Privacy Policy – Auth Sync: Safe & Secure 2FA
🔒 Privacy Policy – Auth Sync: Safe & Secure 2FA
Last updated: 22/08/2025
1. Introduction
Welcome to Auth Sync: Safe & Secure 2FA (“the app”, “we”, “our”, or “us”). We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, store, process, and protect your data when you use the app and related services.
By using Auth Sync, you agree to the terms described in this Privacy Policy. If you do not agree, please discontinue use of the app.
2. General Principles
-
Usable offline: Most features such as TOTP code generation, password generation, Base64 encoding/decoding, and temporary email can be used without creating an account.
-
Login is optional: You only need to sign in if you want to use Cloud Sync, Cloud Restore, or multi-device sharing.
-
End-to-End Encryption (E2EE): All sensitive data, including TOTP secrets, are encrypted locally on your device before being transmitted to our servers. We cannot access or decrypt your codes.
-
Zero-knowledge approach: Our systems are designed so that we never have knowledge of your secrets.
3. Information We Collect
We aim to minimize data collection. Depending on how you use the app, we may process the following categories of information:
3.1. Data we do not collect
-
TOTP secrets, passwords, one-time codes: These remain on your device and, when synced, are encrypted with your private key. We cannot access or read this data.
-
Generated passwords: Created locally on your device and never sent to our servers.
-
Temporary email content: Stored only temporarily for functionality and deleted automatically after expiration.
3.2. Data we may collect (if you create an account or enable sync)
-
Account Information: Email address, Apple ID, or Google ID to identify your account.
-
Device Information: Anonymous identifiers used for secure synchronization across multiple devices.
-
Diagnostics and Crash Reports: Logs about errors, app performance, and device type (e.g., iOS version, device model). This data is anonymized and used solely to improve app stability.
-
Basic Usage Data (optional, if analytics is enabled): Information about which features are most used, strictly without collecting TOTP content.
4. How We Use Your Information
-
To provide core services: Ensuring that features like sync, backup, and restore function correctly.
-
To secure your account: Verifying identity when signing in, linking devices, or restoring data.
-
To improve the app: Analyzing diagnostics and crash reports to fix bugs and optimize performance.
-
To communicate with you: Responding to support requests or notifying you about critical updates.
We do not use your data for advertising purposes and do not share it with third parties for marketing.
5. Data Storage & Security
-
On-device storage: TOTP secrets, passwords, and sensitive data are encrypted and stored locally on your device.
-
Cloud storage (if enabled): Data is encrypted with end-to-end encryption. We only store encrypted blobs; we do not hold the keys to decrypt your data.
-
Transmission security: All data transmitted between your device and our servers is protected with industry-standard TLS/SSL encryption.
-
Server security: Our servers are hardened and monitored for unauthorized access attempts.
6. Data Sharing & Third Parties
We do not sell or trade your information. However, the app may integrate with trusted third-party services for specific functionality:
-
Authentication Providers: Apple, Google, or other identity providers, to allow you to sign in securely.
-
Cloud Services: For optional encrypted synchronization and storage.
-
Analytics / Crash Reporting: Tools such as Firebase Crashlytics may be used to capture anonymized error logs and performance data.
These third parties have their own privacy policies, and we recommend reviewing them.
7. Data Retention
-
Local data: Remains on your device until you delete the app or manually remove it.
-
Cloud data: Retained as long as you maintain your account. If you delete your account, all associated cloud data will be permanently deleted from our servers.
-
Temporary emails: Automatically deleted after expiration.
-
Diagnostics data: Stored only as long as necessary to resolve issues, typically no longer than 90 days.
8. Your Rights
Depending on your location, you may have rights under applicable data protection laws (such as GDPR, CCPA), including:
-
Access: Request access to the information we hold about you.
-
Correction: Update or correct inaccurate information.
-
Deletion: Delete your account and associated data at any time.
-
Export: Request a copy of your synced data in a portable format.
-
Opt-out: Use the app offline without providing personal information.
You can exercise these rights by contacting us at support@1timetech.com.
9. Children’s Privacy
Our app is not directed to children under 13 (or the age required by local law). We do not knowingly collect personal data from children. If we learn we have inadvertently collected such data, we will delete it immediately.
10. International Data Transfers
Your information may be transferred to and stored on servers located outside your country of residence. Regardless of where it is stored, we apply the same strong encryption and security measures.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be effective immediately upon posting to our website. If the changes are significant, we will provide a clear notice within the app.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our practices, you can reach us at: