Authenticator privacy policy
Authenticator generates two-factor authentication codes, stores passwords, and includes a built-in web browser. This policy explains what data the app handles, where each kind is stored, and how it is protected. It applies to the Authenticator app for iOS published by Bakir Store LLC ("we", "us"), which publishes its apps under the Bakir Apps brand.
The short version
- Your codes, secrets, saved passwords, account names, and notes stay on your device. They are never sent to us or to any service the app uses. The app has no accounts and no login.
- Secrets and passwords are stored in the iOS Keychain as "this device only", so they are never stored in iCloud. The only thing that can sync through iCloud Keychain is the password of an encrypted backup, and only if you turn that on.
- Account details are kept on your device, in a local database and mirrored in the Keychain. Deleting the app therefore does not lose them: reinstalling offers to put them back, and you choose what is restored.
- Subscriptions are handled by Apple and RevenueCat. Anonymous analytics and crash reports go to Google Firebase. Neither receives anything you have typed into the app.
- If you allow tracking when your iPhone asks, the advertising identifier is used to measure the app's ads. Declining changes nothing about how the app works.
- The built-in browser works like any browser: the sites you open, and Google when you search, receive your requests. The app keeps no record of your browsing or searches, and they are never part of analytics.
- You can create an encrypted backup file. You choose its password and where it goes; we never receive it.
- We do not sell your data.
What the app stores, and where
Everything the app saves lives in one of two places on your device, and most of it lives in both. Secrets are only ever in the iOS Keychain. The details around them are kept in the Keychain too, in a separate item beside the secret they describe, and in a local database the app works from. Nothing in either is sent to us.
| Data | Where it is stored | How it is protected |
|---|---|---|
| Two-factor secret keys | iOS Keychain | Readable only while the device is unlocked, and marked device-only, so it never syncs to iCloud and is not carried over to a new device |
| Saved passwords | iOS Keychain | Same as above |
| Your app PIN | iOS Keychain, as a salted hash — never the digits themselves | Same as above |
| Account and entry details: issuer, account name, service name, web address, username, notes, icon, order, dates, and code settings | Kept in both: the iOS Keychain, beside the secret it describes, and a local database file the app works from | The Keychain copy carries the same protection as the secret — readable only while the device is unlocked, device-only, never synced. The database copy is encrypted at rest by iOS under its default file protection, which makes it readable once you have unlocked the device for the first time after a restart |
| Backup password, only if you choose to save it | iOS Keychain, marked to sync | Synced to your other Apple devices through your iCloud Keychain. This is the single exception to the device-only rule, and it is off unless you turn it on |
| Browser tabs, history, cookies, and cache | Memory only | Discarded when you close the app; never written to disk |
| Appearance and biometric preferences | Standard app preferences | Not sensitive, and contains no account data |
Why two copies: the database is the working one, which the app reads and you edit; the Keychain copy is the durable one, because iOS keeps Keychain items when an app is deleted and discards everything else. The app brings the two into step each time it launches, writing only what differs and never touching a secret. Where a detail is held in both, the database copy carries the weaker of the two protections, so that is the one to judge it by.
Two-factor accounts
When you add an account, its secret key goes straight to the Keychain, and the issuer, account name, and code settings are written twice — into the Keychain as a separate item beside the secret, and into the local database. Codes are generated on your device from the secret and the current time. Generating a code needs no network connection, and the app never transmits a code or a secret.
Revealing or copying a secret key requires Face ID, Touch ID, or your device passcode, falling back to your app PIN when the device has no passcode set. Generated codes are not gated this way, because you use them many times a day and they expire on their own.
Saved passwords
The password vault stores a password, username, service name, web address, and notes for each entry. The password itself goes in the Keychain, on its own. The username, service name, web address, and notes are kept in both places, like account details above: in the Keychain beside the password, and in the local database. Because a copy sits in the database under the weaker file protection, treat your notes accordingly and avoid putting a second copy of the password there.
Revealing or copying a saved password requires Face ID, Touch ID, or your device passcode, with your app PIN as the fallback.
The built-in browser
The app includes a browser tab for opening websites without leaving the app — useful when you are signing in to a service and need a code at the same time. It is a standard iOS web view.
Codes are generated on your device, and your accounts and passwords are stored and read there. None of that goes over the network. The browser is where requests go out to the web, exactly as they would from any other browser.
