Privacy Policy
Last updated: June 10, 2026
Overview
Sushii OAuth("we", "us", or "our") operates oauth.sushii.dev, a universal OAuth platform that lets developers add sign-in to their applications and lets end users authenticate through supported identity providers. This policy describes what information we collect, how we use it, and the choices you have.
Information we collect
Developer accounts. When you create an account, we collect your name, email address, date of birth, and a hashed password. We send a one-time verification code to your email address to confirm ownership.
OAuth projects. If you use the developer console, we store project configuration you provide, including project name, redirect URIs, webhook URLs, selected sign-in methods, requested data scopes, and API credentials (client secrets are stored hashed and encrypted).
End-user sign-in. When someone signs in through an application that uses Sushii OAuth, we process authentication on behalf of that application. Depending on the app's configuration and the identity provider used, we may receive and forward information such as email address, name, profile picture URL, and a provider-specific user ID. We do not create a separate end-user account on Sushii OAuth unless they also register as a developer.
Technical data. We automatically collect standard server logs and security-related data, such as IP addresses, request timestamps, browser type, and error events, to operate and protect the service.
How we use information
- Provide, maintain, and secure the OAuth service
- Authenticate developers and verify email addresses
- Complete sign-in flows and deliver data to authorized applications
- Send optional webhook events to URLs configured by developers
- Review commercial project requests and prevent abuse
- Comply with legal obligations and enforce our terms
Third-party identity providers
Sign-in may be completed through third-party providers such as Google, GitHub, Discord, Twitch, or GitLab. When you choose a provider, you are also subject to that provider's privacy policy and terms. We receive only the information permitted by the application's configured data scopes and the provider's response.
How data is shared
We do not sell your personal information. We share data only in these cases:
- With the application you sign in to, via redirect and token exchange, according to its configured scopes
- With webhook endpoints explicitly configured by the application developer, using signed payloads
- With infrastructure providers that help us host and operate the service (for example, hosting, database, and email delivery)
- When required by law or to protect rights, safety, and security
Cookies and sessions
We use essential cookies to keep developer accounts signed in and to protect OAuth flows. These cookies are required for the service to function and are not used for advertising.
Data retention
We retain account and project data while your account is active. OAuth session, authorization code, and access token records are kept only as long as needed to complete authentication and expire automatically. You may request deletion of your developer account by contacting us.
Security
We use industry-standard measures including encrypted connections (HTTPS), hashed passwords, encrypted client secrets, signed webhooks, and time-limited authorization codes. No method of transmission or storage is completely secure, but we work to protect information appropriately.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict use of your personal information. To make a request, contact us at the email below. If you signed in through a third-party app using Sushii OAuth, that app's developer may also hold your data and should be contacted directly.
Children
Sushii OAuth is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect the latest version. Continued use of the service after changes means you accept the updated policy.
Contact
Questions about this privacy policy can be sent to sashabaranov@sushii.dev.
See also our API documentation.