Authenticator privacy policy
Authenticator generates two-factor authentication codes. This policy explains what data the app handles, where it is stored, and which third-party services it uses. It applies to the Authenticator app for iOS published by Bakir Apps ("we", "us").
The short version
- Your account secrets never leave your device unless you turn on iCloud sync, in which case they are stored in your own iCloud account, encrypted by Apple.
- We cannot see your secrets or your one-time codes. We do not have servers that store them.
- No account or sign-up is required to use the app.
- We use a small number of third-party services for analytics, crash reporting, and purchases. They receive technical data, not your secrets.
- We do not sell your data.
Data stored on your device
When you add an account, the app stores its name, issuer, and secret key in the iOS Keychain, Apple's encrypted storage. This data is protected by your device passcode and, where enabled, Face ID or Touch ID. It is not transmitted to us.
iCloud sync (optional)
If you enable iCloud sync, your accounts are stored in your personal iCloud account using Apple's iCloud Keychain and CloudKit services, so they appear on your other devices signed in to the same Apple ID. This data is encrypted in transit and at rest by Apple. We have no access to your iCloud account. Apple's handling of this data is governed by Apple's privacy policy. You can turn sync off at any time in the app's settings.
Third-party services
The app uses the services below. Each receives only the data listed, and none receives your account secrets or codes.
| Service | Purpose | Data it receives |
|---|---|---|
| Firebase Analytics (Google) | Understand which features are used so we can improve the app | App usage events, app version, device model, OS version, language, country, and a random app-instance identifier |
| Firebase Crashlytics (Google) | Detect and fix crashes | Crash logs, device model, OS version, app version, and a random installation identifier |
| RevenueCat | Manage in-app purchases and subscriptions | Purchase receipt data from Apple, a random app user identifier, app version, and device platform |
| Apple (App Store, iCloud) | Distribution, payments, and optional sync | Handled under your Apple ID according to Apple's privacy policy |
Privacy policies for these providers: Google, RevenueCat, Apple.
Purchases
Payments are processed by Apple through the App Store. We do not receive your name, payment card, or billing address. RevenueCat receives the purchase receipt so the app can unlock what you bought and restore it on your other devices.
Data we do not collect
- Your account secrets or generated codes
- Your name, email address, phone number, or contacts
- Your precise location
- Photos, camera images (the camera is used only to read QR codes on-device), or files
Retention
Data on your device stays until you delete an account in the app or uninstall the app. Analytics and crash data are retained by Google according to their retention settings, which we configure to the shortest available period. RevenueCat retains purchase records for as long as needed to manage your subscription.
Your choices and rights
- Delete any account from the app at any time, or delete the app to remove all local data.
- Turn iCloud sync off in the app's settings.
- Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, or delete personal data we hold. Because we do not hold data that identifies you, most requests can be fulfilled by the steps above; for anything else, contact us.
Children
The app is not directed at children under 13, and we do not knowingly collect personal data from them.
Security
Secrets are stored only in the iOS Keychain or, if you choose, your encrypted iCloud account. Please protect your device with a passcode and keep iOS up to date. If you lose access to your device without iCloud sync enabled, we cannot recover your accounts.
Changes to this policy
If we change this policy, we will update the effective date at the top of this page and, for significant changes, notify you in the app.
Contact
Bakir Apps
support@bakirapps.com