Privacy Policy — Authenticator: 2FA & Vault for iOS
Last updated: September 17, 2026.
Authenticator: 2FA & Vault for iOS helps you store credentials, generate authentication codes, and manage optional backups. This policy explains which information stays on your device and which information is sent to service providers.
Vault storage and device access
Passwords, 2FA secret keys, recovery codes, notes, and other vault fields are stored in an AES-256-GCM encrypted file on your device. The random encryption key is stored in the iOS Keychain, is restricted to this device, and is shared with the app's AutoFill and Widget extensions through a Keychain access group. These extensions can read the shared vault after the device has been unlocked following a restart. The app's optional PIN is an additional app access control; it is not the encryption key for the vault or a separate authentication requirement for the extensions.
When updating from an older version, the app validates existing local vault files, writes an encrypted copy, reads it back to verify it, and only then removes the legacy plaintext files. A missing key or unreadable vault causes an error and blocks further writes until the vault can be opened again.
Because the encryption key is device-specific, the encrypted vault is excluded from ordinary device backups. Moving to another device requires an explicit iCloud backup or an exported copy. If the key is lost and no usable backup exists, we cannot recover the vault.
AutoFill provides the credential you select to the requesting website or app. Widgets can show account names and current codes on the Home Screen; remove the widget if you do not want those details displayed there.
Optional iCloud sync and exports
When you turn on iCloud sync or select Sync Now, the app sends the vault contents, deletion markers, an app installation identifier, a device model label, item count, and update time to your private CloudKit database associated with your Apple account. Restoration reads that data and merges it into the local encrypted vault. Sync is initiated by your actions; this version does not provide continuous background sync.
Depending on the entries you choose to save, a cloud snapshot can include names, email addresses, card or bank account details, identity-document fields, credentials, and notes. These user-provided fields are used for vault backup and restoration, not supplied to Firebase or Google Mobile Ads.
CloudKit protects data during transport and storage. This app does not apply an additional end-to-end encryption layer to its CloudKit snapshots. The device-specific local vault key is not uploaded. Do not interpret local vault encryption as a promise that cloud snapshots are inaccessible to Apple under all circumstances.
Turning sync off stops future sync actions but does not delete an existing cloud backup. Permanent deletions are propagated when you next successfully sync. Items in Trash remain stored until permanently deleted. Other devices must sync to receive deletion changes. You may also manage the app's iCloud storage through Apple's available account and storage controls.
JSON exports contain readable passwords, 2FA secrets, and other exported vault fields. The app warns you before opening the share sheet. The destination you choose controls the exported copy. Deleting data in this app does not remove copies you have exported or shared.
Password breach checks
When you request a password check, or enable scanning when Security Hub opens, the app hashes each checked login password on your device and sends only the first five hexadecimal characters of its SHA-1 hash to the Pwned Passwords service over HTTPS. The service also receives ordinary network information, including your IP address. The full password, full hash, account email, and vault title are not sent for this check. Responses are requested with padding and an ephemeral network session.
A match means that password appears in the provider's database; it does not establish that your particular account was compromised. No match is not a guarantee of safety. Network errors and invalid responses are reported as unavailable or incomplete checks. Scan results are kept in memory for the current app session.
Provider information: https://haveibeenpwned.com/Privacy and https://haveibeenpwned.com/API/v3#PwnedPasswords.
Optional email breach checks
Email checks use the free LeakCheck Public API and run only when you tap Check Email. The app trims whitespace around the entered address, converts it to lowercase, calculates its SHA-256 hash on your device, and sends the first 24 hexadecimal characters to https://leakcheck.io/api/public over HTTPS. It does not send the original email, full hash, vault contents, or app analytics identifiers in this request. No API key or account is required. Email addresses saved in the vault are not automatically submitted for checking.
A hash is a pseudonymous identifier, not a guarantee of anonymity. LeakCheck can match it against email hashes in its database; someone who guesses an email can also calculate its hash. The provider receives your IP address and ordinary technical request information. LeakCheck's policy states that it does not store search queries or build search history, but it does process technical logs. See the provider's policy for its handling and retention practices.
The API returns a count of matching records and names/dates of breach sources. That count is not a count of distinct breaches, and the response does not contain exposed passwords or other leaked values. A match does not prove an account takeover; no match does not prove safety. Errors, rate limits and malformed responses never count as a clean result. Requests use an ephemeral session, results stay in the current sheet's memory, and closing the sheet cancels pending work and clears the entered email and results from its UI state. The app does not save these results to the vault or analytics.
