# AuthPlane — Privacy Policy

> How AuthPlane handles data on authplane.ai — cookieless analytics, GDPR rights, retention, and contact.

- Canonical HTML (authoritative legal text): https://authplane.ai/legal/privacy/
- Effective date: June 27, 2026 · Last updated: June 27, 2026
- Questions: privacy@authplane.ai

AuthPlane is an open-source OAuth 2.1 authorization server built for the Model Context Protocol (MCP). This policy explains what data we collect when you visit authplane.ai, why we collect it, and what rights you have over it.

## 1. Who We Are

AuthPlane is operated by Codigo Inc. References to "AuthPlane", "we", "us", or "our" refer to Codigo Inc.

## 2. What Data We Collect

The marketing site uses Cloudflare Web Analytics (cookieless, no cross-site tracking) and, only after you opt in via the consent banner, Google Analytics 4. We do not collect personal accounts on this site.

## 3. Legal Basis for Processing (GDPR)

Cookieless analytics rely on legitimate interest; GA4 relies on your explicit consent, which you can withdraw at any time.

## 4. How Long We Keep Your Data

Analytics data is retained per the processor's default windows; we do not keep raw personal identifiers on this site.

## 5. Who We Share Data With

Sub-processors: Cloudflare (hosting + analytics) and Google (GA4, only on consent). We do not sell personal data.

## 6. Your Rights Under GDPR

Access, rectification, erasure, restriction, portability, and objection. Contact privacy@authplane.ai to exercise them.

## 7. International Data Transfers

Transfers rely on the processors' standard contractual clauses and equivalent safeguards.

## 8. Children's Privacy

The site is not directed at children under 16 and we do not knowingly collect their data.

## 9. Changes to This Policy

We update this policy as practices change; the "last updated" date above reflects the current version.

## 10. Contact

privacy@authplane.ai
