Authenticator privacy policy
Authenticator generates two-factor authentication codes, stores passwords, and includes a built-in web browser. This policy explains what data the app handles, where each kind is stored, and how it is protected. It applies to the Authenticator app for iOS published by Bakir Apps ("we", "us"), which distributes its apps through this site, Bakir Store.
The short version
- Your two-factor secrets and saved passwords are stored in the iOS Keychain on your device, marked so they never sync anywhere.
- We have no servers and no accounts. We cannot see your secrets, your passwords, or your codes, and there is no sign-up.
- The app uses no third-party SDKs, and collects no analytics or crash reports.
- The built-in browser is the one part of the app that uses the network. The sites you open receive requests from your device, as they would in any browser.
- You can create an encrypted backup file. You choose its password and where it goes; we never receive it.
- We do not sell your data.
What the app stores, and where
The app keeps two separate stores on your device. Secrets go in the iOS Keychain; the labels and settings around them go in a local database. Nothing in either store is sent to us.
| Data | Where it is stored | How it is protected |
|---|---|---|
| Two-factor secret keys | iOS Keychain | Readable only while the device is unlocked, and marked device-only, so it never syncs to iCloud and is not carried over to a new device |
| Saved passwords | iOS Keychain | Same as above |
| Your app PIN | iOS Keychain, as a salted hash — never the digits themselves | Same as above |
| Account and entry details: issuer, account name, service name, web address, username, notes, icon, order, dates, and code settings | A local database file on the device | Encrypted at rest by iOS under its default file protection, which makes it readable once you have unlocked the device for the first time after a restart |
| Backup password, only if you choose to save it | iOS Keychain, marked to sync | Synced to your other Apple devices through your iCloud Keychain. This is the single exception to the device-only rule, and it is off unless you turn it on |
| Browser tabs, history, cookies, and cache | Memory only | Discarded when you close the app; never written to disk |
| Appearance and biometric preferences | Standard app preferences | Not sensitive, and contains no account data |
The split matters: the database holds the labels that tell you which account is which, and the Keychain holds the secret that generates the code. The Keychain items carry the stronger protection of the two.
Two-factor accounts
When you add an account, its secret key goes straight to the Keychain, and the issuer, account name, and code settings go to the local database. Codes are generated on your device from the secret and the current time. Generating a code needs no network connection, and the app never transmits a code or a secret.
Revealing or copying a secret key requires Face ID, Touch ID, or your device passcode, falling back to your app PIN when the device has no passcode set. Generated codes are not gated this way, because you use them many times a day and they expire on their own.
Saved passwords
The password vault stores a password, username, service name, web address, and notes for each entry. The password itself goes in the Keychain. The username, service name, web address, and notes go in the local database, under the file protection described above — so treat notes as you would the rest of that database, and avoid putting a second copy of the password there.
Revealing or copying a saved password requires Face ID, Touch ID, or your device passcode, with your app PIN as the fallback.
The built-in browser
The app includes a browser tab for opening websites without leaving the app — useful when you are signing in to a service and need a code at the same time. It is a standard iOS web view.
This is the only part of the app that makes network requests. Everything else — generating codes, storing accounts, unlocking, backing up — works with no network connection at all.
- The browser uses a non-persistent data store. Cookies, caches, local storage, and the back-forward list exist only in memory and are discarded when you close the app. No browsing history is written to disk or retained.
- Sites you visit receive requests from your device, and can see your IP address, the pages you request, and anything you submit to them, exactly as they would in Safari or any other browser. Their own privacy policies govern what they do with that.
- If what you type in the address bar is not a web address, it is sent to Google as a search query. That request goes to Google, not to us, and is handled under Google's privacy policy.
- The browser is walled off from the rest of the app. It cannot read your accounts, passwords, or secrets, the app fills nothing into web pages for you, and it runs no scripts of our own inside the pages you open.
- We do not log, collect, or transmit the addresses you visit or the searches you run. We never see them.
Encrypted backups
Because your accounts live only on your device, the app can export an encrypted backup file so you are not one lost phone away from losing them. Backups are created only when you ask for one, and exporting requires Face ID, Touch ID, or your device passcode.
- The file is encrypted with a password you choose, using AES-GCM with a key derived through PBKDF2-HMAC-SHA256 at 1,200,000 iterations and a random salt. The strength of the file rests on the password you pick, so choose a strong one — we cannot recover or reset it.
- It contains your two-factor accounts and saved passwords, including their secrets. It deliberately does not contain your app PIN.
- When the backup is ready, iOS hands you the standard share sheet and you decide where it goes — iCloud Drive, another app, another device, or nowhere. That choice is yours, and the destination you pick handles the file under its own terms. The app's temporary copy is deleted once you are done.
- We never receive the file, the password, or any part of either. There is nowhere for them to be sent.
