TwoAuth (the "App") is a fully offline authenticator for two-factor and multi-factor authentication (2FA/MFA). Our privacy policy comes down to one principle:
We collect no data at all.
Data We Collect
- No account is required, and no personal information is collected (no name, email, or phone number);
- The App contains no advertising SDKs, analytics SDKs, or any other third-party components;
- The App makes no network requests — every feature runs entirely on your device.
Where Your Data Lives
- The accounts you add (issuer, account name, secret key, etc.) are stored encrypted in the local iOS system Keychain, marked "this device only" (they are not migrated with iCloud backups);
- Interface preferences (theme, icon display, etc.) are stored in the App's local sandbox;
- This data never leaves your device unless you explicitly use an export feature.
Permissions
- Camera: used solely to scan two-factor QR codes. Frames are processed on-device in real time and are never saved or uploaded;
- Photos: uses the system photo picker (the App cannot access your photo library) and reads QR codes from the images you select, entirely on-device.
Export Features
When you actively use "Transfer Accounts" or "Export to QR", the App generates QR codes or files containing your secret keys at your request. These stay entirely under your control — keep them safe and delete them after use.
Data Deletion
Deleting an account in the App, or uninstalling the App, deletes the associated data. We hold no copy of your data.
Changes
If this policy changes, we will note it in the App's release notes. Continued use of the App constitutes acceptance of the updated policy.
Contact
For any questions, please reach us via the support link on the App Store page.