Effective April 16, 2026
Privacy Policy
Autheory is Theory Cloud's provider-hosted identity platform. This Privacy Policy explains how Autheory collects, uses, and protects personal information when users authenticate to Theory Cloud applications and customer namespaces.
Information we collect
- Basic identity details such as name, email address, and profile metadata returned by sign-in providers
- Account, tenant, and membership records needed to authorize access
- Security and session data such as sign-in timestamps, MFA enrollment, IP address, browser, and device signals
- Operational logs and audit events needed to secure and troubleshoot the service
How we use information
- Authenticate users and issue secure sessions and tokens
- Protect accounts, detect abuse, and enforce security controls
- Support tenant-aware access to Theory Cloud applications
- Maintain audit trails, reliability, and compliance processes
Sharing and disclosure
We may share information with customer tenant administrators, infrastructure providers, and service providers who help us operate Autheory. We may also disclose information when required for legal, security, or fraud-prevention purposes.
Retention and security
We retain information for as long as needed to provide the service, maintain security records, satisfy legal obligations, and enforce our agreements. We use reasonable technical and organizational safeguards to protect the information Autheory handles.
Your choices
Access to Theory Cloud applications is generally managed by your organization or tenant administrator. If you have questions about your access, account data, or this policy, contact noreply@autheory.app.