- You may optionally save the backup password to your iCloud Keychain so it survives the loss of the device. This is off by default. When on, the password syncs to your other Apple devices through your own iCloud account, encrypted by Apple; we have no access to it. Your secrets and passwords themselves are never synced this way.
- Restoring asks for the file and its password and puts the entries back on the device, with nothing leaving it.
Importing from Google Authenticator
The app can read the QR codes Google Authenticator produces from its "Transfer accounts" export. The code is decoded on your device, and the accounts it contains are added to your Keychain and local database the same way a manually added account would be. Nothing about the import is sent anywhere, and we are not involved in it.
The clipboard
Copying is handled differently depending on what you copy.
- Secret keys and saved passwords are marked local-only, so they stay on the device and are not offered to your other Apple devices through Universal Clipboard. They expire from the clipboard after two minutes, and the app clears them sooner if it locks while they are still there.
- Generated codes and usernames are not marked local-only, so — like anything else you copy — they may reach your other Apple devices through Universal Clipboard if you have it enabled. This is deliberate, so you can paste a code on your Mac. Codes expire within seconds on their own.
Camera
The camera is used for one thing: reading QR codes when you add an account. iOS asks your permission the first time. The app reads only the code's text, on your device. No photo or video is captured, stored, or transmitted.
Third-party services
The app itself uses none. It contains no analytics, no crash reporting, no advertising, and no third-party SDKs of any kind. The only data that reaches anyone else is what you send by using the browser: the sites you choose to open, and Google if you search from the address bar, both described above.
If a future version adds analytics, crash reporting, purchases, or syncing of your accounts, we will update this policy and change the effective date at the top of this page before that version ships.
Data we do not collect
We operate no servers and receive nothing from the app. In particular we never collect:
- Your secret keys, saved passwords, or generated codes
- Your backup files or backup password
- Your name, email address, phone number, or contacts
- Your precise location
- Photos, camera images, or files
- The websites you visit or the searches you run in the browser
- Usage analytics, crash reports, or device identifiers
Retention
Your data stays on your device until you remove it. What each kind of removal actually does differs, and the difference matters:
- Deleting an entry in the app removes both its Keychain secret and its record in the local database. This is complete.
- Uninstalling the app removes the local database — every issuer, account name, username, note, and setting — but not the Keychain items. iOS deliberately preserves an app's Keychain entries after the app is deleted, so your two-factor secrets, saved passwords, and app PIN remain on the device. Reinstalling restores access to them: the app will ask for your existing PIN rather than offering to set a new one.
- Erasing everything in the app — on the lock screen, "Forgot password?" then "Erase Everything & Reset PIN" — deletes every account and password the app is currently showing, secrets included, and resets your PIN. Do this before uninstalling if your intent is to leave nothing behind.
Because the database is what tells the app which Keychain item belongs to which account, uninstalling first and erasing afterwards is not possible: after a reinstall the app no longer has the references, so those secrets stay on the device unreachable by it. They are still protected by the Keychain, still readable only while the device is unlocked, and still never sent anywhere — but they are not removed until the device is erased or you erase the app's data before uninstalling.
Any backup file you exported stays wherever you put it until you delete it yourself. Because we never receive any of this, there is nothing for us to retain or delete on our side.
Your choices and rights
- Delete any account or password entry at any time. To remove everything, use "Forgot password?" then "Erase Everything & Reset PIN" on the lock screen — and do that before uninstalling, because uninstalling alone leaves your secrets in the Keychain.
- Export an encrypted backup, or don't — the feature is entirely optional.
- Turn off saving the backup password to your iCloud Keychain, which also removes it from your other devices.
- Use or ignore the browser tab. The rest of the app works with no network connection.
- Withdraw camera permission at any time in the iOS Settings app, and add accounts by typing the key instead.
- Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, or delete personal data we hold. Because we do not hold data that identifies you, most requests can be fulfilled by the steps above; for anything else, contact us.
Children
The app is not directed at children under 13, and we do not knowingly collect personal data from them.
Security
Secrets and passwords are held in the iOS Keychain, readable only while your device is unlocked, and marked so they never leave it. The app can be locked with Face ID, Touch ID, or a PIN, and repeated wrong PIN entries are slowed down with increasing delays. Revealing or copying a secret requires authentication. The app also covers its contents in the iOS app switcher so a revealed password does not end up in a screenshot of your recent apps.
Please protect your device with a passcode and keep iOS up to date. Because your accounts exist only on your device, losing it without a backup means losing them — we cannot recover them for you. Make an encrypted backup, and keep the backup codes each service gives you when you set up two-factor authentication.
Changes to this policy
If we change this policy, we will update the effective date at the top of this page and, for significant changes, notify you in the app.
Contact
Bakir Apps
[email protected]