Login Broker exists to answer one question — is this person really this email address? — so an email address is very nearly the only personal data it ever touches. This page says exactly what it holds, for how long, and who else sees it.
Building an app on Login Broker rather than signing in to one? The page you want is privacy for customers, which covers how we handle your users' data on your behalf.
Last updated 17 August 2026
Login Broker is operated by Gyxi, a company registered in Denmark, VAT number DK28916779. For anything on this page — a question, a request to see or delete your data, a complaint — write to nb@gyxi.com and a human will answer.
We wear two hats, and which one matters depends on how you arrived here. If you signed up for a Login Broker account, we decide what happens to your data and this policy is the whole story. If you are signing in to somebody else's app that uses Login Broker, that app decides — we are handling your email on its behalf, and its own privacy policy governs what it then does with you.
All of it, in one list. There is no other list.
Read from the identity provider you chose. We ask those providers for the narrowest scope they offer — openid email, or openid user:email on GitHub. We do not request, receive or store your name, your profile picture, your contact list, your posts or anything else the provider holds.
A short session record: a random session id, which app you were signing in to, which provider you picked, whether it worked, any error, the address you were returned to, and when it was created.
Only if you signed up here rather than passing through: your email, the sign-in tokens that keep you logged in, and which tenants you administer.
The marketing pages load an analytics script from pagerain.net that counts visits. It is not tied to your account and it does not follow you to other sites.
We do not build profiles, we do not run advertising, we do not sell anything to anyone, and nothing here is fed to a third party for their own purposes.
Login Broker sets no cookies — which is why you have never seen a consent banner here. Signing in stores two things in your own browser instead: your email address and a sign-in token, kept in localStorage so the site knows you on your next visit, plus the provider you picked, kept in sessionStorage for the few seconds you are away at the provider. Logging out deletes both, and so does clearing your browser data.
A login session is valid for ten minutes. After that it can no longer be read or exchanged for anything, and the record is cleared out in routine housekeeping.
If you hold a Login Broker account, your email and tenant list stay for as long as the account does. Ask us to close it and they go.
Four kinds of third party, and no others:
We will also hand data over if the law actually requires it, and we would rather tell you when that happens.
Verifying your email is what you asked us to do when you pressed the button, so we do it to perform that service. Keeping the site working and unabused, and counting page views, rest on our legitimate interest in running a functioning product — and both are done with the least data we could manage.
A copy of what we hold about you, a correction, deletion, a machine-readable export, or an objection to a particular use. Email nb@gyxi.com and we will sort it out within a month. There is no charge and no form to fill in.
If you signed in to someone else's app, ask that app first — it holds your account, and we hold at most a long-expired session. We will help them answer.
If we handle it badly, you can complain to Datatilsynet, the Danish data protection authority, or to the equivalent authority where you live.
Everything moves over TLS. Session records are readable only by the app that started the login, and only with that app's API key. Sign-in tokens and API keys are secrets — treat them as such, and tell us at once if one gets loose.
Login Broker is a developer tool and is not aimed at children. We do not knowingly collect data from anyone under 16. If you believe we have, write to us and it will be deleted.
If this policy changes, the date at the top changes with it. Anything that meaningfully affects account holders gets an email as well, not a silent edit.
Privacy pages are usually written to be unreadable. If this one still managed it somewhere, say so and we will fix the wording.