Privacy Policy
How Authenticator App handles your information — and why your 2FA secrets never leave your device.
TechSmart LLC ("we," "us," or "our") operates the Authenticator App application ("Authenticator App," "the app"). This Privacy Policy explains what information the app collects, why we collect it, and the choices you have. By downloading, installing, or using Authenticator App, you agree to the practices described here. If you do not agree, please do not use the app.
Authenticator App is built on a zero-knowledge, offline-first design. Your 2FA secrets, one-time codes, and saved passwords are encrypted and stored in your device's Keychain — they are never uploaded to servers we control, and no Authenticator App account is required. Codes are generated entirely on your device, even with no internet connection. If you enable iCloud backup, your encrypted data syncs through your own iCloud account (managed by Apple), which we cannot access.
1. Information We Collect
We aim to collect as little as possible. You can use all of Authenticator App's core features — generating codes, App Lock, the password vault — without creating an account or giving us any personal information.
Information you provide
Nothing is required to use the app. We only receive information you choose to send us — for example, if you email our support team at [email protected], we will see your email address and whatever you write in your message so we can help you.
Information collected automatically
When you use the app, we and our analytics providers may automatically collect technical and usage information, including your device model, operating system version, app version, device language, coarse in-app usage and analytics events (such as which screens you open or how many accounts you have added — never the accounts themselves), crash and diagnostic data, and your approximate region derived from your IP address. This information is used in aggregate to keep the app stable and to understand which features are useful. It never includes your 2FA secrets, one-time codes, account names, or saved passwords.
Anonymous device identifier
The app uses a device-provided identifier (Apple's Identifier for Vendor) with certain requests — for example, to verify and log your subscription status. We use it only to operate features like subscriptions and to keep our analytics accurate. This identifier is not linked to your name, email, or Apple ID, and is not used to track you across other apps or websites.
Install attribution (Apple Search Ads)
If you installed the app after tapping an Apple Search Ads ad in the App Store, the app may ask Apple's AdServices framework for an attribution token to learn, in aggregate, which campaign the install came from. This involves no ad tracking inside the app and no advertising identifier; it only helps us measure our own App Store campaigns.
Purchase information
If you subscribe to Authenticator App PRO or buy the Lifetime unlock, your purchase is processed by Apple through the App Store (StoreKit). We receive confirmation of your subscription status so we can unlock PRO features, but we never receive or store your card number or any payment details — those are handled entirely by Apple.
2. Your 2FA Secrets & Passwords
When you add an account by scanning a QR code or typing a setup key, the secret is encrypted and saved in your device's Keychain, protected by iOS security. One-time codes are computed from that secret on your device; neither the secret nor the codes are ever transmitted to us. The camera feed used for QR scanning is processed in real time on the device and is not recorded or uploaded.
The same applies to the built-in password vault: passwords and notes you save are stored encrypted on your device (and in your own iCloud if you enable sync). We have no way to read them.
Service logos. To show a recognizable icon next to an account or saved login, the app may fetch that service's public logo from an icon service (Google's favicon service) using the service's public domain name (for example, github.com). This request never includes your secrets, codes, usernames, or any personal data.
Encrypted export. If you use the export feature, the app creates a file or QR codes encrypted with AES-256 using a key derived from the password you choose. The export is saved where you decide (for example, your photo library) and never sent to us. Anyone with the file and your password can restore the accounts, so store both carefully.
3. iCloud Backup & Sync
iCloud sync is an optional PRO feature. When enabled, your encrypted account data is stored in your personal iCloud account and synchronized by Apple across your devices signed in to the same Apple ID. That data lives under Apple's control; we do not host it, cannot read it, and never receive your Apple ID credentials. You can disable sync at any time in the app's settings or by turning off iCloud for Authenticator App in iOS Settings; iCloud storage is governed by Apple's terms and privacy policy.
