Sentent CoreLegal

Privacy Policy

Effective July 27, 2026 · SententAI, LLC

Sentent Core exists to prove who you are to the applications you use, and it collects only what that requires. This policy describes exactly what is collected, who it is shared with, how long it is kept, and what you can change yourself. It took effect on July 27, 2026.

1.Scope of this policy

This Privacy Policy explains how SententAI, LLC, a Texas limited liability company (“SententAI, LLC,” “we,” “us”) handles personal information in Sentent Core, our hosted identity and authentication service. It covers the sign-in screens, the consent screen, the account portal at /account, the operator console, and the protocol endpoints that issue tokens.

It does not cover what a connected application does with information after you sign in to it. Those applications may be operated by SententAI, LLC or by our clients, and each has its own privacy practices. See how information is shared below.

Sentent Core is a business service. It is not directed to children, and we do not knowingly collect information from anyone under 16.

2.Information we collect

Sentent Core is deliberately narrow: it collects what is needed to prove who you are, to keep that proof secure, and to record what was authorized. Specifically:

Profile information

  • your name;
  • your email address, and whether it has been verified;
  • your profile picture, where one is supplied; and
  • your organization (tenant) membership and the roles assigned to you within it.

Profile information comes from your sign-in provider, from the administrator who invited you, or from edits you make yourself in the account portal.

Authentication and security records

  • a security audit log of authentication events — sign-in attempts and outcomes, sign-outs, multi-factor challenges, email changes, consent decisions, and administrative actions on your account — each recorded with a timestamp, the application involved, your IP address, and your browser or client user agent;
  • your active sessions, including the device or client that created each one and when it was last used;
  • your multi-factor authentication enrollment status, including whether a time-based one-time password (TOTP) authenticator is enrolled and when it was last verified; and
  • your OAuth consent grants — which connected applications you have authorized, what information each was authorized to receive, and when.

We store TOTP secrets and session material in a form managed by our authentication provider and never display them again after enrollment. We do not receive or store your password for any third-party sign-in provider.

Operational records

Our infrastructure providers generate short-lived server and request logs, and rate-limit counters keyed to an identifier such as an IP address or account, in order to detect abuse and keep the Service available.

3.Sign-in providers

You can sign in to Sentent Core in these ways:

  • Google — you authenticate with Google, which returns your name, email address, and profile picture to us. We do not see your Google password.
  • Email magic link — we email a single-use sign-in link to the address on your account.
  • Microsoft Entra ID — offered for organizations that use it, and it works the same way as Google: Microsoft authenticates you and returns your directory profile claims to us.

Which methods are available depends on your organization’s configuration. Your use of Google or Microsoft to authenticate is also subject to their own privacy policies.

4.How we use information

We use the information above only to operate the Service:

  • to authenticate you and maintain your session;
  • to issue identity and access tokens to connected applications you authorize;
  • to enforce your organization's membership, roles, and access decisions;
  • to provide multi-factor authentication and step-up challenges for sensitive operations;
  • to detect, investigate, and prevent unauthorized access, fraud, and abuse, including rate limiting;
  • to send transactional email — sign-in links, email-change confirmations, invitations, and security notices;
  • to provide support when you contact us; and
  • to comply with legal obligations and to establish or defend legal claims.

We do not use your information for advertising, profiling, or behavioral targeting, and we do not send marketing email from the Service.

5.The role of your organization

Where your account was provisioned by an organization, that organization directs how the account is used. It decides who is invited, what roles they hold, which applications they may reach, and when access ends. In data-protection terms, the organization is generally the controller of that information and SententAI, LLCprocesses it on the organization’s behalf, subject to our agreement with them.

Practically, this means your organization’s administrators can see your account status, your membership and roles, and security and audit information about activity on the organization’s account. If you want your information corrected or removed and your account belongs to an organization, we may need to direct your request to that organization.

6.How information is shared

With connected applications you authorize

Sharing profile claims with applications is the purpose of the Service. When you sign in to a connected application, Sentent Core releases the claims that application was authorized to receive — typically your name, email address, profile picture, and your organization membership and roles — in the identity and access tokens it issues, and through the userinfo endpoint.

You are shown what an application is asking for before the first release, and you can review and revoke every authorization from the account portal. Connected applications may be operated by SententAI, LLC or by our clients; once information is released to an application, that application’s own privacy practices govern it, and revoking an authorization here does not delete what it already holds.

