What This Policy Covers
This policy is a transparent account of every type of data AccorID stores, how it is stored, how it is protected, and who can access it. We believe you should know exactly what's on our servers.
Infrastructure
AccorID runs on Cloudflare Workers. Our data is stored in two systems:
- Cloudflare D1 — a serverless SQL database for structured data (accounts, profiles, authorizations, etc.).
- Cloudflare R2 — private object storage for files (avatars, identity document images, vault files). Identity documents and vault files are encrypted at rest with AES-256-GCM before being written to R2. All sensitive file access goes through authenticated API endpoints.
All traffic is served over HTTPS. There is no unencrypted path to our service.
Account Data
When you create an account, we store:
- Username — stored in plaintext; used for login and display.
- Email address — stored in plaintext; used for login, verification, and password resets. Optional — you can use AccorID without an email, though some features require one.
- Password — never stored. We store a one-way hash using PBKDF2-SHA256 with 100,000 iterations and a unique random salt. Your password cannot be recovered or viewed by anyone, including us.
- Display name & bio — stored in plaintext; optional, set by you.
- Avatar — stored as an image file in R2. Avatars are served through a public image endpoint (they are profile pictures, intended to be visible).
- Timestamps — account creation date and last update date.
Per-app identity
For each app you authorize, you can curate what it sees:
- A display name specific to that app
- An avatar (and optional banner) specific to that app, stored in R2
Anything you leave unset falls back to your main account profile. Your username is never customizable per app — apps always see your real AccorID username. Each app only ever sees the identity curated for it.
Linked Accounts
When you link an external service (Discord, GitHub, Google, Steam, or Minecraft), we store:
- Provider & provider ID — which service and your unique ID on that service.
- Display name & tag — your username or display name on that service.
- Metadata — additional public profile info the service provides (e.g. avatar URL, discriminator). This varies by provider.
We do not store OAuth tokens from these services after the linking flow completes. We do not access your private messages, friends lists, repositories, or any data beyond basic profile info. You can unlink any account at any time, and the stored data is removed.
Identity Verification
Identity verification is entirely optional. If you choose to verify, the process is handled by Stripe Identity. Upon successful verification, Stripe sends us the results and we store the following — all encrypted at rest with AES-256-GCM:
- Legal name (first and last) — encrypted
- Date of birth — encrypted
- Address (line 1, line 2, city, state, postal code, country) — each field encrypted individually
- Document info (type, last 4 digits of document number, issuing country, expiration) — encrypted. We never store the full document number.
- Document images & selfie — encrypted at rest with AES-256-GCM before being stored in R2 (private storage). Accessible only through authenticated API endpoints that require a valid OAuth token with the appropriate identity scope. These are never publicly accessible and cannot be read even with direct storage access.
We also store the Stripe session/report IDs (not encrypted, as they contain no PII), verification status, and timestamps.
Identity data is never shared with any third-party app unless you explicitly approve the specific identity scopes on the consent screen. Sensitive scopes (date of birth, address, document number, document images, selfie) require an additional on-screen acknowledgment before authorization.
Vault Storage
Third-party apps can store data on your behalf using the AccorID Vault. The vault supports key-value strings, JSON objects, and file uploads. Here's exactly what's stored and how:
- Values (text/JSON) — encrypted at rest with AES-256-GCM. The database only contains ciphertext.
- Metadata (optional JSON) — encrypted at rest with AES-256-GCM.
- Files — encrypted at rest with AES-256-GCM before being stored in R2 (private storage). Files are decrypted on the fly and served through authenticated endpoints; they are not publicly accessible and cannot be read even with direct storage access.
- Per-app encryption keys — the vault also offers encryption-as-a-service, generating a unique AES key per app per user. These keys are themselves encrypted at rest with the platform master key.
- Object name & type — stored in plaintext (not sensitive; used for listing/filtering).
Vault data is scoped per-app. App A cannot read App B's vault data unless you explicitly create a share. You can revoke shares and app access at any time.
Digital Signatures
AccorID can create digital signatures on your behalf (e.g. signing a contract). When you sign something, we store:
- A cryptographic hash of the document/payload (we do not store the document itself)
- The ECDSA signature (P-256 / ES256)
- A label describing what was signed
- Which app requested the signature, and your user ID
- Timestamp and IP address at the time of signing
Signing keys are ECDSA P-256 key pairs generated and stored on our servers. The private key is used only by AccorID to produce signatures on your behalf.
Two-Factor Authentication
If you enable 2FA, we store:
- TOTP secrets — stored in the database (used to verify authenticator app codes).
- Passkey credentials — public key and credential ID (the private key stays on your device, we never see it).
- Recovery codes — stored as one-way hashes. Like your password, we cannot view the original codes.
