login.broker
FOR PEOPLE SIGNING IN

Privacy

Login Broker exists to answer one question — is this person really this email address? — so an email address is very nearly the only personal data it ever touches. This page says exactly what it holds, for how long, and who else sees it.

Building an app on Login Broker rather than signing in to one? The page you want is privacy for customers, which covers how we handle your users' data on your behalf.

Last updated 17 August 2026

Who you are dealing with

Login Broker is operated by Gyxi, a company registered in Denmark, VAT number DK28916779. For anything on this page — a question, a request to see or delete your data, a complaint — write to nb@gyxi.com and a human will answer.

We wear two hats, and which one matters depends on how you arrived here. If you signed up for a Login Broker account, we decide what happens to your data and this policy is the whole story. If you are signing in to somebody else's app that uses Login Broker, that app decides — we are handling your email on its behalf, and its own privacy policy governs what it then does with you.

What we collect

All of it, in one list. There is no other list.

YOUR EMAIL ADDRESS

Read from the identity provider you chose. We ask those providers for the narrowest scope they offer — openid email, or openid user:email on GitHub. We do not request, receive or store your name, your profile picture, your contact list, your posts or anything else the provider holds.

THE LOGIN ATTEMPT ITSELF

A short session record: a random session id, which app you were signing in to, which provider you picked, whether it worked, any error, the address you were returned to, and when it was created.

YOUR LOGIN BROKER ACCOUNT

Only if you signed up here rather than passing through: your email, the sign-in tokens that keep you logged in, and which tenants you administer.

PAGE VIEWS ON THIS SITE

The marketing pages load an analytics script from pagerain.net that counts visits. It is not tied to your account and it does not follow you to other sites.

We do not build profiles, we do not run advertising, we do not sell anything to anyone, and nothing here is fed to a third party for their own purposes.

No cookies

Login Broker sets no cookies — which is why you have never seen a consent banner here. Signing in stores two things in your own browser instead: your email address and a sign-in token, kept in localStorage so the site knows you on your next visit, plus the provider you picked, kept in sessionStorage for the few seconds you are away at the provider. Logging out deletes both, and so does clearing your browser data.

How long we keep it

A login session is valid for ten minutes. After that it can no longer be read or exchanged for anything, and the record is cleared out in routine housekeeping.

If you hold a Login Broker account, your email and tenant list stay for as long as the account does. Ask us to close it and they go.

Who else is involved

Four kinds of third party, and no others:

The identity provider you choose. Google, GitHub, Facebook, LinkedIn, Microsoft or Apple. You are sent to them to sign in, so they know you used Login Broker. Their own privacy policy covers that visit.
The app you were signing in to. It receives the verified email address. That is the entire point of the service.
Our hosting and storage. The service runs on Microsoft Azure, and records are held in Azure Table Storage or in Gyxi, a hosted database we use. They store data for us and do nothing else with it.
Two things this website loads. Fonts from Google Fonts and the page-view counter from pagerain.net. Loading a file from either tells that server your IP address, as loading any file from any server does.

We will also hand data over if the law actually requires it, and we would rather tell you when that happens.

Why we are allowed to

Verifying your email is what you asked us to do when you pressed the button, so we do it to perform that service. Keeping the site working and unabused, and counting page views, rest on our legitimate interest in running a functioning product — and both are done with the least data we could manage.

What you can ask for

A copy of what we hold about you, a correction, deletion, a machine-readable export, or an objection to a particular use. Email nb@gyxi.com and we will sort it out within a month. There is no charge and no form to fill in.

If you signed in to someone else's app, ask that app first — it holds your account, and we hold at most a long-expired session. We will help them answer.

If we handle it badly, you can complain to Datatilsynet, the Danish data protection authority, or to the equivalent authority where you live.

Keeping it safe

Everything moves over TLS. Session records are readable only by the app that started the login, and only with that app's API key. Sign-in tokens and API keys are secrets — treat them as such, and tell us at once if one gets loose.

Children

Login Broker is a developer tool and is not aimed at children. We do not knowingly collect data from anyone under 16. If you believe we have, write to us and it will be deleted.

Changes

If this policy changes, the date at the top changes with it. Anything that meaningfully affects account holders gets an email as well, not a silent edit.

Something here unclear?

Privacy pages are usually written to be unreadable. If this one still managed it somewhere, say so and we will fix the wording.

write to us →