Through signed webhooks

Connected applications can subscribe to signed webhooks so their own records stay current. These deliver membership and session events — for example that a member was invited, that roles changed, that a member was deactivated, or that sessions were revoked — to endpoints registered by the application’s operator. Each delivery is cryptographically signed so the receiver can verify it came from us.

With service providers

We share information with the infrastructure providers listed in subprocessors, which process it on our behalf under contract.

For legal and corporate reasons

We may disclose information where required by law, subpoena, or other legal process; to protect the rights, safety, or security of users, the public, or SententAI, LLC; or in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor commitments materially equivalent to this policy.

We do not otherwise share your personal information with third parties.

7.Subprocessors and infrastructure

Sentent Core is built on the following providers. Each processes personal information only as needed to deliver its function:

  • Supabase — database and authentication: the system of record for accounts, sessions, multi-factor enrollment, consent grants, and the audit log.
  • Vercel — application hosting, edge delivery, and request logging.
  • Upstash — rate limiting: short-lived counters keyed to an IP address or account identifier.
  • Resend — transactional email delivery: sign-in links, invitations, confirmations, and security notices.
  • Google and Microsoft — sign-in providers, where you choose or your organization requires them.

Our providers operate infrastructure in the United States and may process information in other countries where they operate. We may update this list as the Service evolves; the current list is always the one on this page.

8.Cookies

Sentent Core sets essential cookies only. They carry your authenticated session and the state needed to complete a sign-in or authorization flow safely, and a local preference for light or dark theme.

There are no advertising cookies, no analytics or marketing pixels, no cross-site tracking, and no third-party trackers on our sign-in surfaces. Blocking essential cookies will prevent you from signing in.

9.Your choices and controls

Most of what you might ask us to do, you can do yourself. The account portal at /account lets you:

  • view and edit your profile — your name and profile picture;
  • change the email address on your account, with verification of the new address;
  • review every active session, with its device and last-used time, and revoke any of them — including "sign out everywhere", which ends all sessions at once;
  • enroll, re-enroll, or remove multi-factor authentication, subject to any requirement set by your organization; and
  • review which applications you have authorized and disconnect any of them, which revokes their consent grant and the tokens issued under it.

For anything the portal does not cover — access to a copy of your information, correction, deletion, restriction, objection, or a question about how a specific record was used — contact scott@sententai.com. We will verify your identity before acting on a request and will respond within the time required by applicable law. Where your account belongs to an organization, we may need that organization’s instruction before acting.

Exercising these rights will never cost you access to the Service or result in discriminatory treatment.

10.Data retention

  • Account and profile information is kept while your account is active, and afterward for as long as your organization requires or applicable law permits.
  • Sessions and tokens are short-lived by design and are deleted or invalidated when they expire or when you revoke them.
  • Consent grants are kept until you disconnect the application, and the record that a grant was revoked is retained in the audit log.
  • Security audit logs are retained for security, incident investigation, and compliance purposes, and may outlive the account they describe — a record of who signed in and from where is only useful if it survives the event.
  • Rate-limit counters expire automatically within minutes to hours.

When information is no longer needed for these purposes, we delete it or irreversibly de-identify it.

11.No sale of data, no AI training

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have never done so and this policy will not be changed to permit it without prior notice.

We do not use your personal information to train, fine-tune, or evaluate artificial intelligence or machine-learning models, and we do not provide it to any third party for that purpose.

12.How we protect information

  • Encryption in transit — all traffic to the Service is served over HTTPS, and connections to our database and providers are encrypted.
  • Multi-factor authentication — TOTP-based second factors are supported for all accounts and can be required for privileged operator access.
  • Scoped access — tokens carry only the claims an application was authorized to receive, tenant data is isolated at the database layer, and administrative capability is granted by role rather than assumed.
  • Audit logging — authentication and administrative events are recorded so unusual activity can be detected and investigated.
  • Rate limiting and abuse controls on authentication and token endpoints.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and your organization as required by applicable law. Report a suspected security issue to scott@sententai.com.

13.Changes to this policy

We may update this policy as the Service changes, as we add or replace subprocessors, or as legal requirements change. When we do, we will revise the effective date at the top of this page.

For changes that materially affect how we handle your personal information, we will give reasonable advance notice — by email to the address on your account, by notice within the Service, or to your organization’s administrator — before the change takes effect.

14.Contact

SententAI, LLC

Privacy questions, data requests, and security reports: scott@sententai.com

This policy is governed by the laws of the State of Texas, United States, as described in the Terms of Service.