Skip to content
triad/
DEMOACCOUNTDISCOVERYSOURCE ↗

DATA RETENTION / CURRENT IMPLEMENTATION

WHAT TRIAD
KEEPS.

Triad is an identity broker. This inventory describes the data the current service stores and the behavior of account deletion.

01 / INVENTORY

THE ACCOUNT RECORD

IDENTITY VALUES
A pseudonymous account identifier, the provider identity family, and pseudonymous provider-derived claims. The provider account record also keeps the verified issuer and immutable upstream account ID required to recognize the same sign-in again.
PROFILE ENVELOPE
When a provider supplies them, email, email verification state, handle, display name, and avatar URL are stored together in an encrypted, versioned profile envelope. A passkey account stores its canonical username as this encrypted handle. The encryption secrets are separate from the identity and session secrets.
WALLET + PASSKEY CREDENTIALS
Better Auth stores wallet addresses and authenticated chains in its wallet table, and passkey credential IDs and public keys in its passkey table, because those values are required to verify later sign-ins. Triad also stores the immutable canonical username and its account mapping to enforce uniqueness. A Triad account can retain multiple passkeys, and each credential belongs to only that account. Triad does not disclose these values to an OAuth client by default. A client receives the canonical passkey username as preferred_username only when it requests and the user approves handle. A client receives credential material only when it requests and the user approves wallet, chains, chain_id, cred, pubkey, or cosekey. The chain_id value identifies the chain used for the current SIWE session.
SESSION METADATA
Browser sessions include a session credential and expiry. Triad clears the request IP address and user agent before every session record is created or updated, so those generated database fields remain empty. Sessions are used to keep the account page and approval flow authenticated.
PROTOCOL RECORDS
Triad stores OAuth client and resource metadata, consent records, authorization grants, access-token records, refresh-token records, and device authorization records when those flows use them. A device record states whether the requester is Triad itself or a registered OAuth client, plus its requested scopes and resource.
WALLET REQUESTS
A Wallet Authorization temporarily stores the Triad Account, registered Client Application and redirect, callback state, requested message, selected Wallet Namespace and subject, Wallet Profile, Account Index, resolved path, applicable Chain ID, selected Passkey ID, WebAuthn challenge, exact Signing Envelope, expiry, and one-time consumption time. A Wallet Capability proof temporarily stores its Triad Account, selected Passkey ID, challenge, capability envelope, expiry, and one-time consumption time. Expired records are removed when another matching request starts or when the Triad Account is deleted.

02 / BOUNDARY

WHAT IS NOT KEPT

Triad does not retain upstream provider access tokens, refresh tokens, or ID tokens after provider sign-in. Triad also does not receive a provider password. Wallet and Passkey credential material is retained only for authentication and explicitly approved claims; it is not included in default client identity claims. Triad never receives or stores Passkey PRF outputs, Wallet Seeds, Derived Wallet private keys, or mnemonic phrases. The provider remains responsible for data it keeps about your provider account.

Triad's application database does not store request IP addresses, authentication paths, or browser user-agent strings. For rate limiting, Triad derives an opaque keyed bucket from normalized request input in memory and stores only that bucket, its request count, and a timestamp.

03 / RETENTION

WHEN RECORDS LEAVE

The encrypted profile envelope belongs to the Triad Account and is removed with it. Triad Account deletion also removes sessions, wallet or Passkey credentials, provider accounts, device and wallet request records, consents, grants, and Account Holder-bound OAuth token records. Database relationships remove other account-owned records when their account record is deleted.

Already issued short-lived JWTs can remain verifiable until their expiry. Triad does not claim to revoke a provider session or delete data held by an upstream provider. Platform signing keys and anonymous protocol metadata are retained as service infrastructure rather than account profile data.

04 / CONTROL

DELETE THE ACCOUNT

Use the account page while signed in to request account deletion. The action is immediate in the current service: Triad deletes the account and the account-bound records described above, then ends the browser session. If the page cannot complete the request, it shows a recovery state instead of implying deletion.

TRY TRIADDISCOVERYACCOUNTPRIVACYTERMSSOURCE ↗BUILD 044b1d9 ↗