Information Privacy Policy

This Privacy Policy explains how we respectfully collect, use, and protect your information when you interact with our Service. We also outline your privacy rights and how the law helps safeguard them.

The Service exists to generate two-factor authentication codes on your own device. Because of what it does, the most important thing this Policy has to say is about the thing it does not do: the secret keys behind your codes are never sent to us, never stored on our servers, and never leave your iPhone. By using the Service, you acknowledge and agree to the practices described in this Privacy Policy.

Interpretation and Definitions

Interpretation

Words that are capitalized have specific meanings outlined below. These definitions apply consistently throughout this Privacy Policy, whether the terms appear in singular or plural form.

Definitions

Affiliate -- Refers to any organization that controls, is controlled by, or is under shared control with a party. "Control" means owning at least 50% of shares, equity, or voting rights in such an entity.

Application -- Refers to Authenticator App, the two-factor authentication tool provided by Stratadev Studio Limited.

Company (also "We," "Us," or "Our") -- Means Stratadev Studio Limited. Under the GDPR, the Company is considered the Data Controller, responsible for decisions about how personal data is handled.

CCPA/CPRA -- refers to the California Consumer Privacy Act and its amendment, the California Privacy Rights Act of 2020.

Data Controller -- For GDPR purposes, this is the Company, as we determine how and why your Personal Data is processed.

Device -- Any device that can access the Service, such as an iPhone or iPad.

GDPR -- Refers to the EU's General Data Protection Regulation.

Personal Data -- Any information that identifies, relates to, or can be reasonably linked to an individual. Under GDPR, this includes any data tied to your identity.

Secret Key -- The string a service gives you when two-factor authentication is switched on, usually inside a QR code. Every code the Application shows is calculated from it.

Service -- Refers to the "Authenticator App".

Service Provider -- Any individual or organization that processes data on behalf of the Company. This includes third-party partners who assist with delivering, improving, or analyzing the Service. Under GDPR, Service Providers are referred to as Data Processors.

Usage Data -- Information collected automatically through use of the Service, such as device diagnostics or interaction patterns.

You -- The individual or entity accessing or using the Service. Under GDPR, you may also be referred to as the User or Data Subject.

Your Secret Keys Stay on Your Device

When you add an account, the Secret Key behind it is written to the protected storage area that iOS gives the Application and stays there. It is not transmitted to us, not copied to our servers, and not included in any diagnostic report. We have no way of reading it, and no way of producing a code on your behalf.

The codes themselves are arithmetic. The Application combines your Secret Key with the current time and shows the result; nothing needs to be sent anywhere for that to work, which is why the Application keeps generating codes with the phone in airplane mode.

There is no account to create, no email to register, and no cloud copy of your entries. The consequence is worth stating plainly: if the device is lost, wiped, or replaced, and you have kept no backup of your own, the entries cannot be restored by us or by anyone else.

Collecting and Using Your Personal Data

Types of Data We Collect

Personal Data

While using our Service, we may kindly request certain information that helps us support, communicate with, or improve your experience. This may include:

Usage Data

We automatically collect Usage Data to help us understand how the Service performs and how we can make it better for you.

This may include information such as:

When using the Service through an iOS device, additional details may be collected automatically, such as:

None of it carries a Secret Key, an account name you added, or a code the Application displayed.

Information Collected Through the Application

To add an account by scanning, the Application asks for camera access. The camera is read on the setup screen only, and only for long enough to find a QR code in the frame. No photograph is taken, no video is recorded, and the viewfinder is not transmitted anywhere. Where you would rather not use the camera at all, a Secret Key can be typed in by hand and the permission never comes up.

The Application may also offer to lock itself behind Face ID, Touch ID, or a passcode. That check is performed by iOS, which answers only yes or no; biometric data belongs to the system and is never exposed to the Application or to us.

You can adjust or revoke these permissions at any time through your iOS settings.

How We Use Your Personal Data

We process your Personal Data to:

We may share your information in circumstances such as:

Retention of Your Personal Data

We keep the limited data described above — your email if you contact support, and Usage Data — only for as long as it serves that purpose: typically for the length of an active support conversation, or a short diagnostic window after a crash or performance issue. We may hold certain records for longer where the law requires it, or where we need them to resolve a dispute or enforce our agreements.

