We process pseudonymous device and network evidence to prevent account takeover, fraud, automated abuse and fingerprint spoofing. Weak browser signals are treated as evidence, not certain proof of hardware, SIM ownership or misconduct.
The local installation identifier is transformed into an HMAC before server storage. Raw installation IDs, passwords and unnecessary raw entropy data are not retained.
Login-security cases expire automatically under the configured policy. Verified requests for access/export, correction and deletion are handled through the administrator privacy workflow.