1. Scope
This policy covers the Spot Auth application and this website. Spot Auth is a two-factor authentication code manager published by its independent developer.
This policy explains what Spot Auth processes, what can leave your device, and the controls you have.
This policy covers the Spot Auth application and this website. Spot Auth is a two-factor authentication code manager published by its independent developer.
Service names, account labels, preferences, and usage metadata are stored locally. OTP secret keys are encrypted with AES-256-GCM and stored in Apple Keychain, separately from ordinary app data.
Spot Auth has no official account service or analytics server. We do not collect your verification codes, secret keys, account list, advertising identifiers, browsing activity, or precise location. The app contains no ads or behavioral tracking.
If service-logo fetching is enabled, the inferred service domain is sent to Logo.dev to request an icon; no OTP code or secret is sent. You can disable icon fetching or enable Offline Mode. If you send feedback by email, your mail provider processes the message you choose to send.
Cloud sync is optional. Encrypted sync files are stored in your iCloud Drive or WebDAV destination, not on an official Spot Auth server. Access is governed by Apple or your WebDAV provider. Protect your backup password: the developer cannot recover it.
If you buy Spot Auth Pro, Apple processes the App Store transaction. Spot Auth receives only the entitlement information needed to unlock purchased features.
Local data remains until you delete it, erase the app, or remove it through app settings. Recently deleted items may remain locally for up to seven days. You control synced copies through the storage provider you selected.
Material changes will be reflected by a new date on this page. For privacy questions or requests, contact the developer at the email below.