Privacy Policy — 2FA AUTH
Last updated: September 4, 2026
2FA AUTH (published under the in-app name "SecureVault," package `com.elinetec.securevault`) is developed and operated by **Eline Technologies Pvt Ltd** ("Eline Technologies," "we," "us," or "our"). This Privacy Policy explains what information 2FA AUTH collects, how we use it, and the choices you have. It applies to the 2FA AUTH app on Android, iOS, and macOS, and to the backend services that support it.
If you have questions about this policy, contact us at contact@elinetec.com.
---
1. The short version
2FA AUTH is built on a zero-knowledge design: your two-factor codes and the passwords you save in the app are encrypted on your own device with a key derived from your master password. **We never see your master password, and we cannot read, recover, or reset the contents of your vault.** Separately from your vault content, the app also collects limited account, device, diagnostic, and (for free-tier users) advertising information as described below, so that we can operate the service, keep it reliable, and support it commercially.
2. Information we collect
2.1 Account information
When you sign in with Google or Sign in with Apple, we receive your name and email address from that provider in order to create and identify your account. We do not use Firebase Authentication — sign-in tokens are verified directly against Google's and Apple's own public keys.
2.2 Your vault and 2FA content (encrypted, zero-knowledge)
Two-factor authenticator entries, saved passwords, notes, and related vault items are encrypted on your device with AES-256-GCM before anything ever leaves it. The encryption key is derived from your master password using Argon2id. Your master password itself is never transmitted or stored, in any form, on our servers. When you enable encrypted backup, the same already-encrypted data is uploaded so it can be restored later — we store ciphertext only and cannot decrypt it.
2.3 Device and usage information
We collect device identifiers, device model and OS version, app version, and coarse usage events (for example, which screens you open and which features you use) through Firebase Analytics, so we can understand how the app is used and improve it.
2.4 Diagnostic information
We use Firebase Crashlytics to collect crash reports and non-fatal error logs, which may include device state and stack traces, so we can find and fix bugs.
2.5 Push notification token
If you allow notifications, we use Firebase Cloud Messaging to deliver them, which requires a device push token.
2.6 Advertising information (free-tier users only)
If you are on the free plan, the app may show ads served through Google AdMob on non-sensitive screens only (see Section 4). AdMob may collect your advertising identifier (IDFA on iOS/macOS, or the Android Advertising ID) and other information to serve and measure ads. On iOS, we request your permission through Apple's App Tracking Transparency framework before any tracking-based advertising identifier is used; if you decline, you still see ads, but they are not personalized to you. Pro subscribers never see ads and this data is not collected for them.
2.7 Purchase information
If you subscribe to 2FA AUTH Pro, your purchase is processed entirely by the Apple App Store or Google Play. We never receive or store your payment card details. We do receive a purchase/subscription token from Apple or Google, which we use solely to verify your entitlement and keep your Pro status in sync across your devices.
2.8 Support communications
If you email us at contact@elinetec.com, we keep that correspondence to respond to you and to improve the app.
3. How we use information
We use the information above to: operate, maintain, and secure the app and backend; authenticate you and sync your encrypted backups and devices; diagnose and fix crashes and bugs; understand feature usage so we can prioritize improvements; send you service-related push notifications; serve and measure advertising to free-tier users; verify and manage Pro subscription entitlements; and respond to support requests. We do not sell your personal information, and we do not use the contents of your vault for any purpose, because we are cryptographically unable to read it.
4. Advertising and AdMob placement
We take the sensitivity of this app seriously. Ads never appear on your authenticator code list, your password vault list or item detail screens, the unlock/master-password screen, or any screen involved in adding, scanning, importing, backing up, or restoring your data. Ads may appear, at most, on the Tools hub, the 2FA setup guides section, below the fold on generator result screens, and the About/Help screens — none of which display your secrets. Upgrading to Pro removes all ads. Ads never appear at all in the macOS app, which does not include an advertising SDK.
5. Data sharing
We share limited information with the following categories of service providers, solely to operate the app:
- Google (Firebase Analytics, Crashlytics, Cloud Messaging, and Google Sign-In verification) — analytics, crash reporting, push delivery, and sign-in.
- Google AdMob — advertising to free-tier users only, as described above.
- Apple and Google (App Store / Google Play) — processing subscription purchases and providing us a purchase token for entitlement verification.
- Our hosting provider — for running the backend API that stores your account record and encrypted backup ciphertext.
We do not sell your personal information to third parties, and we do not share the decrypted contents of your vault with anyone, because we do not have the ability to decrypt it.
6. Data retention and deletion
We retain your account information and encrypted backups for as long as your account is active. You can delete individual vault items, delete a specific backup, or permanently delete your account and all associated data at any time from Settings within the app. Deleting your account removes your account record, your device records, and your encrypted backups from our servers. Local data on your device is removed when you uninstall the app.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. You can exercise most of these rights directly in the app (Settings → Account, Settings → Privacy, and the account deletion flow), or by contacting us at contact@elinetec.com. If you are in the European Economic Area or the UK, you also have the right to lodge a complaint with your local data protection authority. If you are a California resident, you have rights under the CCPA/CPRA, including the right to know, delete, and opt out of the sale or sharing of personal information — we do not sell or share personal information as those terms are defined by California law.
8. Advertising consent (EEA/UK)
If you are located in the European Economic Area or the United Kingdom, we use Google's User Messaging Platform (UMP) to obtain your consent before showing personalized ads or using advertising identifiers, in line with GDPR and applicable ePrivacy rules. You can withdraw or change your consent at any time from Settings → Privacy → Ad preferences.
9. Children's privacy
2FA AUTH is not directed at children, and we do not knowingly collect personal information from children under the age of 13 (or the relevant minimum age in your country). If you believe a child has provided us with personal information, please contact us so we can delete it.
10. International data transfers
We and our service providers (including Google/Firebase and our hosting provider) may process information in countries other than your own. Where required, we rely on appropriate safeguards, such as standard contractual clauses, for these transfers.
11. Security
Vault content and backups are protected with AES-256-GCM authenticated encryption and Argon2id key derivation, entirely on your device. Data in transit to our backend is protected with TLS. No system is perfectly secure, but because your master password and vault contents never reach our servers in usable form, a compromise of our servers alone cannot expose your vault contents.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app. Continued use of 2FA AUTH after a change becomes effective means you accept the updated policy.
13. Contact us
Eline Technologies Pvt Ltd
Email: contact@elinetec.com
App: 2FA AUTH (com.elinetec.securevault)