The agreement between you and us when you use Login Broker in your app. It is short on purpose, and written to be read rather than clicked past.
Last updated 17 August 2026
Login Broker is operated by Gyxi, a company registered in Denmark, VAT number DK28916779. “We” and “us” mean Gyxi. “You” means the person or company that holds a Login Broker account.
Everything goes through nb@gyxi.com. There is no ticket system to escalate through.
Login Broker sends someone to an identity provider, gets a verified email address back, and hands that address to your app. That is the entire service.
It is not an identity platform. It does not hold your user table, issue your sessions, or manage your roles and permissions. Those stay yours, and building them is your job, not ours.
You pick a tenant name when you sign up. It cannot be changed afterwards, which we say on the sign-up screen and repeat here because people are surprised by it.
Your API key is a server-side secret. Keep it off the client, out of your repository and out of your bug tracker. Anything done with your key is treated as done by you, so tell us immediately if it leaks and we will issue a new one.
You need to be old enough to enter a contract where you live, and if you are signing up for a company you need to be allowed to commit it.
The short version is: use it to log people into your app, and nothing else. Specifically, do not
Security research is welcome — email us first and we will tell you what is in scope.
When your users sign in through Login Broker, you decide what happens to their data and we act on your instructions. In data protection terms you are the controller and we are your processor. What that means in practice — what we hold, for how long, who we use underneath, and what happens if something goes wrong — is set out on the privacy page for customers, and those processing terms are part of this agreement.
You are responsible for having your own lawful basis for signing those people in, and for telling them what your app does with their address. We cannot do that part for you.
Express is free up to 100,000 monthly active users. Pro is €19 per month plus €0.005 for each monthly active user above 100,000. A monthly active user is one distinct verified email address that completed at least one login in a calendar month — failed attempts, abandoned attempts and repeat logins by the same person are not counted twice.
Prices are in euro and exclude VAT, which is added where the rules require it. Pro is billed monthly; usage above the included allowance is billed after the month it happened in. There is no card on file for Express and no minimum term on either plan.
If you outgrow the free plan we get in touch before anything changes. We do not switch off a working sign-in button because a launch went well, and we do not backdate a bill to the month you crossed the line.
If an invoice goes unpaid we will chase it by email. Suspension is a last resort and never happens without at least 14 days' warning.
We work hard to keep the service up and we do not promise a specific uptime figure on either plan. If you need a contractual SLA, we can agree one in writing — it is the kind of thing Pro exists for. Support is by email; Pro gets priority.
The service will change over time. We may add providers, endpoints and behaviour whenever. If we need to change or remove something in a way that would break working integrations, account holders get at least 90 days' notice by email first.
Occasionally something has to change faster than that — a provider changes their API, or a vulnerability needs closing. We will still tell you, as early as we can.
You can stop whenever you like. Email us and the account and its data go. Leaving is unusually painless by design: you already hold the verified email addresses, so you register with the providers yourself and point your button at your own endpoint.
We can end the agreement if you break these terms and do not fix it within 30 days of us asking, or immediately if the breach is serious — an attack on the service, or something illegal. If we ever discontinue Login Broker entirely, account holders get at least 90 days' notice and a refund of anything paid for time not used.
We promise to provide the service with reasonable skill and care. Beyond that, and as far as the law allows, Login Broker is provided as it is: we do not warrant that it will be uninterrupted or error-free, and we are not responsible for the identity providers, who are not ours to control.
Neither of us is liable to the other for indirect or consequential loss, lost profits, lost revenue or lost data. Our total liability in any twelve-month period is capped at what you paid us in that period, or €100 if you are on the free plan.
Nothing here limits anything that cannot legally be limited — death or personal injury caused by negligence, fraud, or liability under data protection law. If you are a consumer rather than a business, your statutory rights are untouched by any of this.
Danish law applies, and the Danish courts have jurisdiction. If you are a consumer, this does not deprive you of the protection of the law where you live.
If a clause here turns out to be unenforceable, the rest still stands. Not enforcing something once does not mean giving it up. You may not transfer this agreement without asking us; we may transfer it if the business changes hands, and will tell you if that happens.
These terms plus the two privacy pages are the whole agreement between us. If we change them materially, account holders get 30 days' notice by email, and continuing to use the service after that means you accept the new version. If you would rather not, close the account and we will refund anything paid for time not used.
Signed data processing agreement, an SLA with numbers in it, a security questionnaire. All doable — that is what Pro is for.