Authenticator privacy policy

Effective 11 September 2026 · Bakir Apps

Authenticator generates two-factor authentication codes, stores passwords, and includes a built-in web browser. This policy explains what data the app handles, where each kind is stored, and how it is protected. It applies to the Authenticator app for iOS published by Bakir Apps ("we", "us"), which distributes its apps through this site, Bakir Store.

The short version

What the app stores, and where

The app keeps two separate stores on your device. Secrets go in the iOS Keychain; the labels and settings around them go in a local database. Nothing in either store is sent to us.

DataWhere it is storedHow it is protected
Two-factor secret keysiOS KeychainReadable only while the device is unlocked, and marked device-only, so it never syncs to iCloud and is not carried over to a new device
Saved passwordsiOS KeychainSame as above
Your app PINiOS Keychain, as a salted hash — never the digits themselvesSame as above
Account and entry details: issuer, account name, service name, web address, username, notes, icon, order, dates, and code settingsA local database file on the deviceEncrypted at rest by iOS under its default file protection, which makes it readable once you have unlocked the device for the first time after a restart
Backup password, only if you choose to save itiOS Keychain, marked to syncSynced to your other Apple devices through your iCloud Keychain. This is the single exception to the device-only rule, and it is off unless you turn it on
Browser tabs, history, cookies, and cacheMemory onlyDiscarded when you close the app; never written to disk
Appearance and biometric preferencesStandard app preferencesNot sensitive, and contains no account data

The split matters: the database holds the labels that tell you which account is which, and the Keychain holds the secret that generates the code. The Keychain items carry the stronger protection of the two.

Two-factor accounts

When you add an account, its secret key goes straight to the Keychain, and the issuer, account name, and code settings go to the local database. Codes are generated on your device from the secret and the current time. Generating a code needs no network connection, and the app never transmits a code or a secret.

Revealing or copying a secret key requires Face ID, Touch ID, or your device passcode, falling back to your app PIN when the device has no passcode set. Generated codes are not gated this way, because you use them many times a day and they expire on their own.

Saved passwords

The password vault stores a password, username, service name, web address, and notes for each entry. The password itself goes in the Keychain. The username, service name, web address, and notes go in the local database, under the file protection described above — so treat notes as you would the rest of that database, and avoid putting a second copy of the password there.

Revealing or copying a saved password requires Face ID, Touch ID, or your device passcode, with your app PIN as the fallback.

The built-in browser

The app includes a browser tab for opening websites without leaving the app — useful when you are signing in to a service and need a code at the same time. It is a standard iOS web view.

This is the only part of the app that makes network requests. Everything else — generating codes, storing accounts, unlocking, backing up — works with no network connection at all.

Encrypted backups

Because your accounts live only on your device, the app can export an encrypted backup file so you are not one lost phone away from losing them. Backups are created only when you ask for one, and exporting requires Face ID, Touch ID, or your device passcode.

Importing from Google Authenticator

The app can read the QR codes Google Authenticator produces from its "Transfer accounts" export. The code is decoded on your device, and the accounts it contains are added to your Keychain and local database the same way a manually added account would be. Nothing about the import is sent anywhere, and we are not involved in it.

The clipboard

Copying is handled differently depending on what you copy.

Camera

The camera is used for one thing: reading QR codes when you add an account. iOS asks your permission the first time. The app reads only the code's text, on your device. No photo or video is captured, stored, or transmitted.

Third-party services

The app itself uses none. It contains no analytics, no crash reporting, no advertising, and no third-party SDKs of any kind. The only data that reaches anyone else is what you send by using the browser: the sites you choose to open, and Google if you search from the address bar, both described above.

If a future version adds analytics, crash reporting, purchases, or syncing of your accounts, we will update this policy and change the effective date at the top of this page before that version ships.

Data we do not collect

We operate no servers and receive nothing from the app. In particular we never collect:

Retention

Your data stays on your device until you remove it. What each kind of removal actually does differs, and the difference matters:

Because the database is what tells the app which Keychain item belongs to which account, uninstalling first and erasing afterwards is not possible: after a reinstall the app no longer has the references, so those secrets stay on the device unreachable by it. They are still protected by the Keychain, still readable only while the device is unlocked, and still never sent anywhere — but they are not removed until the device is erased or you erase the app's data before uninstalling.

Any backup file you exported stays wherever you put it until you delete it yourself. Because we never receive any of this, there is nothing for us to retain or delete on our side.

Your choices and rights

Children

The app is not directed at children under 13, and we do not knowingly collect personal data from them.

Security

Secrets and passwords are held in the iOS Keychain, readable only while your device is unlocked, and marked so they never leave it. The app can be locked with Face ID, Touch ID, or a PIN, and repeated wrong PIN entries are slowed down with increasing delays. Revealing or copying a secret requires authentication. The app also covers its contents in the iOS app switcher so a revealed password does not end up in a screenshot of your recent apps.

Please protect your device with a passcode and keep iOS up to date. Because your accounts exist only on your device, losing it without a backup means losing them — we cannot recover them for you. Make an encrypted backup, and keep the backup codes each service gives you when you set up two-factor authentication.

Changes to this policy

If we change this policy, we will update the effective date at the top of this page and, for significant changes, notify you in the app.

Contact

Bakir Apps
[email protected]