Privacy Policy
What we collect, why, who processes it, and how to reach us about it.
Effective 19 September 2026
Who we are
RealmSSO is operated by Peasy Services. For anything in this policy, write to support@realmsso.com.
This website
realmsso.com is a set of static pages. It sets no cookies, runs no analytics, and loads no third-party scripts or fonts. When you open a page, the web server that serves it sees the same thing every web server sees — your IP address, the page requested and your browser's user-agent string — in its ordinary access logs. We do not combine that with anything else.
The site has one form, on the contact page. What you type there — your name, your email address, your company if you give one, and your message — is sent from your browser to our API at api.realmsso.com, which emails it to our support mailbox — through Amazon SES, named below — together with the IP address and browser user-agent of the request, so that we can tell people from bots. Before it sends, your browser solves a small puzzle issued by that same API — a proof-of-work check that runs on your device, uses no third-party CAPTCHA service, sets no cookie and sends nothing about you. Neither the site nor the API stores what you submit; the email is the only copy, and we keep it for as long as we need it to answer you.
Whether you use the form or write to support@realmsso.com directly, your message is delivered to the same mailbox and kept there for as long as we need it to answer you.
The product
RealmSSO is single sign-on infrastructure. When you or your customers use it, the server stores the following — and only the following — about people:
- Vendor users (the people who run a RealmSSO dashboard): the email address you sign in with and whether it has been verified. Sign-in is by a one-time link sent to that address; there is no password to store.
- Accounts (your customers): the account name and identifier you give it, and any email domain you register and verify for it.
- SSO connections: the configuration of a customer's identity provider — its entity ID or issuer, sign-on URL, signing certificate, and for OIDC a client ID and secret. The secret and the certificate are encrypted at rest; see Encryption at Rest for exactly which fields and how.
- Admin-portal invitations: the email address and display name of the customer administrator you invite, and the short-lived, single-use session that link opens.
- API keys and webhooks: a hash of each API key (the key itself is never stored), and for webhooks the destination URL and a log of delivery attempts.
- Audit and sign-in events: who did what and when — including the IP address and user-agent of the request — so that an administrator can answer “who changed this?” and “who signed in?”.
- Directory sync (SCIM): when a customer connects their directory, the users and groups their identity provider pushes to us — typically name, email and group membership. The customer's directory is the source of that data and controls it.
People who sign in through a customer's SSO connection authenticate with their own organisation's identity provider. RealmSSO brokers that sign-in and records the event; it does not hold their password.
Why we hold it
To provide the service you asked for: to sign you in, to broker your customers' sign-ins, to let their administrators configure their own connection, and to give you an accurate record of what happened. We do not use any of it for advertising, we do not sell it, and we do not send marketing email.
Who else processes it
Amazon Web Services (Amazon SES, US East region) delivers every email the product sends — sign-in links, admin-portal invitations, and the messages submitted through the contact form. AWS receives the recipient address and the message; for a contact-form message that is everything you typed, together with the IP address and user-agent of the request, on its way to our mailbox. Nothing else about you leaves infrastructure operated by Peasy Services.
If you self-host RealmSSO, none of the product data above reaches us at all — it stays on your infrastructure, and you are the controller of it. If we host it for you, it sits in the Keycloak realm we run for your account, on the cluster described under Pricing, and we process it for you under the written agreement that covers that tier.
How long we keep it
For as long as the account it belongs to exists. Deleting an account deletes its configuration, its connections and the identity realm behind them (see Backup & Recovery for what that means operationally). Sign-in links expire in minutes and admin-portal invitations within the hour; both are single use.
Your rights
You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Write to support@realmsso.com from the address in question. If you are an end user of a customer's application, your organisation's administrator controls your directory data; we will help them act on your request.
Changes
When this policy changes in substance, the effective date at the top changes with it. The current version is always at this address.