Privacy policy
Effective date:
LoginHub is a sign-in service operated by Unikum – Unikt lärande AB, Swedish organisation number 556649-2350 ("Unikum", "we"). It verifies identities for connected education applications. This policy explains how LoginHub handles personal data, including data received from Google.
This deployment is a test environment for authorised test accounts. The connected application and your organisation determine your account and permissions; their privacy notices also apply to their own processing.
Information we receive
- Google Workspace sign-in: we receive a signed identity response containing your Google user ID, Workspace domain and security information needed to validate the login. We request the
openid,emailandclassroom.profile.emailspermissions and retrieve your own Google Classroom user profile. We check that its user ID matches the signed Google user ID. The standard Google email permission supports the identity response, including Workspace-domain information. The identity response can contain your email address and email-verification status; LoginHub discards these fields after validation and does not store or forward them. Although the Classroom profile response can include your email address, name and photo information, LoginHub uses only its ID and discards the other profile fields. We do not use email to match accounts or as a substitute for the signed Workspace domain. - Other sign-in providers: we receive the verified Unikum user ID or the identity attributes configured for your organisation's SAML provider. Depending on that provider, these can include a personal or national identifier. We also process the provider's identity and authentication evidence to verify the response.
- Service and security information: we process session and authorisation records, login and security events, and technical request information such as IP addresses and browser information in server logs.
Your provider receives your password on its own sign-in page. LoginHub does not receive your Google or Unikum password. LoginHub does not request Google Classroom courses, rosters, assignments or grades, and does not modify Classroom data.
How we use and share information
We use this information to verify sign-ins, recognise the same external identity on later visits, issue and refresh LoginHub tokens, and protect the service against unauthorised access and replay attacks.
LoginHub assigns a stable internal identifier to each external identity. When you sign in to a registered application, it receives signed LoginHub identity information. Where configured for that application, this also includes selected verified identifiers that it needs to find your account. School Hub receives your verified Google user ID or Unikum user ID according to the provider you use. The authorised test application can display selected identity attributes for integration testing. Each application controls its own account matching and access decisions.
We do not pass your provider's access tokens, refresh tokens or original authentication response to connected applications. Google tokens are used during login validation and are not retained for later Google API access.
Access by service operators is limited to operating and protecting the service and handling authorised support or legal requests. Any service providers processing information for us must act under our instructions and applicable data-protection arrangements. Information may also be disclosed when required by law.
Google data and Limited Use
Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google data is used for the sign-in and account-identification features described here. Transfers to connected applications support those features with your authorisation, or are necessary for security or legal compliance.
We do not sell Google data, use it for advertising, or use it to train general-purpose AI models. Human access to Google data is limited to your explicit agreement to view specific data, necessary security investigations, or legal obligations.
Storage, security and retention
LoginHub stores the association between a provider's identifier and its internal identifier, together with security and authorisation records. Stored external identifiers are encrypted, and their lookup values are protected using keyed hashing. Public connections use HTTPS. Access to operational data is restricted to authorised operators.
Identity records remain available across sign-ins so that your identity stays consistent. They are retained while needed for that purpose, your organisation's authorised use, and applicable security or legal obligations. Signing out does not delete these records. This test deployment does not automatically erase identity or audit records on a fixed schedule; deletion is handled by operators following the request process below. Session and token expiry ends their validity and is not a promise that all related database, log or backup records have been erased.
Cookies and sign-out
LoginHub uses essential session and security cookies to complete sign-in, associate requests with your browser and protect the login process. It does not use advertising or analytics cookies. Blocking essential cookies can prevent sign-in. Fonts and branding assets are served by this service.
Signing out of LoginHub does not necessarily sign you out of Google, Unikum or a connected application. You can also remove LoginHub's access through your Google Account's third-party connections settings. Removing Google access prevents future use of that permission, but does not itself delete stored LoginHub identity records or immediately end an existing LoginHub session. Contact us if you also need those records removed or access revoked.
Your choices and contact
For access, correction or deletion requests, or questions about this policy, contact dataskydd@unikum.net and mention LoginHub. You can also contact your organisation's administrator. Do not send passwords or tokens. We may need to verify your identity before acting on a request.
Where Unikum processes information on behalf of your school or organisation, we help that organisation respond under its data-protection arrangements. Depending on applicable law, you may also have rights to restrict or object to processing, receive a portable copy, or complain to your data-protection authority. Withdrawal of a permission does not affect processing already lawfully carried out.
Changes to this policy
Updates will be published on this page with a revised effective date. Material changes to how we use Google data will be brought to your attention, with renewed consent where required before the new use begins.