1. Scope and responsible developer
This policy applies to the Spot Auth mobile application, the official Spot Auth website, and the 2FA test tool. Spot Auth is published by an independent developer (referred to as “Spot Auth,” “we,” or “us”). Privacy questions may be sent to [email protected].
Future Android or browser releases are covered when they link to this policy. Platform-specific behavior is identified below; a store listing does not mean every feature is available on every platform.
2. Information processed on your device
To provide authentication, the app processes the service or issuer name, account label, OTP secret, algorithm, digit count, period, display order, preferences, locally cached service logos, sync state, and recently deleted records. These items are used to generate codes, organize your vault, preserve settings, and perform actions you request.
OTP secrets are encrypted with AES-256-GCM before being stored in the device Keychain. Ordinary metadata and preferences are stored in platform-provided local storage. Spot Auth has no official account database or official server that receives your vault.
- TOTP codes are calculated locally.
- Review-prompt counters and similar app preferences stay on the device.
- Recently deleted entries may retain their encrypted secret locally for up to seven days so you can restore them.
3. Camera, photos, biometrics, and files
Camera access is requested only when you choose to scan a QR code. If you select a QR image from your photo library, the system photo picker provides only the item you select. Camera frames and selected images are decoded on-device and are not uploaded by Spot Auth.
Face ID, Touch ID, or the device passcode may be used to unlock the app or confirm a sensitive action. Authentication is performed by the operating system; Spot Auth receives only the success or failure result and does not receive or store biometric templates. Files are accessed only when you choose an import, export, backup, or restore action.
- You can deny camera or photo access and add accounts manually.
- Permission controls are available in your operating-system settings.
4. Optional service-logo retrieval
Network logo retrieval is off until you enable it. When enabled, Spot Auth derives a likely service domain from the issuer and requests an image from Logo.dev. The request can reveal the inferred domain plus ordinary connection data such as IP address, user agent, and request time to Logo.dev and network providers. OTP secrets and verification codes are never included in the logo request.
Downloaded logos are cached on your device. You can disable logo retrieval or enable Offline Mode at any time; cached logos may remain until you clear the related entry or app data. Logo.dev handles request data under its own privacy terms.
5. Optional cloud sync: iCloud Drive, Google Drive, and WebDAV
Cloud sync is optional and intended for Pro users, and provider availability depends on the operating system and app version. On Apple-platform releases, the app can store an encrypted backup in your iCloud Drive. On Android releases, Google Drive is covered by this policy only when the app actually presents Google Drive as an available sync provider. WebDAV is available only on releases that show it in the app. Before any upload, Spot Auth packages vault metadata and OTP secrets into an encrypted backup protected by the password you choose. No copy is stored on an official Spot Auth server.
Apple, Google, or your WebDAV provider receives the encrypted file and ordinary service data needed to operate the connection. For WebDAV, the server address and username are stored in local preferences and the password is stored in the secure credential store; HTTP Basic authentication is used only over HTTPS. A Google Drive implementation should request only the narrowest app-file or app-data permission needed. The developer cannot recover your backup password or decrypt your cloud file without it.
- Enabling more than one provider sends an encrypted copy to each enabled provider.
- Provider availability, retention, access logs, authorization tokens, and international transfers are governed by that provider.
- Turning sync off stops new syncs but does not automatically delete an existing remote file.
6. Import, export, sharing, and clipboard
Imports are parsed on-device from QR codes, otpauth links, or files you choose. Exports and backups are created only at your request. When you share or save an exported file, the destination app, file provider, cloud service, or recipient you select receives that file under its own terms. Unencrypted exports can expose OTP secrets; encrypted backups should use a strong, unique password.
When you tap copy, the displayed verification code is written to the operating-system clipboard. The clipboard is managed by the operating system and may be accessible to other software according to platform rules. Avoid copying codes on devices you do not trust.
7. Purchases and store services
Purchases are processed by the platform store, such as Apple’s App Store or Google Play. The store may provide Spot Auth with product, transaction, entitlement, and restoration status needed to complete the purchase and unlock features. Spot Auth does not receive your full payment-card number. Store providers handle billing information under their own privacy policies.
