Privacy and data notice
For the Authenticator iOS app
Updated: Sep 14, 2026
At a glanceThis policy explains how Authenticator handles information related to its features. We are designed to keep authenticator and password data on your device. When you choose iCloud sync, system sharing, or App Store features, the selected action is handled by the relevant Apple system service.
In this policy
- 1. Scope
- 2. Information we handle
- 3. Camera and one-time passwords
- 4. Password-manager data
- 5. Use and external actions
- 6. Local storage and security
- 7. iCloud backup and sync
- 8. Subscriptions and App Store
- 9. Your choices and rights
- 10. Updates and contact
1. Scope
This policy applies to the Authenticator iOS app and its one-time password, password-manager, password-generator, sync, and membership features. Third-party websites, apps, and their privacy rules are outside this policy.
2. Information We Handle
Depending on the features you use, the app may store a service name, account identifier, TOTP secret, code settings, password-manager entries, favorites, app preferences, and purchased entitlement status on your device. You can choose not to add an account or use the password manager.
We do not ask you to provide: bank-account passwords, your Apple ID password, or complete login credentials for a third-party service. Enter information only on a device you trust.
3. Camera and One-Time Passwords
When you scan a QR code, camera input is used on the device to read its configuration. The camera view does not need to be uploaded to a server. One-time passwords are calculated on the device using a standard time-based one-time password algorithm, so codes can be generated without a network connection.
If you deny camera access, you can still add an account by entering its secret manually. You can change camera permission at any time in iOS Settings.
4. Password-Manager Data
Account names, usernames, passwords, notes, and categories that you save are used to display, search, edit, and copy entries in the app. Password content is not automatically sent to us when you open a page or browse a category.
Do not save more sensitive information than you need, and keep separate recovery codes or backup sign-in methods for important accounts.
5. Use and External Actions
We handle this information to provide code calculation, account display, password management, preference storage, entitlement checks, and troubleshooting. The app does not sell personal data or use authenticator secrets for advertising.
When you choose to copy the support email, share the app link, open the App Store, or send feedback, iOS or the relevant external service handles that action. External services follow their own rules.
6. Local Storage and Security
The app uses local storage and security capabilities provided by iOS to keep app data, and Face ID or Touch ID can provide additional access protection. No device security measure is absolute. Use a device passcode, keep iOS updated, and avoid using the app on jailbroken or untrusted devices.
If you uninstall the app, clear its data, or lose your device, data that was not backed up may not be recoverable. Confirm that you have what you need before deleting anything.
7. iCloud Backup and Sync
Only when you enable sync does the app use your iCloud account to synchronize supported data. Sync depends on Apple account, network, and system-service availability, and may take time to appear on another device.
Apple manages iCloud accounts. We cannot see your Apple ID password and cannot control Apple availability, storage policies, or retention rules.
8. Subscriptions and App Store
Weekly, monthly, annual, and lifetime memberships are purchased through Apple StoreKit. The app reads verified Apple transactions or entitlement status only to enable the relevant features. We do not access card information or sensitive payment credentials.
Billing, refunds, cancellation of auto-renewal, and restore purchases are handled by Apple through Apple ID subscription management.
9. Your Choices and Rights
You can disable camera access, turn off iCloud sync, delete authenticator accounts and password entries in the app, or stop using the app. To make a privacy request, contact us using the email below and include the request, device, and app version when possible.
To protect account security, we may need to verify that a request comes from the relevant person. We handle requests as required by applicable law and when needed to protect users, the app, or public safety.
10. Updates and Contact
We may update this policy for feature, legal, or security changes. The updated version will ship with the app and the date at the top of this page will be updated. Continued use means that you have read the updated policy.
For privacy questions, to report a privacy concern, or to exercise a relevant right, email guanyunchang2022@gmail.com.