LatchID

Latch Privacy Policy

Last updated: September 22, 2026

This policy explains how Latch (also called LatchID) handles information when you use latchid.com, auth.latchid.com, our application console, or a Latch sign-in connection. Contact the Latch team at auth@wrooms.ai with privacy questions.

Our role

Latch connects identity providers, such as Google, to applications that use Latch for sign-in. We operate the Latch console and authentication service. The application you sign into controls its own account, content, and use of information it receives. Its privacy policy also applies. Provider consent screens may identify Latch even when you are signing into another application.

Information we process

How we use information

We use information to authenticate users, deliver sign-in results to the application they selected, maintain app-specific accounts and sessions, send account and security emails, prevent abuse, investigate faults, provide support, and operate the service. Matching email addresses alone do not automatically link identities across applications.

Google sign-in

Google sign-in requests basic OpenID, email, and profile permissions. It does not request access to Gmail messages, Drive files, or Calendar events. We use Google account information for the authentication and account features described here. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Latch's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

When information is shared

When you sign in, Latch shares the authentication result, an app-specific user identifier, and available identity profile information with the application you chose. Your identity provider processes the sign-in under its own policies. Infrastructure providers process information needed for hosting, database storage, network delivery, and transactional email; our infrastructure includes Render and Cloudflare. We may disclose information when necessary to comply with applicable law, protect users or the service, or handle a business transfer subject to appropriate safeguards. Latch does not sell authentication information or share it for targeted advertising.

Cookies and local settings

We use authentication cookies and temporary browser state to bind sign-in requests and protect sessions. Local browser storage may remember presentation preferences such as the color theme. Blocking necessary cookies can prevent sign-in. Revoking access at your identity provider does not necessarily end a session already created by a connected application; sign out of that application as well.

Retention and security

Temporary authorization codes, sign-in requests, and sessions have expiration times and are periodically cleaned up. Identity mappings and application records remain while needed to operate the account or application. Security, support, and infrastructure records may be retained for operational, dispute-resolution, or legal needs. Deletion from backups may take longer than deletion from active systems. We use encrypted transport, server-side credential encryption, password hashing, and access controls. No system can guarantee absolute security.

Your choices and requests

You can decline provider consent and manage connected access through your provider. Application owners can manage their connections and revoke Latch sessions in the console. To request access, correction, export, or deletion of information held by Latch, contact auth@wrooms.ai; include the application name, but never send passwords or provider secrets. We may verify your identity before acting. Contact the connected application separately for data it holds. Depending on your location, you may also have rights to object, restrict processing, withdraw consent, or complain to your local data-protection authority.

International processing and children

Infrastructure providers may process information in countries other than your own. Applicable safeguards depend on the service and region involved. Latch is not directed to children under 13. If you believe a child has provided information inappropriately, contact us so we can investigate.

Changes

We will update this page when our practices change and provide additional notice when appropriate or required. The date above identifies this version.