Secret Keys are outside this arrangement entirely, since they are never in our possession to retain or to delete.

Transfer of Your Personal Data

Your data, including Personal Data, may be processed at the Company's headquarters or any other location where processing parties are located. This means your data may be transferred to and stored on computers outside your region, where privacy laws may differ.

By consenting to this Privacy Policy, you agree to this transfer. The Company will take all reasonable measures to ensure data security in line with this Privacy Policy. No transfer will occur unless adequate controls are in place.

Delete Your Personal Data

Any entry you added can be removed inside the Application, and removing the Application takes every entry with it. Both actions are immediate and final, and because nothing was ever mirrored on our side, there is nothing left for us to erase.

You can also contact us at help.info.stratadev@gmail.com to update or delete information you have sent us, such as support correspondence. However, we may retain data if legally obligated or permitted.

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. You will be notified before any transfer subject to a new Privacy Policy.

Law Enforcement

In specific circumstances, the Company may be required by law to disclose your Personal Data in response to requests from public authorities. A demand of that kind cannot reach your Secret Keys, because we do not hold them.

Other Legal Requirements

The Company may disclose your data in good faith if necessary to:

Security of Your Personal Data

We strive to protect your data, but no method of transmission or storage is entirely secure. While we apply industry-standard security, we cannot guarantee absolute protection.

Much of the security here rests with the device rather than with us. Keeping iOS current, using a device passcode, and switching on the Application's own lock does more to protect your codes than anything we can do from a distance.

Detailed Information on Data Processing

Our Service Providers may have access to your data for specific tasks, such as monitoring or analyzing Service usage.

Analytics

We use third-party analytics to track and analyze Service usage. These tools help us understand overall traffic patterns, general user behavior, and the performance of different features across the Service. Some analytics providers may also process this information as part of their broader platform ecosystem and may use aggregated, non-personal insights to support their own services.

You may opt out of certain data collection features through your device settings or by adjusting the privacy controls offered by your operating system. Additional information about how analytics partners handle data can typically be found in the privacy or policy sections provided by those service providers.

GDPR Privacy

Legal Basis for Processing Personal Data

The Company may process Personal Data under conditions such as:

Your Rights under GDPR

As a European resident, you have rights under this Privacy Policy, including:

Withdrawing consent for data use

To exercise these rights, contact us directly. We may verify your identity before responding.

Exercising of Your GDPR Data Protection Rights

You can exercise your rights of access, rectification, cancellation, and opposition by contacting us. Please note that we may ask you to verify your identity before responding to such requests. We will make every effort to respond to your request as soon as possible.

You have the right to lodge a complaint with a Data Protection Authority regarding our collection and use of your Personal Data. For more information, if you are in the European Economic Area (EEA), please contact your local data protection authority in the EEA.

CCPA/CPRA Privacy Notice (California Privacy Rights)

This section applies only to California residents and supplements our main Privacy Policy.

Personal Information We Collect

We only collect the following categories of personal information:

We do not collect other categories of personal information unless you voluntarily provide them.

How We Obtain Personal Information

Personal information may come from:

How We Use Personal Information

We may use the collected data for the following permitted business purposes:

If our data practices change, we will update this notice.

Your CCPA/CPRA Rights

California residents have the right to:

Exercising Your Rights

You or an authorized agent may contact us at help.info.stratadev@gmail.com or via our website to submit a request. Please provide enough information for identity verification.

Limiting the Use of Sensitive Personal Information

We do not collect sensitive personal information as defined under the CCPA/CPRA. If this changes, we will update this section accordingly.

Children's Privacy

The Application is not built for children under 13, and we do not knowingly gather personal information from that age group. Should you have reason to believe otherwise, write to us and the information will be removed.

Links to Other Websites

Our Service may contain links to sites we do not operate. If you follow a link to a third-party site, please review its privacy policy. We are not responsible for the privacy practices or content of external websites.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, the latest version will always be posted here. Please check this page occasionally to stay updated, as we do not send notifications about these changes.