Privacy Policy

Last updated: August 17, 2026

1. Information We Collect

We collect account information (email addresses, organization names) and technical telemetry necessary to authenticate software licenses (one-way SHA-256 hashed hardware identifiers, IP addresses for rate limiting and audit logging, timestamp records).

2. Hardware Fingerprint Privacy

We strictly adhere to zero-reconstruction principles: client SDKs compute cryptographic hashes locally before transmitting hardware binding identifiers. NineAuth cannot reverse-engineer or extract personal machine details from hashed HWID tokens.

3. Data Retention & GDPR/LGPD Compliance

Audit logs are retained according to your active subscription plan (7 to 365 days). Account holders may request export or deletion of personal data at any time by contacting privacy@nineauth.xyz.

4. Third-Party Processors

We utilize trusted data processing partners for database hosting (AWS/Supabase) and payment settlement (PIX). We do not sell or monetize developer or end-user telemetry.