Privacy Policy
Last updated 5 September 2026Overview
TriviAll ("we", "us") is operated by TriviAll Ltd, a company registered in England and Wales. This policy explains what we collect when you sign in through the Auth Service — the sign-in system shared across TriviAll's products — and why. This site itself requires no sign-in and holds no account data of its own; the "Server logs" section below is the one thing it collects directly.
Your account
When you sign in, we store a user record containing your email address, the sign-in method you used (an OAuth provider, or a magic email link), an internal account identifier, and the date the account was created.If you sign in with an OAuth provider, we also store a lookup linking that provider's identity for you to your TriviAll account, together with your email address, so a repeat sign-in with the same provider identity resolves back to the same account. If you sign in via a magic email link, we store an equivalent lookup from your email address to your account.
Signing in
- Magic-link tokens. Requesting a sign-in link creates a single-use token tied to your email address. It expires automatically after 10 minutes, and is marked used the moment you redeem it — it cannot be reused after that.
- Sessions. Once you're signed in, we keep a session record — your account id, email, and when it was created — for up to 7 days, matching the lifetime of your session cookie. Keeping this record separately from the cookie is what lets us end a session early, for example when you sign out, rather than waiting for the cookie itself to expire.
- Rate limits. To stop the sign-in system being abused, we keep short-lived counters of sign-in attempts by IP address and by email address, each covering a rolling 1-hour window. These counters exist purely to enforce sending limits and expire automatically at the end of that window.
Server logs
Requests to our APIs — including this site's — are recorded in a structured log that includes your IP address, used for operational monitoring, debugging, and abuse prevention.
Who we share data with
We don't sell your data. A small number of service providers help us run TriviAll:
- Google, GitHub, Microsoft, and Apple — if you choose to sign in with one of these providers, they authenticate you and share your provider identity and email address with us.
- Amazon Web Services (AWS) — hosts our services, stores account and session data in DynamoDB, and sends magic-link sign-in emails through Amazon SES.
- Cloudflare — sits in front of our sites, routing traffic and identifying your IP address for the server logs described above.
A known limitation
Signing in with an OAuth provider and signing in with a magic link to the same email address currently create two separate TriviAll accounts, rather than one shared account. We're aware of this and plan to unify sign-in methods under a single account in future. Until then, each sign-in method you use is its own account.
Your data, your choices
Contact us at [email protected] to ask what we hold about you, correct it, or have your account deleted. TriviAll is in beta, so treat this as best-effort rather than a guaranteed turnaround — see the Terms of Service.
Changes to this policy
We may update this policy as the product changes — particularly as we build out account management or unify sign-in identities. We'll update the "last updated" date above whenever we do.