Powered by LeakCheck: https://leakcheck.io. Public API documentation and terms: https://docs.leakcheck.io/public-api/lookup. Provider privacy policy: https://leakcheck.io/privacy.
Usage analytics
The iOS app uses Google Firebase Analytics to understand app use and purchase flows. Events include app opens, paywall views, product loading, purchase attempts, purchase results, and restore results. Event parameters can include product identifiers, offer/price/currency details, and error descriptions. Firebase also processes app-instance identifiers, device and operating-system information, app version, event timestamps, and approximate geographic information derived from network data under its service configuration.
These identifiers are pseudonymous, not a guarantee of anonymous data. Vault passwords, secrets, notes, card details, and account labels are not included in the app's analytics events. Firebase Analytics uses the variant without advertising-ID support, disables IDFV collection, and denies advertising storage, advertising user data, and ad personalization consent. Analytics for app use remains enabled. The iOS app does not include Crashlytics or Firebase Remote Config in its target dependencies.
Google privacy information: https://policies.google.com/privacy and https://firebase.google.com/support/privacy.
Advertising SDK and tracking permission
The app includes Google Mobile Ads (AdMob). On the first active launch where iOS has no tracking decision for this app, it requests permission through Apple's App Tracking Transparency prompt before onboarding or the initial subscription screen. The app uses the decision stored by iOS and does not repeatedly ask after a decision has been made. iOS may suppress the prompt due to device, account, or system privacy restrictions.
Google Mobile Ads is initialized only while the app is active and iOS reports that tracking is authorized. If permission is denied, restricted, or not yet determined, the app does not start the advertising SDK. Declining tracking does not prevent use of the app's regular features; existing subscription and app-lock requirements still apply. You can change the permission in iOS Settings under Privacy & Security > Tracking.
When initialized with permission, Google Mobile Ads may process device identifiers including the advertising identifier, IP-derived approximate location, diagnostic and performance information, and advertising or interaction data for advertising and measurement, as described by Google. Vault contents are not supplied to the advertising SDK. This integration initializes the SDK; it does not add banner, interstitial, or other ad placements. Firebase's advertising consent remains denied independently of the ATT choice.
Google Mobile Ads data disclosure: https://developers.google.com/admob/ios/privacy/data-disclosure. Google privacy policy: https://policies.google.com/privacy.
Purchases and subscriptions
Apple StoreKit processes purchases and subscriptions. RevenueCat receives a randomly generated app user identifier, signed transaction data or App Store receipts, product identifiers, purchase or restore status, and available price and currency information to validate and manage entitlements. The app can contact RevenueCat on startup, purchase, and restore. RevenueCat and Apple also process technical request information as described in their policies.
We do not receive your payment card or bank details from Apple for subscription billing. This statement concerns purchase processing; any card or bank details you manually save as vault entries are part of your vault and any optional cloud backup or export.
Provider information: https://www.revenuecat.com/privacy and https://www.apple.com/legal/privacy/.
Camera, photos, biometrics, clipboard, and browsing
Camera access is used for scanning QR codes. Selected photos can be processed to extract QR information. The app does not upload those images as part of scanning. Face ID and Touch ID authentication is handled by iOS; the app receives an authentication result and does not receive biometric templates.
When you copy text, the app asks iOS to keep it on this device and expire the clipboard entry after 60 seconds. Other apps may read the value if you paste it before expiry; any copy they retain is outside this app's control.
The in-app browser uses a nonpersistent WebKit website data store. Websites you visit still receive normal web requests, including your IP address and information you submit to them. Bookmarks you choose to save persist in the app's preferences. Private browsing does not make you anonymous to websites or network providers.
Retention, deletion, and choices
Local vault items remain until you delete them, with deleted items retained in Trash until permanent deletion. The app retains local preferences such as language, app lock settings, bookmarks, and purchase-status cache. Uninstalling does not by itself delete iCloud snapshots, exports, service-provider records, or necessarily all Keychain entries.
Analytics and purchase records are retained according to the configured provider retention settings and applicable requirements. You may contact us to request information, access, correction, or deletion where applicable. We may need information to locate pseudonymous provider records. Purchase records may need to be retained to provide subscriptions or meet legal requirements. You can control iCloud use and automatic password checks in the app and camera/photo/biometric permissions through iOS settings.
Children, changes, and contact
This app is not directed to children under 13. If you believe a child has provided personal information, contact us so that we can review the request.
We may update this policy as the app changes and will publish the effective date with the revised policy.
Contact: dangthixuanhuongdn@gmail.com