Skip to content
Authpipe
Features Pricing Providers Docs
Sign in Get started
Features Pricing Providers Docs
Sign in Get started

Mataki Labs LLC (“Authpipe,” “we,” “us,” or “our”), a Wyoming limited liability company, operates the authpipe.dev website, the Authpipe Cloud platform, and related services (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Services.

By using our Services, you agree to the collection and use of information as described in this policy.

Information We Collect

Information You Provide

When you create an account, subscribe to a plan, or contact us, we may collect:

  • Account information: Name, email address, password (hashed), and company or organization name
  • Billing information: Payment method details are collected and processed by our payment processor (Stripe). We do not store full credit card numbers on our servers.
  • Communications: Any information you include when you contact us via email, support tickets, or Discord, including your name, email address, and message content
  • API keys and configuration: Provider configurations, OAuth application credentials, callback URL settings, and other content you create through the Services
  • OAuth tokens: Access tokens, refresh tokens, and related credentials obtained through the OAuth flows you configure. These tokens are encrypted at rest and are never used for any purpose other than token refresh and connection health monitoring.

Information Collected Automatically

When you use our Services, we automatically collect:

  • Usage data: API call volumes, connection counts, token refresh frequencies, provider usage patterns, and feature usage metrics
  • Server logs: IP address, browser type and version, operating system, referring URL, pages visited, timestamps, and request/response metadata
  • Performance data: Page load times, API response latencies, token refresh latencies, and error logs used to maintain service reliability
  • Device information: Device type, screen resolution, and timezone

How We Use Information

We use the information we collect to:

  • Provide and maintain the Services: Manage OAuth connections, store and refresh tokens, deliver API responses, manage your account, and handle billing
  • Token refresh and health monitoring: Automatically refresh expiring tokens and monitor connection health to ensure uninterrupted access to the third-party APIs you have connected
  • Improve the Services: Analyze usage patterns to identify bugs, optimize performance, and develop new features
  • Ensure security: Detect and prevent fraud, abuse, and unauthorized access to accounts, tokens, or APIs
  • Communicate with you: Send transactional emails (account verification, billing receipts, connection alerts), respond to support requests, and provide product updates you have opted into
  • Comply with legal obligations: Respond to lawful requests from government authorities and comply with applicable laws

We do not sell your personal information to third parties.

Important: We never access, read, or process data from the third-party provider APIs that your tokens grant access to. Authpipe stores and refreshes tokens on your behalf — we do not use those tokens to retrieve, inspect, or analyze any data from third-party services.

Information Sharing and Disclosure

We share information only in the following circumstances:

Service Providers

We use third-party service providers to help operate our Services, including:

  • Stripe for payment processing
  • Cloud infrastructure providers for hosting and data storage
  • Monitoring and logging services for operational visibility

These providers access information only as necessary to perform their services and are bound by contractual obligations to protect your information.

Token Handling

We do not share, transmit, or expose your stored OAuth tokens to any third party. Tokens are used exclusively to communicate with the provider APIs you have authorized, solely for the purpose of token refresh and connection health checks. We never access, read, or process data from provider APIs — we only store and refresh tokens.

Legal Requirements

We may disclose information if required to do so by law or in response to valid legal process, including subpoenas, court orders, or government requests. We will notify you of such requests when legally permitted to do so.

Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website before your information becomes subject to a different privacy policy.

Data Retention

  • OAuth tokens are retained for as long as the corresponding connection is active. Upon disconnection, tokens are retained for 30 days to allow for reconnection, after which they are permanently deleted.
  • Audit logs are retained according to your plan tier (7 days for Free, 30 days for Pro, 90 days for Scale, as configured for Enterprise).
  • Account data is retained for as long as your account is active. Upon account deletion, we will remove your personal information within 30 days, except where retention is required by law.
  • Billing records are retained for 7 years as required by applicable tax and accounting regulations.
  • Server logs are retained for 90 days for security and debugging purposes.

Data Security

We implement security measures designed specifically for the sensitive nature of credential storage:

  • Encryption at rest: All OAuth tokens are encrypted using AES-256-GCM before storage. Authenticated encryption ensures both confidentiality and integrity of stored credentials.
  • Per-tenant key isolation: Each workspace’s tokens are encrypted with a distinct data encryption key (DEK), preventing cross-tenant exposure. A compromise of one workspace’s key material cannot affect any other workspace.
  • HSM-backed key management: Key encryption keys (KEKs) are managed through hardware security modules (HSMs), ensuring keys are never exposed in plaintext outside secure hardware boundaries. Key rotation is automatic and transparent.
  • Tokens never logged: OAuth tokens are never written to application logs, error reports, crash dumps, or monitoring systems. Log redaction is enforced at the serialization layer.
  • Tokens never displayed in raw form: The Authpipe dashboard never displays full token values. Only masked prefixes are shown for identification purposes. Full tokens cannot be retrieved through the dashboard UI.
  • Separation of secrets: Client secrets are stored separately from access and refresh tokens, using distinct storage backends with independent access controls and encryption keys.
  • Encryption in transit: All communications use TLS 1.3. Older TLS versions are not supported.
  • Access controls: Employee access to production credential stores is restricted, logged, and requires multi-party approval.

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Self-Hosted Token Proxy

Enterprise customers may deploy the Authpipe token proxy on their own infrastructure. When using the self-hosted proxy, OAuth tokens never transit to Authpipe Cloud. Token storage, refresh, and health checks occur entirely within your infrastructure. In this configuration, Authpipe Cloud communicates only with the proxy’s control plane for connection metadata and orchestration — credential material remains within your network boundary.

The self-hosted proxy is open source, enabling your security team to audit the code that handles your credentials.

Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your personal information and stored tokens (subject to legal retention requirements)
  • Export your data in a portable format, including connection metadata
  • Withdraw consent for optional data processing activities

To exercise any of these rights, contact us at privacy@authpipe.dev. We will respond to your request within 30 days. If we need additional time to fulfill your request, we will notify you of the delay and the reason for it.

Data Residency

By default, all data is stored in the United States. Enterprise customers may elect EU data residency (in which case account data and encrypted tokens are stored within the European Union) or request custom data residency configurations to meet specific regulatory requirements.

Data residency selection is made at the workspace level and applies to all tokens and connection data within that workspace.

Cookies and Tracking

The Authpipe dashboard uses strictly necessary cookies to maintain your authenticated session. We do not use third-party advertising trackers, social media pixels, or cross-site tracking cookies. Analytics, if any, are privacy-respecting and do not track individual users across sites.

Children’s Privacy

Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

International Data Transfers

Mataki Labs LLC is based in the State of Wyoming, United States. If you access our Services from outside the United States, your information may be transferred to and processed in the United States, unless you have elected an alternative data residency option. By using our Services, you consent to such transfer and processing.

For customers who require specific transfer mechanisms (such as Standard Contractual Clauses), please contact us to discuss available options.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. For significant changes, we will provide additional notice via email to the address associated with your account.

Governing Law

This Privacy Policy is governed by the laws of the State of Wyoming, United States, without regard to its conflict of law provisions.

Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Mataki Labs LLC State of Wyoming Email: privacy@authpipe.dev

Authpipe

The credential layer for modern integration infrastructure.

Product

  • Features
  • Providers
  • Pricing

Developers

  • Documentation
  • API Reference
  • SDKs
  • GitHub

Legal

  • Terms
  • Privacy
  • Security
  • All Policies

Authpipe is a Mataki Labs product. © 2026 Mataki Labs LLC. All rights reserved.

Built for developers who ship.