Legal
Privacy Policy
Effective date: 11 September 2026
authentication (“we”, “our”, or “us”) respects your privacy. This policy explains what information the app handles, how it is used, and what stays on your device.
By installing or using the app you agree to the practices described here. If you do not agree with this policy, please discontinue use of the app.
1. Information we collect
1.1 Personal information
The app is designed to work without personally identifying information. We do not ask for your name, email address, phone number, or contacts, and there is no account to create. You can use the app without submitting any personal data to us.
1.2 Authentication data
The app generates time-based one-time passwords (TOTP) for two-factor authentication. The setup keys behind those codes, and the codes derived from them, are stored on your device.
We do not collect, access, or store your setup keys or generated codes on our servers, unless you explicitly enable the optional backup feature in the app.
You are responsible for keeping your device secure and for keeping the recovery codes each service provides when you enable two-factor authentication.
1.3 Non-personal information
To keep the app stable we may automatically collect limited technical information that does not identify you, such as:
- Device model and manufacturer
- Operating system version
- Crash reports and diagnostic information
- General region or country (not precise location)
- TODO_CONFIRM: advertising identifier provided by the device
2. How we use information
The information described above may be used to:
- Operate and improve the app
- Identify and fix crashes and technical faults
- Understand general usage trends
- Prevent misuse or unauthorised activity
We do not sell your personal information.
3. Permissions the app requests
Each permission is requested in context and used for a single purpose:
- Camera — requested only when you add an account, so the app can scan the QR code a service shows you. No photo or video is recorded, stored, or uploaded.
- Fingerprint and face unlock — handled entirely by your device's biometric system. The app receives only a pass or fail result; your biometric data never reaches us.
- Storage — used only if you enable encrypted backup, so the app can write and restore the backup file.
- Network access — used for crash diagnostics and, if you enable it, backup. Generating a code never requires a connection.
4. Advertising — TODO_CONFIRM
TODO: confirm whether authentication displays advertising. If it does, state that plainly here and name the networks used, linking to their policies — for example Google AdMob. If it does not, delete this section; an advertising clause in a policy for an app that shows no ads is misleading in the other direction.
5. Analytics — TODO_CONFIRM
TODO: confirm which analytics or crash-reporting service is bundled, if any, and link its privacy policy — for example Firebase. Information collected by such services is typically aggregated and anonymised. Delete this section if nothing is bundled.
6. Data security
We use reasonable technical and organisational measures to protect information against unauthorised access, alteration, or loss. Your setup keys remain on your device unless you enable backup. No system can be guaranteed completely secure.
7. Children's privacy
The app is not directed at children under 13, and we do not knowingly collect personal information from them. If we learn that we have, we will take steps to delete it.
8. Location
The app does not collect precise location. Where regional information is used, it is the general country or region reported by the device, and it is not used to track individuals.
9. Legal disclosure
We may disclose information where required by law or legal process, or where necessary to protect the rights, safety, or integrity of the app and its users.
10. Changes to this policy
We may update this policy from time to time. Changes are reflected by updating the effective date above. Continued use of the app after an update indicates acceptance of the revised policy.
11. Contact
Email: authentication@gamil.com