Authenticator
SupportPrivacyTermsSubscriptions简体中文
Cosine Studio

Privacy Policy

How the current iOS version of Authenticator processes and protects information.

Effective and last updated: July 22, 2026

Plain-language summary. Authenticator does not require a developer-operated account and contains no advertising, analytics, tracking, or crash-reporting SDK. Your vault is encrypted locally. Optional Pro sync stores independently encrypted records in your private Apple iCloud database.
Contents
  1. Scope
  2. Data we do not collect
  3. Local data
  4. iCloud Sync
  5. Apple services
  6. Website data
  7. Retention and deletion
  8. Security
  9. Children
  10. Choices and rights
  11. Changes
  12. Contact

1. Scope and service provider

This Privacy Policy applies to the iOS and iPadOS version of Authenticator (bundle identifier com.pixelcraft.authenticator.app.safe) and this support website. Authenticator is provided by Cosine Studio (“we,” “us,” or “our”).

This policy describes the released functionality reflected by the current app build. If the app’s data practices change, we will update this policy and the corresponding App Store privacy disclosures.

2. Data we do not collect through the app

The current iOS app does not include a developer-operated user account, advertising SDK, analytics SDK, tracking SDK, or crash-reporting SDK. Through the app, we do not collect or receive:

  • authentication secrets, generated one-time codes, passwords, private notes, or backup passwords;
  • your precise or coarse location;
  • contacts, browsing history, search history, advertising identifiers, or device fingerprints;
  • usage analytics or diagnostic logs sent to Cosine Studio; or
  • your payment-card number or full App Store billing information.

3. Information processed and stored locally

When you choose to enter, scan, paste, or import information, the app may process and store the following on your device:

  • authentication account names, issuers, secret keys, tags, icons, TOTP/HOTP settings, counters, and organization choices;
  • Password Vault titles, usernames, passwords, website associations, and private notes;
  • app preferences and security settings;
  • custom icons you import; and
  • encrypted backup files you create or import.

Sensitive vault records are encrypted on the device. The corresponding local encryption key is stored using Apple’s Keychain services. Non-sensitive preferences may use standard operating-system preferences storage.

4. Optional encrypted iCloud Sync

iCloud Sync is optional, requires an active Authenticator Pro entitlement, and uses the user’s private CloudKit database. When enabled:

  • authentication accounts and Password Vault records are encrypted on the device before upload;
  • a random sync key encrypts the synchronized payloads;
  • the sync password wraps that key and is never saved or uploaded by Authenticator;
  • Cosine Studio cannot access the user’s private CloudKit database or recover the sync password; and
  • CloudKit account and transport operations are provided by Apple under Apple’s terms and privacy policy.

Turning off sync stops synchronization and removes local sync-key material when cleanup succeeds, but it does not delete local records or existing iCloud records. You may reconnect later using the same sync password.

5. Apple system services and purchases

Features you choose to use may rely on Apple system services:

  • Camera: requested only when you choose QR scanning.
  • Photos and Files: the app receives only items you explicitly select through Apple’s pickers.
  • Clipboard: processed when you explicitly paste or copy; optional automatic clearing is performed on device.
  • Face ID or Touch ID: evaluated by iOS. The app receives the authentication result, not biometric data.
  • StoreKit and App Store: Apple provides product information, offer eligibility, transaction verification, and entitlement status. Apple processes billing. The app does not receive full payment-card details.
  • Share sheet, Siri, Spotlight, and Shortcuts: used only when you invoke those system features.

Apple’s handling of information is governed by Apple’s Privacy Policy and applicable Apple service terms.

6. This support website

This website is served through Firebase Hosting. We do not load advertising, analytics, tracking pixels, social-login tools, or non-essential cookies on these pages. Google, as the hosting provider, may process basic request and security information such as IP address, user agent, requested URL, timestamp, and network diagnostics to deliver and protect the site. That hosting activity is governed by Google’s applicable privacy terms.

If you email support, we receive your email address and the information you voluntarily include. Do not send authentication secrets, one-time codes, passwords, backup files, or sync passwords.

7. Retention and deletion

  • Local app data: remains until you delete individual records or uninstall the app. We cannot remotely access or delete it.
  • Private iCloud data: remains in your private iCloud database when sync is turned off. You can manage or delete app data using Apple’s iCloud storage controls. Labels and paths may vary by OS version. We cannot perform this deletion for you.
  • Exported backups: remain wherever you saved or shared them and must be deleted there separately.
  • Support correspondence: may be retained for as long as reasonably necessary to answer the request, maintain support records, prevent abuse, or meet legal obligations.

Detailed steps are available on the Privacy Choices and Data Deletion page.

8. Security

We design the app to minimize developer access to sensitive information. Local encryption, Keychain-protected key material, optional independently encrypted CloudKit payloads, privacy shielding, and system authentication help protect data. No method of storage or transmission is completely secure, and you are responsible for keeping device credentials, sync passwords, and exported backup passwords safe.

Recovery limitation: Cosine Studio and Apple cannot recover the app’s separate sync password or encrypted backup password. Losing them may permanently prevent access to the corresponding encrypted data.

9. Children

The app is not directed to children under 13, and we do not knowingly collect personal information from children through the current iOS app. A parent or guardian with a privacy question may contact us.

10. Privacy choices and rights

Depending on your location, applicable law may provide rights concerning personal information. Because we do not operate an app account or receive the app’s vault contents, we generally cannot access, export, correct, or delete that device or private-CloudKit data for you. You retain direct control using the app, iOS, iCloud, and the files you created.

You may contact us about support correspondence or this website. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.

11. Changes to this policy

We may update this policy when the app, website, law, or service providers change. We will revise the date above and publish the updated version here. Material changes will be communicated where required by applicable law.

12. Contact

Cosine Studio
Email: xqing4049@gmail.com
Support: authenticator-b2558.web.app/support

This policy is an operational disclosure of the app’s current data practices and is not a substitute for advice from qualified legal counsel in your jurisdiction.

© 2026 Cosine Studio
Privacy ChoicesTermsSubscriptionsSupport