Authenticator privacy policy

Effective 11 September 2026 · Bakir Apps

Authenticator generates two-factor authentication codes. This policy explains what data the app handles, where it is stored, and which third-party services it uses. It applies to the Authenticator app for iOS published by Bakir Apps ("we", "us").

The short version

Data stored on your device

When you add an account, the app stores its name, issuer, and secret key in the iOS Keychain, Apple's encrypted storage. This data is protected by your device passcode and, where enabled, Face ID or Touch ID. It is not transmitted to us.

iCloud sync (optional)

If you enable iCloud sync, your accounts are stored in your personal iCloud account using Apple's iCloud Keychain and CloudKit services, so they appear on your other devices signed in to the same Apple ID. This data is encrypted in transit and at rest by Apple. We have no access to your iCloud account. Apple's handling of this data is governed by Apple's privacy policy. You can turn sync off at any time in the app's settings.

Third-party services

The app uses the services below. Each receives only the data listed, and none receives your account secrets or codes.

ServicePurposeData it receives
Firebase Analytics (Google)Understand which features are used so we can improve the appApp usage events, app version, device model, OS version, language, country, and a random app-instance identifier
Firebase Crashlytics (Google)Detect and fix crashesCrash logs, device model, OS version, app version, and a random installation identifier
RevenueCatManage in-app purchases and subscriptionsPurchase receipt data from Apple, a random app user identifier, app version, and device platform
Apple (App Store, iCloud)Distribution, payments, and optional syncHandled under your Apple ID according to Apple's privacy policy

Privacy policies for these providers: Google, RevenueCat, Apple.

Purchases

Payments are processed by Apple through the App Store. We do not receive your name, payment card, or billing address. RevenueCat receives the purchase receipt so the app can unlock what you bought and restore it on your other devices.

Data we do not collect

Retention

Data on your device stays until you delete an account in the app or uninstall the app. Analytics and crash data are retained by Google according to their retention settings, which we configure to the shortest available period. RevenueCat retains purchase records for as long as needed to manage your subscription.

Your choices and rights

Children

The app is not directed at children under 13, and we do not knowingly collect personal data from them.

Security

Secrets are stored only in the iOS Keychain or, if you choose, your encrypted iCloud account. Please protect your device with a passcode and keep iOS up to date. If you lose access to your device without iCloud sync enabled, we cannot recover your accounts.

Changes to this policy

If we change this policy, we will update the effective date at the top of this page and, for significant changes, notify you in the app.

Contact

Bakir Apps
support@bakirapps.com