Privacy Policy
Last updated: 2 October 2026
Overview
BlitzCore ID (BCID) is the central identity platform for the BlitzCore ecosystem. It provides authentication, account management, and authorization for first-party BlitzCore applications and third-party applications that integrate with BCID.
This Privacy Policy describes what information BCID collects, how it is used, and the choices you have regarding your data. It applies when you create a BCID account, sign in, or use any BlitzCore application that authenticates through BCID.
Information we collect
Account information: When you register for a BCID account, we collect your email address, a username of your choice, your first and last name (optional), and a password. The password is hashed using PBKDF2-SHA256 before storage; we never store plaintext passwords.
Profile information: You may optionally provide a profile picture, display name, country, administrative division (state/province/region), date of birth, bio, and a recovery email address. Profile pictures are stored in a private Cloudflare R2 bucket and are only accessible through authenticated BCID endpoints.
Location information: When you select your country and administrative division, BCID stores the ISO 3166-1 country code and the ISO 3166-2 subdivision code you selected. This data is reference-based and validated against a structured dataset of countries and first-level administrative divisions.
Authentication data: If you sign in with Google, BCID receives your Google subject identifier (a stable, unique ID), your Google email address, and the display name and profile picture from your Google account. BCID uses the Google subject identifier as the trusted external identity key; we never rely on email alone to identify a Google-linked account.
Session and device information: When you sign in, BCID records the IP address, user agent string, browser family, operating system, device type, and approximate country derived from the request. This information is associated with your active sessions so you can review and revoke them from your account portal.
Security event data: BCID logs security-relevant events such as successful and failed sign-in attempts, password changes, email verification, account recovery, OAuth consent, session creation and revocation, and connected-app authorization. These logs do not contain plaintext passwords, tokens, or secrets.
How we use information
To authenticate you and authorize access to BlitzCore applications.
To send you transactional emails including email verification, password reset, recovery, and security alerts. These emails are sent via the Brevo transactional email service from the mail.bcr.com.ng domain.
To display your account information, sessions, and connected applications in the BCID account portal.
To detect and prevent unauthorized access, abuse, and fraud. This includes rate limiting, bot detection via Cloudflare Turnstile, and audit logging of security events.
To allow you to manage your account, including profile updates, password changes, session revocation, connected-app revocation, and account deletion.
To issue OpenID Connect ID tokens and OAuth access tokens to applications you have authorized, containing only the claims and scopes you have explicitly consented to.
Cookies and session technologies
BCID uses HTTP-only, secure cookies to maintain your authenticated session. The primary session cookie (bcid_sid) is set on the blitzcore.com.ng domain and is not accessible to JavaScript in your browser. This prevents cross-site scripting (XSS) attacks from stealing your session.
A CSRF protection cookie (bcid_csrf) is also set. Its value is sent as a custom request header on state-changing requests and validated server-side using a constant-time comparison to prevent cross-site request forgery.
BCID does not use third-party advertising cookies, tracking pixels, or analytics cookies. Cloudflare Turnstile may set a functional cookie on public authentication forms to verify you are a human; this is a security measure, not a tracking mechanism.
Session cookies are persisted for up to 30 days unless you explicitly sign out, revoke the session, or change your password (which revokes all other sessions).
Google sign-in
BCID integrates with Google using the OAuth 2.0 Authorization Code flow with PKCE. When you choose to sign in with Google, you are redirected to Google's authentication page, and Google redirects you back to BCID after you consent.
BCID receives your Google ID token and validates it server-side using Google's published JSON Web Key Set (JWKS). We verify the token signature, issuer, audience, expiration, and nonce. We never accept a client-submitted Google profile without server-side verification.
The Google client secret is stored only in the BCID backend and is never exposed to the browser. The Google OAuth redirect URI is configured as https://api.id.blitzcore.com.ng/api/v1/auth/google/callback.
You can link a Google account to an existing BCID account from the account portal, and you can unlink it at any time. If you unlink Google and your account has no password set, you will not be able to sign in until you add a password.
Connected applications and OAuth
When a third-party application requests access to your BCID account, you will see a consent screen showing the application name, the requested scopes, and a summary of what each scope allows. You can approve or deny the request.
BCID supports the standard OpenID Connect scopes: openid, profile, email, and offline_access. Each scope grants a specific, limited set of claims. Applications cannot request scopes you have not approved, and they cannot access data outside the scopes they were granted.
You can review and revoke any connected application at any time from the Connected Apps section of your account portal. Revoking an application immediately invalidates its access tokens and refresh tokens.
Application developers register their applications through the BCID developer console at console.bcr.com.ng. Client secrets are stored hashed and are never exposed after initial creation.
Data retention
Your account data is retained for as long as your account is active. If you deactivate your account, your data is retained but you cannot sign in until you reactivate.
If you request account deletion, your account enters a 14-day grace period during which you can cancel the deletion. After the grace period, your user record, profile, sessions, refresh tokens, OAuth grants, and profile picture are deleted from the active database.
Security audit events are retained for up to 365 days after which they are purged by an automated scheduled job.
Expired sessions, refresh tokens, email verification tokens, and password reset tokens are purged automatically on a regular schedule.
BCID does not guarantee that all backups, legally retained records, or cached data are instantly erased. If you have questions about specific retention obligations, contact us using the method described in the Contact section below.
Security
BCID is built on Cloudflare Workers and uses Cloudflare D1 for relational data and Cloudflare R2 for private object storage. All traffic is served over HTTPS.
Passwords are hashed using PBKDF2-SHA256 with a per-record random salt and a high iteration count. Verification tokens, password reset tokens, session IDs, refresh tokens, and authorization codes are stored as SHA-256 hashes, not as plaintext values.
BCID enforces layered rate limiting per IP, per account, per email, per action, and per OAuth client. Public authentication endpoints are protected by Cloudflare Turnstile.
BCID implements CSRF protection, CORS allowlisting, strict cookie attributes (HttpOnly, Secure, SameSite), and structured audit logging of security-relevant events.
No system can be guaranteed to be completely secure. If you believe your BCID account has been compromised, revoke all sessions from the account portal and change your password immediately.
Your choices
You can view, update, or delete your profile information from the BCID account portal at account.blitzcore.com.ng.
You can view and revoke active sessions and connected applications at any time.
You can export a machine-readable copy of your account data, including your profile, sessions, connected applications, and recent security events, from the Privacy section of your account portal.
You can deactivate your account temporarily or request permanent deletion. Permanent deletion enters a 14-day grace period; you can cancel during this window.
You can unlink Google from your account at any time from the Security section, provided your account has a password set.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the Last updated date at the top of this page. If we make material changes that affect your rights, we will notify you by email or through the BCID account portal before the changes take effect.
Continued use of BCID after a policy change constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy or your BCID account data, you can contact us through the BCID account portal or by email at no-reply@mail.bcr.com.ng. Transactional emails from BCID are sent from this address; for account-specific inquiries, sign in to your BCID account and use the support contact information provided there.