted advertising.

### Communications and contact data

We process your email address to send essential account messages such as sign-in links, verification messages, and security notices. If you contact us, we process the information in your message and any contact details you provide so we can respond.

## 4. How Falcata ID shares data with connected applications

After you confirm your account, Falcata ID may provide the requesting application with your stable account identifier, confirmed email address, display name, and an application-specific signed-in session. Falcata ID does not provide your password or email-link token to the application.

The connected application is responsible for explaining how it uses the identity it receives and any other personal data you provide to that application.

## 5. Our legal bases

Under the EU General Data Protection Regulation, we rely on:

- **Contract** to create and operate your Falcata ID, authenticate you, and provide requested account features.
- **Legitimate interests** to secure, maintain, understand, and improve our services, provided those interests are not overridden by your rights.
- **Legal obligations** when we must retain or disclose information under applicable law.
- **Consent** where we ask for it, such as for optional communications. You may withdraw consent at any time without affecting earlier processing.

## 6. Service providers

We use service providers to operate Falcata ID and the Falcata website. They process data on our instructions for the purposes described in this policy. These providers include:

- **Convex**, for application data, authentication, and real-time backend infrastructure.
- **Resend**, for transactional email such as sign-in and verification messages.
- **Hetzner**, for hosting and infrastructure.
- **Bunny.net and Cloudflare**, for domain name, content delivery, traffic routing, and security services where applicable.

We may replace a provider or add a provider when needed to operate the service. We require providers to protect personal data and use it only for the services they provide to us.

## 7. International transfers

Some providers may process data outside Finland or the European Economic Area. Where required, we use an approved transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses, together with appropriate safeguards.

## 8. Browser storage and cookies

Falcata services use browser storage for essential functions. Falcata ID stores its signed-in session in local storage for its own origin so that sign-in can survive a page refresh. It uses session storage for a pending sign-in handoff in the current tab. Participating applications store their own signed-in sessions on their own origins. We may also store interface preferences, security state, and first-party analytics identifiers.

The one-time sign-in assertion is returned in the URL fragment, which is not sent to the destination application's server as part of the HTTP request. The application removes it from the visible address after processing it.

Blocking or clearing essential browser storage can sign you out or prevent sign-in from completing. We do not use third-party advertising cookies.

## 9. Retention

We retain account information while your Falcata ID is active and for a reasonable period afterward when needed to complete deletion, resolve disputes, enforce agreements, prevent abuse, or meet legal obligations. Authentication tokens and pending handoff data are short-lived or removed after use. Security, technical, and communications records are kept only as long as reasonably necessary for the purpose for which they were collected.

When retention is no longer necessary, we delete or anonymize the information unless the law requires us to keep it.

## 10. Your rights

Depending on where you live, you may have the right to:

- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests;
- receive certain data in a portable format;
- withdraw consent; and
- complain to a data protection authority.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman. You may contact us at [contact@falcata.io](mailto:contact@falcata.io) to exercise your rights. We may need to verify your identity before completing a request.

California residents may also have rights to know, correct, and delete personal information and to limit certain disclosures. Falcata does not sell personal information or share it for cross-context behavioural advertising, and we will not discriminate against you for exercising an applicable privacy right.

## 11. Security

We use technical and organisational measures intended to protect personal data, including encrypted transport, access controls, origin-bound sign-in handoffs, short-lived single-use assertions, and monitoring for misuse. No service can guarantee absolute security. Please use a unique password, protect access to your email account, and contact us if you believe your account has been compromised.

## 12. Children

Falcata ID is not directed to children under 13, and we do not knowingly collect personal data from a child under 13. A connected application may set a higher minimum age in its own terms. If you believe a child has provided personal data without appropriate permission, contact us.

## 13. Changes to this policy

We may update this policy when our services, providers, or legal obligations change. We will post the updated policy here and change the effective date. If a change materially affects how we use personal data, we will provide additional notice where required.
