Authenticator App ("we", "our", "us") respects your privacy. This Privacy Policy explains how we collect, use, and protect your information when you use our mobile application and related services ("Service"). Because this Service exists to protect your accounts, we have designed it to collect as little personal information as technically possible.
Your vault contents are stored in encrypted form only. We do not have the keys required to decrypt them, which means we cannot read your data, disclose it to third parties, or restore it for you if you lose access.
The app requests camera access solely to scan QR codes when you add a new two-factor authentication account. Scanning is performed entirely on your device. Images from your camera are not stored, uploaded, or transmitted anywhere.
The security monitoring feature checks whether your email addresses or passwords have appeared in known public data breaches. These checks are performed using privacy-preserving methods: your passwords are never sent to us or to any third party in readable form, and only a partial, irreversible hash is used to perform the lookup. Results are displayed on your device.
The built-in browser does not store browsing history, cookies, or site data by default, and blocks third-party trackers. We do not collect, log, or transmit the addresses of the websites you visit. Websites you open are still subject to their own privacy practices.
We use trusted third-party services such as Firebase, Google Analytics, and attribution SDKs to help us analyze app usage and deliver core functionality. These third parties may collect anonymous or aggregated data for analytics purposes. They never receive your vault contents, secret keys, or passwords. We do not sell personal data to advertisers.
Your secret keys and passwords are encrypted on your device and protected by the iOS Keychain and Secure Enclave. You can add Face ID, Touch ID, or a PIN, with automatic locking when you leave the app. Any data transmitted to our servers is sent over secure connections.
Your vault lives on your device and in your own iCloud account. Deleting the app removes local data, and you can delete your encrypted backup at any time through your Apple ID settings. Usage and analytics data is retained only as long as needed for the purposes described above.
You may request access to or deletion of your personal data. If you are located in the EU or California, you have rights under GDPR and CCPA to request access, deletion, and opt-out of data sales (we do not sell data). Please note that we cannot access or delete your encrypted vault contents on your behalf, because we do not hold the keys to them.
Our Service is not intended for children under the age of 13, and we do not knowingly collect personal data from children.
We may update this Privacy Policy to reflect changes to our practices. We will notify users of significant changes by posting an updated policy within the app or on our website.
For questions or concerns, please contact us at: support@lumetro.com