dxAuth legal
Independent platform
Updated 2026-07-13

Legal terms for identity verification, registered applications, and secure auth-code exchange.

dxAuth operates as a dedicated authentication and application-registration platform. These documents set out platform boundaries, operational safeguards, privacy handling, retention, and reporting channels.

Last updated 2026-07-13
Current release

dxAuth Privacy Policy

Privacy notice for dxAuth application registration, email verification, anti-abuse processing, and auth-code exchange.

Section 01

Controller and contact

  1. 1.1

    dxAuth is an independent authentication and application-registration platform operated for doxanh applications and other approved registered applications.

  2. 1.2

    General contact: contact@doxanh.dev. Privacy requests: privacy@doxanh.dev. Abuse reports: abuse@doxanh.dev. Legal notices: legal@doxanh.dev.

Section 02

Categories of information

  1. 2.1

    Application configuration may include app id, client id, active secret prefix, protected secret hash records, redirect URI allowlists, browser origin allowlists, login mode, client mode, sender settings, and security policy.

  2. 2.2

    Sign-in and identity data may include email address, challenge method, request-token metadata, verification status, failed-attempt state, one-time auth-code records, and verified identity data returned after successful exchange.

  3. 2.3

    Email delivery and anti-abuse records may include email job status, provider metadata, retry state, delivery failure state, suppression records, rate-limit signals, Turnstile results, failed attempts, and auth/security audit logs.

  4. 2.4

    We collect hashed admin/session tokens and session metadata for dxAuth admin use.

Section 03

Processing purposes

  1. 3.1

    We use information to verify email control, send magic-link or 6 digit code emails, issue one-time auth codes, and allow registered application backends to exchange auth codes for verified identity data.

  2. 3.2

    We use operational records to enforce redirect URI and origin restrictions, prevent enumeration, email bombing, brute force, spam, abusive login attempts, and support incident review.

Section 04

Product boundary

  1. 4.1

    dxAuth does not create dx Capture's final logged-in web or extension session. The registered application backend creates its own session after successful auth-code exchange.

  2. 4.2

    dxAuth does not own dx Capture media, recordings, screenshots, share links, viewer ads, or dx Capture workspace data.

Section 05

Disclosures and service providers

  1. 5.1

    We may share verified identity data with the registered application backend after successful auth-code exchange.

  2. 5.2

    We may share information with email, anti-abuse, hosting, storage, logging, monitoring, legal, and security providers that help operate, secure, and support the platform.

  3. 5.3

    dxAuth returns only the verified identity data needed for the registered application to create its own session.

Section 06

Cookies and security technologies

  1. 6.1

    dxAuth may use necessary session cookies for admin sessions, request tokens or verification state needed to complete sign-in, Turnstile or similar anti-abuse technology, operational logs, and audit records.

  2. 6.2

    dxAuth verification pages should not load advertising scripts, optional analytics pixels, behavioral tracking pixels, or third-party widgets unrelated to authentication or abuse prevention.

Section 07

Retention and deletion

  1. 7.1

    Login challenges, request tokens, and auth codes are one-time or short-lived. Exchanged or expired auth codes and old email jobs may be removed by cleanup jobs.

  2. 7.2

    Audit logs, abuse events, suppression records, and admin/session records are retained according to operational, security, and legal needs. Deletion may be delayed for legal obligations, abuse investigation, security investigation, dispute resolution, backup recovery windows, or service integrity.

Section 08

Security safeguards

  1. 8.1

    dxAuth uses controls such as hashed secrets and tokens, one-time request tokens, one-time auth codes, exact redirect URI allowlists, browser origin checks, generic public responses, rate limits, Turnstile/adaptive challenge support, suppression records, and audit logging.

  2. 8.2

    No internet service can guarantee absolute security.

Section 09

Privacy rights

  1. 9.1

    Depending on location, users may request access, correction, deletion, restriction, portability, objection, or consent withdrawal.

  2. 9.2

    Requests should be sent to privacy@doxanh.dev.

Section 10

Children and international use

  1. 10.1

    dxAuth is not intended for children under 13 or for anyone below the minimum age required by applicable law. Registered applications must not use dxAuth to collect children's personal information unless approved by the operator and legal reviewer.

  2. 10.2

    If dxAuth is offered outside the operator's home jurisdiction, additional transfer, lawful-basis, and local rights disclosures may be required.

Section 11

Policy changes

  1. 11.1

    We may update this policy. Material changes should be posted with an updated date and, where appropriate, additional notice.

Last updated 2026-07-13.Contact contact@doxanh.dev, privacy@doxanh.dev, legal@doxanh.dev, or abuse@doxanh.dev.