Skip to content

Document SSO authentication in Terms and Privacy Policy - #1153

Merged
AvdLee merged 1 commit into
masterfrom
docs/sso-legal-disclosures
Sep 4, 2026
Merged

Document SSO authentication in Terms and Privacy Policy#1153
AvdLee merged 1 commit into
masterfrom
docs/sso-legal-disclosures

Conversation

@AvdLee

@AvdLee AvdLee commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Summary

  • Documents organization-managed SSO authentication in the Terms of Service.
  • Explains the identity and authentication data processed during SSO in the Privacy Policy.
  • Documents temporary OAuth/OIDC session data, the sso_session_code cookie, retention, and Auth0's role as authentication broker.
  • Updates the Privacy Policy revision date.

Context

This replaces #952 by applying its approved intent to the current legal pages. The wording was refreshed to avoid coupling the policy to volatile token lifetimes or storage details, to cover the applicable GDPR basis when the subscribing customer is the user's organization, and to use the current Microsoft Entra ID product name.

Verification

  • npm run format:check
  • npm run lint
  • npm run typecheck (passes with four existing hints)
  • npm run build
  • npm test (7 tests passed)

Co-authored with the original contributors from #952.

Co-authored-by: Niek Nijland <ngnijland@gmail.com>

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
@AvdLee
AvdLee enabled auto-merge (squash) September 4, 2026 10:56
@AvdLee
AvdLee merged commit 858f178 into master Sep 4, 2026
1 check passed
@AvdLee
AvdLee deleted the docs/sso-legal-disclosures branch September 4, 2026 10:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant