Privacy Policy
Nanjing Xiayuyue Network Technology Co., Ltd.
Effective Date: January 2026
1. Introduction
This Privacy Policy explains how Nanjing Xiayuyue Network Technology Co., Ltd. (hereinafter referred to as "we", "us", or "our") processes your information when you use the Authenticator application (hereinafter referred to as "the App"). We strictly comply with applicable international personal data protection laws and standards.
Before using the App, please read this policy carefully. Continued use of the App indicates that you understand and agree to all terms outlined in this policy.
Core Security & Zero-Knowledge Design
We firmly believe that your data belongs strictly to you. The App adopts a local-first security sandbox architecture covering the entire iOS, macOS, and watchOS ecosystem. All of your secret keys and account details are securely encrypted and kept on your local device via Apple's hardware-backed Keychain and Secure Enclave. Even during cloud synchronization (iCloud) or self-hosted private cloud backup (WebDAV), data is transmitted strictly through end-to-end encrypted direct channels, entirely bypassing our own servers. In our technical architecture, we have structurally eliminated the possibility of accessing your data, going far beyond simple written promises.
2. Data We Process
2.1 Data Stored Exclusively on Your Device (Inaccessible to Us)
The following data is generated and stored locally on your device. We do not upload, access, or share it:
- 2FA Account Credentials: All 2FA account names, issuer details, secret keys, and calculated dynamic passcodes;
- Biometric Authentication: Face ID / Touch ID verification is executed 100% locally by Apple's operating system. We never access raw biometric data;
- Password Vault: Passwords, usernames, and notes stored in the vault are encrypted locally with hardware-level encryption;
- WebDAV Configuration Credentials: Your self-hosted WebDAV server address, username, and password are saved strictly in the local Secure Keychain. Data connections go directly between your device and your private server;
- AES Encrypted Exports: Offline backup packages encrypted with your custom master password, placing decryption authority entirely in your hands.
2.2 Device Permissions Requested
Permissions are requested strictly on demand and can be revoked anytime in System Settings:
- Camera (iOS): Used solely for scanning QR codes to add 2FA accounts. Captured video frames are processed locally in real-time and never saved or uploaded;
- Screen Recording / Capture (macOS): Used on-demand when you explicitly trigger "Scan Screen for QR Code" on Mac desktop. The screen frame is parsed in milliseconds and destroyed immediately, never recorded, cached, or uploaded;
- Photo Library: Used only when you manually choose to "Import QR Code from Photos". Processing happens entirely on-device;
- Network: Used for time synchronization (ensuring TOTP passcode accuracy), iCloud/WebDAV encrypted data roaming, and anonymous crash telemetry. Never used to intercept or upload your credentials.
2.3 Third-Party SDK Integrations
To analyze crash reports, optimize system performance, and handle subscription in-app purchases, the App integrates trusted third-party SDKs:
| SDK Name | Purpose | Data Collected | Privacy Link |
|---|---|---|---|
| UMeng SDK | Analytics & APM Performance | Device info (e.g. OpenUDID/GUID/IP/device model/OS version/network type) | UMeng Privacy |
| Adapty SDK | Subscription & In-App Purchases | Device info (e.g. IDFV/device model/OS version/IP/language/timezone), transaction receipts | Adapty Privacy |
3. Data Storage and Cross-Border Transfers
Core 2FA & Password Data: Kept exclusively on your local device. There is no replica on our servers.
Telemetry & Crash Data: Stored in de-identified format on service provider servers solely for performance optimization and automatically purged upon fulfillment of purpose.
4. Your Data Control Rights
| Rights | How to Exercise |
|---|---|
| View Verification Data | View and manage your tokens directly in the App |
| Edit Account Info | Edit token names and notes anytime inside the App |
| Delete Local Data | Delete individual accounts in-app, or uninstall the App |
| Revoke Permissions | Disable Camera, Screen Capture, or Network permissions in device Settings |
5. Policy Updates
We may periodically update this policy to reflect product changes or legal requirements. Updates will be posted with an updated effective date. Continued use of the App constitutes acceptance of the revised terms.
6. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
- Company: Nanjing Xiayuyue Network Technology Co., Ltd.
- Email: service@xiayuyue.com
- Website: http://authenticator.xiayuyue.com/en/