Privacy Policy
Authenticator App: Authkey 2FA
The short version. Authkey 2FA does not have user accounts and does not run servers. Every two-factor account you add — the label, the issuer and the secret key — is stored encrypted on your own phone and is never transmitted to us or to anyone else. We cannot see your codes, your accounts, or your secret keys.
The app does show advertisements supplied by Google AdMob. Google's advertising systems collect certain device-level information, described in section 6. That is the only data collection connected with this app, and it never includes your two-factor account data.
This policy explains what Authkey 2FA (the "app", "we", "our") does and does not do with information, and what rights you have. It applies to the Android application "Authenticator App: Authkey 2FA" distributed through Google Play by AB Properties.
1.Information we do not collect
We want to be specific about this rather than vague, because it is the whole point of the app.
- We do not collect your name, email address, phone number or postal address.
- We do not ask you to register, sign in, or create an account of any kind.
- We do not collect, transmit, receive or store your two-factor secret keys, account labels, issuer names or generated verification codes.
- We do not operate any server, database or cloud storage that holds your data.
- We do not sell, rent or trade any information to data brokers.
- We do not have any technical ability to recover your accounts for you. If you lose your device without a backup, your entries are gone, and we cannot restore them.
2.Information stored on your device
Authkey 2FA stores the following locally on your phone, in the app's private storage area, protected by Android's application sandbox and by encryption:
| What is stored | Why |
|---|---|
| Account label and issuer name (for example "Google — you@example.com") | So you can identify which code belongs to which account |
| The TOTP secret key for each account | Required to generate your verification codes |
| App settings — theme choice, fingerprint unlock, screen-lock and screen-capture preferences | To keep the app configured the way you left it |
This information stays on your device. Uninstalling the app removes it. Because your accounts are held only on your device, you are responsible for keeping a backup if you want to be able to recover them.
3.Permissions the app requests
Camera
Used only when you choose to add an account by scanning a QR code. The camera preview reads the 2FA barcode and closes. We do not take photographs, do not record video, do not store any image, and do not transmit anything from the camera. You can decline this permission and add accounts by typing the setup key instead.
Biometric and device credentials
If you enable Fingerprint Unlock or Device PIN / Screen Lock, the app asks Android to confirm your identity. Verification is performed entirely by the Android operating system and the secure hardware on your device. The app receives only a yes-or-no result. We never receive, see or store your fingerprint, face data or PIN.
Internet access
Your verification codes are calculated on the device using the TOTP standard and do not require a network connection. Internet access is used only to request and display advertisements, as described in section 6.
4.Backup and export files
The app can create an encrypted backup file of your accounts using Backup to File, and read one back using Restore from File. These files are produced on your device and saved wherever you choose to put them.
Once a backup file leaves the app, it is under your control, not ours. If you save it to a cloud service such as Google Drive, Dropbox or a messaging app, that provider's privacy policy governs it. Treat a backup file like a spare key: keep it somewhere private, and do not email it to yourself.
The Copy Account URI (otpauth://) feature places a single account's setup details, including its secret key, on your device clipboard so you can move it to another authenticator. Other applications on your device may be able to read the clipboard. Paste it where you intend to and then copy something else to clear it.
5.Screen capture protection
When Prevent Screen Capture is switched on, the app instructs Android to block screenshots and screen recording while the app is open. This is a protection offered by the operating system. It is effective against ordinary screenshot and recording tools, but it is not a guarantee against every possible method of capture, particularly on a device that has been rooted or compromised.
6.Advertising
Authkey 2FA displays advertisements provided by Google AdMob so that the app can remain free to use.
To serve and measure those advertisements, Google collects information from your device. This is handled by Google's advertising systems, not by us — we do not receive this data and cannot link it to your two-factor accounts, which never leave your phone. The information Google may collect includes:
- Your Android Advertising ID, a resettable identifier assigned by the operating system
- IP address and approximate, IP-derived location
- Device model, operating system version, language and mobile network information
- Which advertisements were shown, viewed or tapped
Google's use of this information is governed by its own policies. You can read how Google handles data from apps that use its services at policies.google.com/technologies/partner-sites and Google's privacy policy at policies.google.com/privacy.
Controlling advertising on your device
You can reset or delete your Advertising ID at any time, and turn off ad personalisation, in your device settings under Settings → Google → Ads. Deleting the Advertising ID stops apps from receiving it. Advertisements will still appear, but they will be less relevant to you.
Consent in the European Economic Area, the United Kingdom and Switzerland
If you are in one of these regions, the app presents a consent request the first time you open it, using Google's User Messaging Platform, as required by Google's EU User Consent Policy. You choose whether to allow personalised advertising. You can change your choice later from the app's settings. If you decline, you will see non-personalised advertisements instead.
7.Children
Authkey 2FA is a general-audience security tool. It is not directed at children, and we do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your country). If you believe a child has provided personal information through this app, contact us at the address in section 12 and we will act on it.
8.Your rights
Because we hold no personal data about you on any server, there is nothing on our side for us to look up, export or delete. Your rights therefore work as follows:
- Access and portability. Everything the app holds about you is on your device and visible in the app. Backup to File and Copy Account URI let you export it at any time.
- Deletion. Delete an individual account from within the app, or uninstall the app to remove everything it stores.
- Advertising data. Requests relating to data collected by Google's advertising systems should be directed to Google, since Google is the controller of that data. Google's controls are linked in section 6.
If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your national data protection authority. If you are a California resident, we confirm that we do not sell or share personal information as those terms are defined by the California Consumer Privacy Act.
9.Security
Account secrets are stored in the app's private storage area with encryption, and the app offers biometric or device-credential locking and screen-capture blocking as additional layers. No method of storage is perfectly secure, and the security of your data also depends on your device: keep your operating system updated, use a screen lock, and be cautious about installing software from outside Google Play. A device that has been rooted or infected with malware may expose data that would otherwise be protected.
10.Third parties
The only third-party service integrated into this app is Google AdMob, described in section 6. We do not use third-party analytics, crash reporting, attribution or user-tracking software. If that changes in a future version, this policy will be updated before the change is released.
11.Changes to this policy
We may update this policy to reflect changes to the app or to legal requirements. The effective date at the top of this page will change when we do. Material changes will be reflected in the app's Google Play listing and in the app's release notes. Continuing to use the app after an update means you accept the revised policy.
12.Contact
Questions, concerns or requests about this policy or about privacy in Authkey 2FA:
AB Properties
abbasbawazirab786@gmail.com