Privacy Policy

Last updated: March 2026

Introduction

Smoke Turner, LLC (“we”, “us”, or “our”) operates the Vouch authentication service (“Vouch” or the “Service”). This Privacy Policy describes how we collect, use, and protect your personal information when you use Vouch through your organization’s deployment.

Vouch is designed with a privacy-first approach. We collect only the minimum information necessary to authenticate your identity and issue short-lived credentials. We do not sell your data, do not use it for advertising, and do not share it with third parties except as described in this policy.


Information We Collect

Account Information

When you enroll with Vouch, we receive basic identity information from your organization’s identity provider (IdP):

We do not ask you to create a separate username or password. Your identity is established entirely through your organization’s existing identity provider.

GitHub Integration Data

If your organization uses the Vouch GitHub integration, we store:

Authentication Data

When you register a security key and authenticate with Vouch, we collect:

Vouch never stores your private keys. The private key component of your FIDO2 credential never leaves your hardware security key. We store only the public key, which cannot be used to impersonate you.

Usage Logs

We collect operational logs to maintain security and troubleshoot issues:


How We Use Your Information

We use the information we collect for the following purposes:


Data Retention


Data Security

We employ multiple layers of security to protect your information:


Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

To exercise any of these rights, contact your organization’s IT administrator or security team. They can process your request directly or escalate it as needed.


Contact

For questions about this Privacy Policy or about how your data is handled within Vouch, contact your organization’s IT administrator or security team. They manage your organization’s Vouch deployment and can address questions about data collection, retention, and deletion.

For questions about the Vouch software itself, contact Smoke Turner, LLC at privacy@vouch.sh.


Cookies and Tracking

Vouch uses a single session cookie (vouch_session) required for authentication. This cookie is set with HttpOnly, Secure, and SameSite=Lax attributes — it cannot be read by JavaScript, is only sent over HTTPS, and is not sent in cross-site requests. We do not use analytics cookies, advertising trackers, or any third-party tracking technologies.


International Data Transfers

The Vouch service is hosted in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer of your information to the United States.


Children’s Privacy

Vouch is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided personal information, we will take steps to delete that information. If you believe a child under 13 has provided personal information to us, please contact us at privacy@vouch.sh.


Data Controller and Processor

Under applicable data protection laws, your organization (the entity that operates the Vouch deployment) is the data controller responsible for determining the purposes and means of processing your personal information. Smoke Turner, LLC acts as a data processor, processing personal information on behalf of your organization according to their instructions and the terms of the applicable service agreement.

For questions about how your personal data is processed, contact your organization’s data protection officer or IT administrator. For questions about Smoke Turner, LLC’s data processing practices, contact privacy@vouch.sh.