Legal
Privacy Policy
Last updated: September 9, 2026
1. Overview
This Privacy Policy explains what information Re-Factored ("we", "us", "our") collects when you use the Re-Factored Portal (the "Portal") — the sign-in hub and directory linking to our sub-domain applications (each an "App") — and how that information is used, stored, and shared. This policy covers the Portal itself; each App may collect additional information described in its own privacy notice.
2. Information we collect
When you sign in, we receive the following from your identity provider via OpenID Connect (OIDC):
- Identity claims: a stable subject identifier (
sub), and, if shared by the provider, your name and email address. - Role claims: the list of roles associated with your account (for example
re-factored:userorquests:user), used solely to decide which App tiles to show and unlock. - Session data: a single encrypted, HTTP-only session cookie that lets you stay signed in. It is not readable by JavaScript and is not used for advertising or cross-site tracking.
We do not use analytics trackers, advertising cookies, or third-party marketing pixels on the Portal.
3. How we use this information
- To authenticate you and keep you signed in across a visit.
- To determine which Apps you are authorized to see and access, based on your roles.
- To maintain the security and integrity of the Portal.
4. Identity providers
Sign-in is handled by a third-party identity provider (such as Logto, or, where applicable, Google) using the OIDC protocol. That provider's own privacy policy governs how it handles your credentials and any consent you grant during sign-in. The Portal only receives the identity and role claims described above — it never sees your password.
5. Cookies
The Portal sets a single session cookie required for sign-in to function. It is strictly necessary — it is not used for advertising, profiling, or analytics, and no consent banner is required for it under most privacy regimes as a result. It expires automatically and is cleared immediately when you sign out.
6. Data retention
Session data lives only as long as your sign-in session (typically a few hours) and is discarded when the session expires or you sign out. We do not maintain a separate database of Portal visits.
7. Sharing
We do not sell your information. Role and identity claims are used only within Re-Factored's own systems to grant or deny access to Apps you are entitled to use.
8. Your choices
You can sign out at any time to end your session immediately. If you believe your roles are incorrect, or you would like your account information corrected or removed, contact us using the details below.
9. Children's privacy
The Services are not directed to children and are not knowingly used to collect information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
11. Contact
Questions about this Privacy Policy or your data can be sent to [email protected].