8. Website and 2FA test tool
The website saves your language choice in browser local storage. The 2FA test tool performs OTP and QR generation in your browser and can save test configurations in local storage when you ask it to. Test secrets are not intentionally uploaded to Spot Auth. Do not use production secrets in a test tool.
For the tool’s built-in issuer catalogue, logo files are served from this website. If you type an issuer that has no local logo, your browser may request one from Logo.dev using the issuer name or derived domain; the OTP secret is not placed in that request. The hosting provider may process routine connection and security logs, such as IP address, request time, requested path, and user agent, to deliver and protect the site.
The website uses Umami Cloud for privacy-focused traffic analytics. Umami may process page views, referrer, browser, operating-system and device type, and approximate country using an anonymous session hash rather than analytics cookies. Spot Auth does not send OTP secrets, promo codes, email addresses, or user-account identifiers to Umami.
Promo campaign pages set an HttpOnly random browser identifier so the same browser can retrieve a previously issued code. The server stores only a salted anonymous browser hash, a short-lived salted network hash for abuse prevention, the claim time, and code status. These records do not confirm that a code was redeemed in the App Store.
9. Support communications
If you email us, we receive the email address, message, attachments, and technical details you choose to provide. We use them to answer the request, investigate issues, prevent abuse, and meet legal obligations. Do not include OTP secrets, live verification codes, backup passwords, or unredacted backup files.
Support messages are kept only as long as reasonably needed for those purposes, taking into account whether the issue remains open and any legal recordkeeping requirement, then deleted or anonymized where practical.
10. What we do not do
We do not sell personal information, share it for cross-context behavioral advertising, display ads, create advertising profiles, or track you across apps and websites. The app contains no third-party analytics or crash-reporting SDK. We do not intentionally collect precise location, contacts, health data, advertising identifiers, browsing history, or your biometric template.
Optional transfers described in this policy are used for app functionality you choose, not for advertising. Spot Auth will update this policy and the relevant store disclosures before introducing materially different collection or use.
11. Retention, deletion, and no account
Spot Auth does not offer an official account, so there is no Spot Auth server account to delete. Local vault data remains until you delete entries or use the app’s clear-data controls. Recently deleted entries may remain recoverable on-device for up to seven days unless permanently erased sooner.
On Apple platforms, deleting the app alone may not remove items preserved by the system Keychain. For the most complete deletion, use the in-app Clear App Data function before uninstalling; if the app was already removed, reinstall it and clear data where possible. Delete optional iCloud or WebDAV copies through the app’s remote-data control or directly through the storage provider. Browser language and test configurations can be removed by clearing site data in your browser.
Promo claim records are retained while the related campaign remains in the management system and are deleted when the campaign is deleted. The browser identifier cookie expires automatically and can also be removed by clearing site data. Short-lived network rate-limit records expire automatically.
12. Security and limitations
Spot Auth uses platform security controls, Keychain storage, AES-256-GCM encryption, encrypted backup formats, HTTPS-only WebDAV connections, and optional device-owner authentication. No system can guarantee absolute security. Anyone with access to an unlocked device, an exported file, the clipboard, a backup password, or the configured cloud account may be able to access related information.
You are responsible for securing your device, backup password, cloud account, and exported files. If you believe your OTP secret has been exposed, replace the 2FA credential with the issuing service rather than relying only on deletion from Spot Auth.
13. Children
Spot Auth is a general-purpose security utility and is not directed to children under 13 or the minimum digital-consent age in their jurisdiction. We do not knowingly collect personal information from children through an official account or advertising system. A parent or guardian who believes a child sent personal information in a support message may contact us to request deletion.
14. Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection concerning personal information we hold. Because the vault stays on your device or in storage you choose, most access, export, correction, and deletion actions are performed directly in the app, browser, iCloud, or WebDAV service.
You can disable network logos, cloud sync, camera access, and other permissions without using those optional features. For support data or another request, email us. We may need enough information to verify and process the request, and we will respond as required by applicable law. You may also contact your local data-protection authority.
15. Changes and contact
We may update this policy when the product, providers, law, or store requirements change. Material changes will be shown by a revised date and, when appropriate, an in-app or website notice. The version posted here is the current policy.
Questions, privacy requests, or complaints may be sent to [email protected]. Please identify the product and request, but never send an OTP secret, live code, or backup password.
↗External providers
These services apply only when the related platform or optional feature is used.