durumis official blog

We Cherish Your Personal Information

Created: 2024-02-07

Created: 2024-02-07 17:00

durumis Logo

durumis Logo

durumis service values your personal information.

Therefore, when you sign up or log in, we only collect your email address. We do not collect passwords separately. Instead, we send a verification email to your email address so you can log in by entering a verification code or clicking a link.

Personal Information Collection: Email

Since we send a verification number via email, we must store a cookie value to maintain your login status afterward.

Passwordless Authentication Method

durumis uses a passwordless method.

“Passwordless” refers to a method of logging in without entering a password by sending a verification code via email. It is a secure method against password hacking and fundamentally prevents issues like password leaks.

Currently, we are using a passwordless method, but we plan to upgrade to a more secure “passkey” method in the future.

(Passkeys are the most secure method used by companies like Google and Apple.)

Why We Don't Collect Passwords

According to various company research, 52-65% of users use the same password for three or more services. If a password is leaked from one of those three or more services, it becomes extremely dangerous because it can be used to log in to the other services as well. However, managing separate passwords for each service is inconvenient because users often forget their passwords.

For these reasons, durumis does not collect passwords individually from users and instead sends a verification email for login.

Comments0