- The browser uses a non-persistent data store. Cookies, caches, local storage, and the back-forward list exist only in memory and are discarded when the app is closed. No browsing history is written to disk or kept.
- Sites you visit receive requests from your device, and can see your IP address, the pages you request, and anything you submit to them, exactly as they would in Safari or any other browser. Their own privacy policies govern what they do with that.
- If what you type in the address bar is not a web address, it is sent to Google as a search query. That request goes to Google Search, not to us, and is handled under Google's privacy policy.
- The browser is walled off from the rest of the app. It cannot read your accounts, passwords, or secrets, the app fills nothing into web pages for you, and it runs no scripts of our own inside the pages you open.
- We do not log, collect, or transmit the addresses you visit or the searches you run, and they are never included in analytics or crash reports.
Encrypted backups
Because your accounts live only on your device, the app can export an encrypted backup file so you are not one lost phone away from losing them. Backups are created only when you ask for one, and exporting requires Face ID, Touch ID, or your device passcode.
- The file is encrypted with a password you choose, using AES-GCM with a key derived through PBKDF2-HMAC-SHA256 at 1,200,000 iterations and a random salt. The strength of the file rests on the password you pick, so choose a strong one — we cannot recover or reset it.
- It contains your two-factor accounts and saved passwords, including their secrets. It deliberately does not contain your app PIN.
- When the backup is ready, iOS hands you the standard share sheet and you decide where it goes — iCloud Drive, another app, another device, or nowhere. That choice is yours, and the destination you pick handles the file under its own terms. The app's temporary copy is deleted once you are done.
- We never receive the file, the password, or any part of either. There is nowhere for them to be sent.
- You may optionally save the backup password to your iCloud Keychain so it survives the loss of the device. This is off by default. When on, the password syncs to your other Apple devices through your own iCloud account, encrypted by Apple; we have no access to it. Your secrets and passwords themselves are never synced this way.
- Restoring asks for the file and its password and puts the entries back on the device, with nothing leaving it.
Importing from Google Authenticator
The app can read the QR codes Google Authenticator produces from its "Transfer accounts" export. The code is decoded on your device, and the accounts it contains are added to your Keychain and local database the same way a manually added account would be. Nothing about the import is sent anywhere, and we are not involved in it.
The clipboard
Copying is handled differently depending on what you copy.
- Secret keys and saved passwords are marked local-only, so they stay on the device and are not offered to your other Apple devices through Universal Clipboard. They expire from the clipboard after two minutes, and the app clears them sooner if it locks while they are still there.
- Generated codes and usernames are not marked local-only, so — like anything else you copy — they may reach your other Apple devices through Universal Clipboard if you have it enabled. This is deliberate, so you can paste a code on your Mac. Codes expire within seconds on their own.
Camera
The app itself uses the camera for one thing: reading QR codes when you add an account. iOS asks your permission the first time. The scanner reads only the code's text, on your device. No photo or video is captured, stored, or transmitted.
Third-party services
The app uses two outside services: Google Firebase, for anonymous analytics and crash reports, and RevenueCat, for subscriptions. Payments are handled by Apple through the App Store. None of them receives your codes, secrets, passwords, account names, usernames, web addresses, notes, or anything you type in the browser.
Subscriptions
Subscriptions are sold and billed by Apple through the App Store; we never see your name, payment card, or billing address. RevenueCat records that this installation has an active subscription. That record contains the purchase receipt from Apple and an anonymous identifier generated for the installation — nothing you have typed into the app. Because the app has no accounts and no login, there is nothing else for a purchase to be linked to. See RevenueCat's privacy policy.
Analytics and crash reports
The app uses Google Firebase for anonymous product analytics and crash reports. Analytics events record which onboarding and subscription screens were reached, which plan was chosen, the answer given to the tracking question, and a few simple actions — such as setting up a PIN or Face ID, or how an account was added (scanned, typed, or imported), never which account. Crash and performance reports are sent so faults can be found and fixed. Reports carry basic technical details such as the app version, device model, and iOS version, and an identifier Firebase generates for the installation. Firebase does not use your iPhone's Location Services: it works out an approximate region, such as the country or city, from your IP address, and never your precise location.
No code, secret, account name, username, web address, note, or search term is ever included. The app is built so that none of these can be attached to an event. So that subscriptions can be counted alongside these reports, RevenueCat is given Firebase's identifier for the installation and reports subscription events to Firebase against it. See Google's privacy policy.
