ZidhuXD
Privacy Policy
Last updated: September 29, 2026
1. Overview
This Privacy Policy explains how ZidhuXD ("we", "us", or "our") collects, uses, and protects your information when you use our authentication portal at auth.zidhuxd.com and related services at zidhuxd.com.
2. Information We Collect
We only collect the minimum information necessary to authenticate and secure your account:
- Direct Account Credentials: Full name, email address, and securely salted and hashed password representations (handled via Supabase Auth).
- OAuth Social Login (Google & GitHub): When you sign in using Google or GitHub, we receive your basic public profile information, including your full name, email address, and OAuth provider identifier. We do not access your contacts, private files, or search history.
- Technical & Security Telemetry: IP address, browser user-agent, and access timestamps solely for rate limiting, brute-force defense, and account security.
3. How We Use Your Data
We use the collected information exclusively to:
- Authenticate your identity and grant access to the ZidhuXD platform.
- Protect our services against credential stuffing, brute force attacks, and automated abuse.
- Send essential transactional notifications (such as password reset links or security alerts).
4. Data Sharing & Third Parties
We do not sell, rent, monetize, or trade your personal information. Your authentication data is strictly processed by:
- Supabase: Our identity and database infrastructure provider. Data is stored in secure, encrypted cloud data centers.
- Google / GitHub: Exclusively for the OAuth 2.0 handshake when you choose social login.
5. Data Retention & Deletion
We retain your profile data for as long as your account remains active. You may request account deletion and removal of all associated personal data at any time by contacting us.
6. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data privacy rights, please contact us at zidhuxd@gmail.com.