4. How We Use Information
We use the limited information described above to: operate, maintain, and improve the app; diagnose and fix crashes and bugs; measure how features are used so we can make them better; process and verify your subscription and unlock PRO features; measure our own App Store ad campaigns; and respond to your support requests. We do not use this information to build a profile of you, we do not show third-party ads in the app, and we never access your 2FA secrets or passwords.
5. Permissions
Camera. Requested only when you scan a QR code to add an account. The feed is processed on-device and never recorded or uploaded.
Photos (add only). Requested only if you save exported backup QR codes to your photo library. The app asks for add-only access and does not read your existing photos.
Face ID / Touch ID. Used for the optional App Lock. Biometric verification is performed entirely by iOS — the app receives only a success or failure result and never your biometric data.
Notifications. The app may ask permission to send you local reminders (for example, a reminder to enable backup). These are scheduled on your device; you can decline or disable them any time in iOS Settings.
Network. Used for subscription processing, analytics, remote configuration, iCloud sync, and fetching service logos — never for transmitting your secrets.
6. Third-Party Services
We rely on a small number of trusted service providers, each governed by its own privacy policy:
- Apple (App Store / StoreKit for purchases, iCloud for optional sync, AdServices for install attribution) — apple.com/legal/privacy
- Google Firebase (Analytics, Crashlytics, Remote Config) — firebase.google.com/support/privacy
- Google Favicon Service (public service logos, as described in Section 2) — policies.google.com/privacy
Authenticator App contains no advertising SDKs and shows no third-party ads.
7. Data Sharing & Selling
We do not sell, rent, or trade your personal information, and we do not share it with advertising networks. The limited technical information described in this policy is shared only with the service providers listed above, and only to the extent needed to operate and improve the app — or where we are legally required to do so, such as to comply with a valid legal request or to protect our rights and the safety of our users.
8. Data Retention
We keep information only for as long as it is needed for the purposes described in this policy, or as required to comply with our legal obligations, resolve disputes, and enforce our agreements. Aggregated and diagnostic data may be retained for analysis. Your 2FA secrets and passwords stay on your device (and in your own iCloud, if you enable sync) until you remove them — deleting accounts in the app, or uninstalling it from all devices and removing its iCloud data, erases them. When information is no longer needed, we delete or anonymize it.
9. Security
Your secrets are protected with the strongest tools the platform offers: storage in the iOS Keychain, optional biometric App Lock, and exports encrypted with AES-256-GCM using keys derived from your password with PBKDF2 (600,000 rounds). We also apply reasonable safeguards to the limited technical data we handle. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security — please keep your device, passcode, and export passwords safe.
10. Children's Privacy
Authenticator App is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us at [email protected] and we will delete it.
11. Your Rights (GDPR / CCPA)
Depending on where you live, you may have rights over your personal information, including the right to access it, to correct it, and to request its deletion. Because your authentication data is stored only on your device and in your own iCloud, you exercise most of these rights directly: delete accounts in the app, or uninstall the app and remove its iCloud data. We do not sell or share your personal information for cross-context behavioral advertising, so no "Do Not Sell or Share" opt-out is needed. To exercise any right over the limited technical data we do handle, email us at [email protected] and we will respond in accordance with applicable law. We will not discriminate against you for exercising these rights.
12. International Transfers
We and our service providers may process and store information in countries other than the one in which you live. Where we transfer data internationally, we take steps to ensure appropriate safeguards are in place to protect it, consistent with applicable data protection laws.
13. Changes to This Policy
We may update this Privacy Policy from time to time as the app evolves or as the law requires. When we do, we will revise the "Last Updated" date at the top of this page. Significant changes may be highlighted in the app. Your continued use of Authenticator App after an update means you accept the revised policy.
14. Contact Us
If you have questions about this Privacy Policy or how we handle your information, please reach out:
TechSmart LLC
Email: [email protected]
You may also want to read our Terms of Use.