Privacy Policy
Last updated: October 2, 2026 · Parent Vertical LLC
Template for review by counsel before relying on it commercially. It reflects how the service is built but is not legal advice.
Who we are
passvak is the sign-in service operated by Parent Vertical LLC ("we"). It lets you sign in to our products — and to other apps that add "Sign in with passvak" — with a code sent to your email or phone, and gives you one place to see your sessions, team, keys and the apps you've allowed.
What we hold
- Your account — the email address and/or phone number you signed in with, the name you chose, your language, and when you created the account and last signed in.
- Sessions — for each device you're signed in on: when, how (email or phone), the browser and system family (e.g. "Safari · iOS"), and a shortened network address. Never the full address.
- Teams — the teams you created or joined, who is in them and with which role, and pending invitations (an email address and a role).
- Keys and app grants — the API keys you created (we store only a hash; the key itself is shown to you once and never kept) and which apps you allowed to sign you in.
- The sign-in log — your last 50 sign-ins and account changes, so a sign-in you didn't make stands out.
- Sign-in codes — kept for 10 minutes as a one-way hash only; the code itself is never stored.
How we use it
Only to sign you in, keep your account safe, let the apps you use know who you are and which teams you're in, and show you what we hold. We do not sell personal data and we do not advertise.
What apps receive
When you sign in to an app with passvak, that app receives your account id, your email and/or phone number, your name, your language, and your teams and roles — and nothing else. You can cut an app off at any time from your account page.
Who processes data for us
- Cloudflare — hosting for this site and the API, and storage of everything listed above.
- mailvak and linevak (our own services) — deliver the codes and invitations to your email or phone. They see the address, the code and the message, only to deliver it.
- amacli (our own service) and Amazon Web Services — a daily, deletion-locked backup of accounts, teams and key records (never sessions or codes), kept so your account survives a failure on our side.
Retention
Sessions expire after 30 days unless you sign out sooner. Codes expire in 10 minutes. Invitations expire in 7 days. Everything else stays until you delete it or your account. Backups are kept for 30 days.
Your rights
You can download everything we hold about you, and delete your account and everything in it, from your account page at any time, with no request needed. Depending on where you live (e.g. GDPR, CCPA) you may have further rights; write to hello@passvak.com.
Contact
hello@passvak.com