Privacy policy
Last updated 3 October 2026.
Who processes the data
Sigve Løndal is the controller of the data in idgo. Contact: post@idgo.no.
What is stored
- Username and email address, and whether the address is confirmed.
- Your password, stored as a cryptographic hash. The password itself is not stored and cannot be read out.
- The details you choose to fill in yourself: full name, phone, address, postcode, town and country. All are optional.
- Which login services the account is connected to. Today that is Google and Discord. For each connection, the service’s name for you, the ID you have with the service, and when the connection was added are stored. If the service provides an email address and profile picture, those are stored too.
- If you create an account with Discord without Discord providing an email address, the account gets a placeholder address that is not a real inbox. It is marked as unconfirmed, and you can change it to your own address.
- If you turn on two-factor: the key the authenticator app makes the codes from, the public part of each passkey with the name you gave it, and hashes of the backup codes. The secret part of a passkey never leaves your device.
- When the account and the connections were created, and when the account was last used.
- A login log: time, which app, which login method and whether the login succeeded. Your IP address is not stored in the log.
Why
The data is used to run login across Sigve Løndal’s apps, and to show who you are inside them. The legal basis is the agreement you enter into when you create an account.
The account is shared across the apps
There is one account for all the apps. When you log in to one of them, the app learns who you are, the details on your profile, and which login services the account is connected to, with the ID you have at each of them. The apps need that list to recognise users they already had. They never get your password.
The data is not sold and is not used for ads. Outside the apps, it is only shared with the login services you connect yourself, and only when you choose to connect them.
Usage statistics from the apps
The apps that use idgo send an anonymous message here when a page opens: which page, whether the screen is small or large, which website you came from, and a code made from your network address and your browser. The code is replaced every day and cannot be turned back into you. The message sets no cookie and is not linked to your account. The statistics are used to run and maintain the apps, not for ads.
Cookies
The service sets one cookie that keeps you logged in, and one that remembers the language you chose. They are not used for tracking or statistics, and there are no analytics tools on idgo’s own pages.
How long
The data is stored as long as the account exists. When the account is deleted, it is removed from the database along with the connections to login services. The login log and the usage statistics are deleted after 13 months.
Your rights
- You can see and correct most of the details yourself on your profile page.
- You can ask to see everything that is stored about you.
- You can have your account deleted: send an email to post@idgo.no from the address on the account, and it is deleted as soon as possible.
- If you believe the data is handled wrongly, you can complain to the Norwegian Data Protection Authority (Datatilsynet).