Privacy Policy

Last updated: 2026-06-23

This policy is about your SesameHut account: the single sign-in you use across SesameHut's apps, hosted at https://auth.sesamehut.studio. It covers the sign-in itself, not what each app does with your data once you're in. Each app, and the SesameHut marketing site at https://sesamehut.studio, has its own separate policy.

What this policy covers

It applies to the SesameHut account you create here and to signing in to an app with it. Once you're inside an app, how that app handles your data is its own privacy policy's job, not this one's.

What we collect

Your email address, which you need to sign in. If you use Google, Apple, Microsoft, or GitHub instead, we also get the basic profile they return: your name, your avatar URL, and a stable identifier that lets us recognize you next time.

Every sign-in and account change writes an audit record: what happened, an IP address, the browser's user-agent, and the time. We keep these to catch abuse and to piece together what happened on an account when something looks off.

Two cookies, both on the SesameHut domain: a session cookie (HttpOnly, Secure, SameSite=Lax) that keeps you signed in, and a small one that remembers your language. Nothing for tracking, advertising, or analytics.

We don't collect your contact lists, your browsing history elsewhere, advertising identifiers, biometric data, payment details, or anything you create inside the apps themselves.

What we use it for

Only to run the account: to sign you in and keep you signed in across SesameHut's apps, to send the emails the flow needs (sign-in codes, email-change confirmations), to enforce rate limits and shut out abuse, and to keep the audit log we lean on when something goes wrong. We don't profile you, train models on your data, or use any of it for marketing.

Where it's stored

Account and audit records live in Cloudflare D1, a SQLite database on Cloudflare's edge network. Email goes out through Resend, and error reports may go to Sentry. Each of these is bound by its own data-processing terms, and we hand each one only what it needs to do its job.

How long we keep it

We keep your account record for as long as the account exists. Delete the account from your account page and the record, every linked social login, and all active sessions go with it.

Audit records are kept separately for a limited period and aren't erased when you delete your account, since we may still need them to investigate an incident afterward. They hold IPs and timestamps, not the contents of anything you wrote.

Who we share it with

When you sign in to one of SesameHut's apps, we pass along only what that app asks for and you approve through OIDC: usually a stable user identifier (your SesameHut sub), your email, and whether it's verified. We never push your data to an app you haven't signed in to.

A handful of infrastructure providers process data on our behalf: Cloudflare for hosting and the database, Resend for email, and Sentry for error monitoring. Each works under its own contract with us.

We don't sell or rent your data, and we don't share it with advertisers, data brokers, or analytics firms.

Third-party sign-in providers

If you sign in with Google, Apple, Microsoft, or GitHub, they'll know you signed in to SesameHut, and we get the basic profile they choose to release. What they do with that is governed by their own privacy policy, not ours. You can unlink any of them from your account page whenever you like.

Your rights

Your account page lets you review the email and sign-in methods on the account, unlink a social provider, change your email, and delete the account outright. If the law where you live grants further rights, such as to access, correct, export, or restrict how we process your data, write to support@sesamehut.studio and we'll follow up.

Children

SesameHut isn't meant for children under 13, or whatever the minimum age is where you live. If you think a child has created an account, tell us at support@sesamehut.studio and we'll remove it.

Changes to this policy

We may update this policy now and then; the "Last updated" date at the top tracks the latest change. For anything significant, we'll post a notice on your account page before it takes effect.

Contact

Questions about any of this go to support@sesamehut.studio. This is how SesameHut works today, written plainly rather than as formal legal advice, and we'll keep refining it as the service grows.