Sessions & OAuth Tokens
When you log in, we create a session. When you authorize an app, we issue an OAuth token. Both store:
- A random token (used to authenticate requests)
- Your IP address and user agent at the time of creation
- Expiration timestamp
- For OAuth tokens: which app, which scopes you approved, and which profile you selected
Sessions expire after inactivity. OAuth tokens expire based on the app's configuration. You can revoke either from your dashboard at any time.
Audit Logs
We maintain detailed audit logs for every significant action on your account. This is intentionally thorough — it protects you by creating a complete record of who did what and when. Every audit log entry records:
- Event type — what happened
- IP address — the IP that initiated the action
- User agent — the browser or client used
- Geolocation — country, city, region, continent, and ASN (derived from the IP by Cloudflare; not precise GPS coordinates)
- Cloudflare metadata — datacenter (colo), TLS version, CF-Ray ID, referer, and origin
- Data snapshot — the relevant data at the time of the action (e.g. which app was authorized, which scopes were approved, which account was linked)
- Previous snapshot — the previous state, when applicable (e.g. old email before a change, old role before an update)
- Timestamp
The types of events we log include (not exhaustive):
- Account registration
- Login (success and failure)
- Logout
- Password changes and resets
- Email/phone changes and verification
- Username changes
- Profile creation, update, deletion
- External account linking and unlinking
- 2FA enable, disable, and verification
- Recovery code regeneration
- OAuth authorization (grant and deny)
- OAuth token exchange and revocation
- Userinfo access (and which scopes)
- Identity verification start and completion
- Identity data access by apps
- Signature requests, approvals, and denials
- Vault object create, update, delete
- Vault sharing and share revocation
- App creation, update, deletion
- App secret regeneration
- Organization and team management
- Role and permission changes
- Session termination
Audit logs are used for security monitoring and are included if you request a data export. They are never shared with third-party apps.
Request Logs
Separately from audit logs, we log basic metadata about every API request for operational monitoring:
- HTTP method, path, and response status code
- IP address, approximate geolocation (country, city, region, continent, ASN — derived from the IP by Cloudflare)
- User agent, TLS version, Cloudflare datacenter
- Response time
Request logs do not contain request or response bodies. They are used for debugging and abuse prevention, not analytics or tracking.
What Third-Party Apps Can See
When a third-party application asks you to sign in with AccorID, you'll see a consent screen that lists exactly what information the app is requesting. Only the data you approve on that screen is shared. Common examples include:
- Your display name and avatar
- Your email address
- Which external accounts you've linked
- Identity verification data
None of the above is shared unless you explicitly approve it on the consent screen.
Apps can set requirements (such as "must have a verified email" or "account must be older than 7 days"), but the details behind those checks are never shared. The app only receives a yes/no — it never sees your email, phone number, or account creation date just because it set a requirement.
You can revoke any app's access at any time from your dashboard. Once revoked, the app can no longer retrieve your information.
Encryption Summary
Here is exactly how each type of data is protected:
| Data |
Storage |
Protection |
| Password | D1 | PBKDF2-SHA256 hash (irreversible) |
| Recovery codes | D1 | One-way hash (irreversible) |
| Identity PII (name, DOB, address, document info) | D1 | AES-256-GCM encrypted at rest |
| Vault values & metadata | D1 | AES-256-GCM encrypted at rest |
| Vault per-app encryption keys | D1 | AES-256-GCM encrypted at rest |
| Identity document images & selfie | R2 (private) | AES-256-GCM encrypted at rest; authenticated endpoints only |
| Vault files | R2 (private) | AES-256-GCM encrypted at rest; authenticated endpoints only |
| Avatars | R2 | Publicly accessible (they are profile pictures) |
| Username, email, display name, bio | D1 | Plaintext (not sensitive enough to warrant encryption overhead) |
| Session tokens, OAuth tokens | D1 | Cryptographically random; expire automatically |
What We Don't Do
- We don't sell your data to anyone.
- We don't show you ads or use any advertising trackers.
- We don't track you across other websites.
- We don't share your information with anyone you haven't explicitly approved.
- We don't store your password or identity documents in plaintext.
- We don't use analytics services that collect personal data.
- We don't retain OAuth tokens from external providers after linking is complete.
Deleting Your Data
You can delete your account at any time from your dashboard. This removes:
- Your account and all profile data
- All linked external accounts
- All identity verification data (encrypted fields)
- All vault objects (database records)
- All OAuth authorizations and tokens
- All sessions, 2FA methods, and recovery codes
- All digital signatures
Encrypted files stored in R2 (identity document images, selfies, and vault files) are not deleted upon account deletion. These files are AES-256-GCM encrypted at rest and cannot be read without the platform master key. They are retained for compliance, abuse prevention, and audit purposes.
Audit logs are permanent and are retained indefinitely. They may contain encrypted snapshots of data as it existed at the time of each event.
Changes to This Policy
If we make meaningful changes to this policy, we'll update the date at the top. Continued use of AccorID after changes means you accept the updated policy.