Privacy Policy

Last updated 5 September 2026

Overview

TriviAll ("we", "us") is operated by TriviAll Ltd, a company registered in England and Wales. This policy explains what we collect when you sign in through the Auth Service — the sign-in system shared across TriviAll's products — and why. This site itself requires no sign-in and holds no account data of its own; the "Server logs" section below is the one thing it collects directly.

Your account

When you sign in, we store a user record containing your email address, the sign-in method you used (an OAuth provider, or a magic email link), an internal account identifier, and the date the account was created.If you sign in with an OAuth provider, we also store a lookup linking that provider's identity for you to your TriviAll account, together with your email address, so a repeat sign-in with the same provider identity resolves back to the same account. If you sign in via a magic email link, we store an equivalent lookup from your email address to your account.

Signing in

  • Magic-link tokens. Requesting a sign-in link creates a single-use token tied to your email address. It expires automatically after 10 minutes, and is marked used the moment you redeem it — it cannot be reused after that.
  • Sessions. Once you're signed in, we keep a session record — your account id, email, and when it was created — for up to 7 days, matching the lifetime of your session cookie. Keeping this record separately from the cookie is what lets us end a session early, for example when you sign out, rather than waiting for the cookie itself to expire.
  • Rate limits. To stop the sign-in system being abused, we keep short-lived counters of sign-in attempts by IP address and by email address, each covering a rolling 1-hour window. These counters exist purely to enforce sending limits and expire automatically at the end of that window.

Server logs

Requests to our APIs — including this site's — are recorded in a structured log that includes your IP address, used for operational monitoring, debugging, and abuse prevention.

Who we share data with

We don't sell your data. A small number of service providers help us run TriviAll:
  • Google, GitHub, Microsoft, and Apple — if you choose to sign in with one of these providers, they authenticate you and share your provider identity and email address with us.
  • Amazon Web Services (AWS) — hosts our services, stores account and session data in DynamoDB, and sends magic-link sign-in emails through Amazon SES.
  • Cloudflare — sits in front of our sites, routing traffic and identifying your IP address for the server logs described above.
Each provider processes data under its own privacy policy, in addition to this one.

A known limitation

Signing in with an OAuth provider and signing in with a magic link to the same email address currently create two separate TriviAll accounts, rather than one shared account. We're aware of this and plan to unify sign-in methods under a single account in future. Until then, each sign-in method you use is its own account.

Your data, your choices

Contact us at [email protected] to ask what we hold about you, correct it, or have your account deleted. TriviAll is in beta, so treat this as best-effort rather than a guaranteed turnaround — see the Terms of Service.

Changes to this policy

We may update this policy as the product changes — particularly as we build out account management or unify sign-in identities. We'll update the "last updated" date above whenever we do.