Privacy Policy

Nanjing Xiayuyue Network Technology Co., Ltd.

Effective Date: January 2026


1. Introduction

This Privacy Policy explains how Nanjing Xiayuyue Network Technology Co., Ltd. (hereinafter referred to as "we", "us", or "our") processes your information when you use the Authenticator application (hereinafter referred to as "the App"). We strictly comply with applicable international personal data protection laws and standards.

Before using the App, please read this policy carefully. Continued use of the App indicates that you understand and agree to all terms outlined in this policy.

Core Security & Zero-Knowledge Design

We firmly believe that your data belongs strictly to you. The App adopts a local-first security sandbox architecture covering the entire iOS, macOS, and watchOS ecosystem. All of your secret keys and account details are securely encrypted and kept on your local device via Apple's hardware-backed Keychain and Secure Enclave. Even during cloud synchronization (iCloud) or self-hosted private cloud backup (WebDAV), data is transmitted strictly through end-to-end encrypted direct channels, entirely bypassing our own servers. In our technical architecture, we have structurally eliminated the possibility of accessing your data, going far beyond simple written promises.


2. Data We Process

2.1 Data Stored Exclusively on Your Device (Inaccessible to Us)

The following data is generated and stored locally on your device. We do not upload, access, or share it:

2.2 Device Permissions Requested

Permissions are requested strictly on demand and can be revoked anytime in System Settings:

2.3 Third-Party SDK Integrations

To analyze crash reports, optimize system performance, and handle subscription in-app purchases, the App integrates trusted third-party SDKs:

SDK Name Purpose Data Collected Privacy Link
UMeng SDK Analytics & APM Performance Device info (e.g. OpenUDID/GUID/IP/device model/OS version/network type) UMeng Privacy
Adapty SDK Subscription & In-App Purchases Device info (e.g. IDFV/device model/OS version/IP/language/timezone), transaction receipts Adapty Privacy

3. Data Storage and Cross-Border Transfers

Core 2FA & Password Data: Kept exclusively on your local device. There is no replica on our servers.

Telemetry & Crash Data: Stored in de-identified format on service provider servers solely for performance optimization and automatically purged upon fulfillment of purpose.


4. Your Data Control Rights

Rights How to Exercise
View Verification Data View and manage your tokens directly in the App
Edit Account Info Edit token names and notes anytime inside the App
Delete Local Data Delete individual accounts in-app, or uninstall the App
Revoke Permissions Disable Camera, Screen Capture, or Network permissions in device Settings

5. Policy Updates

We may periodically update this policy to reflect product changes or legal requirements. Updates will be posted with an updated effective date. Continued use of the App constitutes acceptance of the revised terms.


6. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at: