AutonoVerse

Privacy Notice

Last updated: 21 July 2026

What we collect

  • Your account identifier (the username or email you sign in with).
  • A salted hash of your password. We never store the raw password and cannot recover it.
  • A short-lived session cookie (HMAC-signed, HTTP-only, 7-day lifetime) that keeps you signed in.
  • Audit records: each sign-in, sign-out, user change, workspace deploy, and destroy — including who did it and when.

Why we collect it

To authenticate you, keep your session active, and maintain an auditable trail of infrastructure changes. Audit records are required for our platform's security posture and to investigate incidents.

What we do not collect

  • Marketing or advertising identifiers.
  • Third-party trackers or analytics.
  • Any personal data beyond what's listed above.

Where it's stored

All account and audit records live in a MongoDB instance operated by the AutonoVerse platform team. Session cookies live only in your browser and are signed with a secret held in Google Cloud Secret Manager.

Retention

Account records live for as long as your account exists. Audit records are retained for at least 12 months to support incident investigation and compliance.

Your controls

To delete an account or request an audit export, contact your AutonoVerse administrator.