Advertising
The first time you open the app, your iPhone may ask whether to allow it to track you. If you allow it, the advertising identifier is used to measure the effectiveness of the app's ads. If you decline, it is not used, and nothing about how the app works changes. You can change your answer at any time in the iPhone's Settings app, under Privacy & Security → Tracking. The anonymous analytics and crash reports described above are sent whichever you choose.
If a future version adds another service, or sends anything else off your device, we will update this policy and change the effective date at the top of this page before that version ships.
Data we do not collect
Apart from the anonymous analytics, crash, and subscription records described above, nothing leaves the app. In particular, neither we nor the services the app uses ever receive:
- Your secret keys, saved passwords, or generated codes
- Your account names, usernames, web addresses, or notes
- Your backup files or backup password
- Your name, email address, phone number, or contacts
- Your precise location
- Photos, camera images, or files
- A record of the websites you visit or the searches you run in the browser
Retention
Your data stays on your device until you remove it. What each kind of removal does differs, and the difference matters:
- Deleting an entry in the app removes its secret, its Keychain record, and its database row together. This is complete.
- Uninstalling the app removes the local database but not the Keychain items. iOS deliberately preserves an app's Keychain entries after the app is deleted, so your secrets, your saved passwords, the details that go with them, and your app PIN all remain on the device. This is why reinstalling can put your accounts back, and also why uninstalling is not a way to erase them.
- Erasing everything in the app — on the lock screen, "Forgot password?" then "Erase Everything & Reset PIN" — removes every account and password, their secrets, their Keychain records, and anything an earlier install left behind, then resets your PIN. It asks you to confirm with Face ID, Touch ID, or your device passcode. This is the way to leave nothing behind.
If you delete and reinstall the app
Reinstalling finds what is still on the device. Once you unlock the app, it lists the accounts and passwords the Keychain still holds and asks whether to put them back. You choose which to restore, or dismiss the offer and restore nothing. The same list stays available afterwards under Settings → Backup → "Restore from this device". Nothing is restored unless you ask for it, and nothing leaves the device at any point in this.
Entries saved by a version of the app older than this feature come back without their labels, because only their secrets were kept at the time. They still generate the right codes, and you can name them again in the app.
Any backup file you exported stays wherever you put it until you delete it yourself. The anonymous analytics, crash, and subscription records described above are kept by Google and RevenueCat as set out in their privacy policies.
Your choices and rights
- Delete any account or password entry at any time. To remove everything — including anything an earlier install left on the device — use "Forgot password?" then "Erase Everything & Reset PIN" on the lock screen. Uninstalling alone does not do this, because iOS keeps the Keychain items.
- Choose what a reinstall puts back, or decline and restore nothing. Restoring only ever happens because you asked for it.
- Allow or decline tracking when your iPhone asks, and change your answer at any time in the Settings app, under Privacy & Security → Tracking. Declining changes nothing about how the app works.
- Manage or cancel a subscription in the Settings app, under your name → Subscriptions.
- Export an encrypted backup, or don't — the feature is entirely optional.
- Turn off saving the backup password to your iCloud Keychain, which also removes it from your other devices.
- Use or ignore the browser tab.
- Withdraw camera permission at any time in the Settings app, and add accounts by typing the key instead.
- Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, or delete personal data we hold. We hold no name, email address, or account for you; the only records outside your device are the anonymous analytics, crash, and subscription records described above. For anything about those, contact us.
Children
The app is not directed at children under 13, and we do not knowingly collect personal data from them.
Security
Secrets and passwords are held in the iOS Keychain, readable only while your device is unlocked, and marked so they never leave it. The app can be locked with Face ID, Touch ID, or a PIN, and repeated wrong PIN entries are slowed down with increasing delays. Revealing or copying a secret requires authentication. The app also covers its contents in the iOS app switcher so a revealed password does not end up in a screenshot of your recent apps.
Please protect your device with a passcode and keep iOS up to date. Deleting the app is recoverable, because the Keychain keeps your accounts and the app offers them back when you reinstall. Losing or erasing the device is not: your accounts exist only there, and we cannot recover them for you. Make an encrypted backup, and keep the backup codes each service gives you when you set up two-factor authentication.
Changes to this policy
If we change this policy, we will update the effective date at the top of this page and, for significant changes, notify you in the app.
Contact
Bakir Store LLC
[email protected]