Information Privacy Policy
This Privacy Policy explains how we respectfully collect, use, and protect your information when you interact with our Service. We also outline your privacy rights and how the law helps safeguard them.
The Service exists to generate two-factor authentication codes on your own device. Because of what it does, the most important thing this Policy has to say is about the thing it does not do: the secret keys behind your codes are never sent to us, never stored on our servers, and never leave your iPhone. By using the Service, you acknowledge and agree to the practices described in this Privacy Policy.
Interpretation and Definitions
Interpretation
Words that are capitalized have specific meanings outlined below. These definitions apply consistently throughout this Privacy Policy, whether the terms appear in singular or plural form.
Definitions
Affiliate -- Refers to any organization that controls, is controlled by, or is under shared control with a party. "Control" means owning at least 50% of shares, equity, or voting rights in such an entity.
Application -- Refers to Authenticator App, the two-factor authentication tool provided by Stratadev Studio Limited.
Company (also "We," "Us," or "Our") -- Means Stratadev Studio Limited. Under the GDPR, the Company is considered the Data Controller, responsible for decisions about how personal data is handled.
CCPA/CPRA -- refers to the California Consumer Privacy Act and its amendment, the California Privacy Rights Act of 2020.
Data Controller -- For GDPR purposes, this is the Company, as we determine how and why your Personal Data is processed.
Device -- Any device that can access the Service, such as an iPhone or iPad.
GDPR -- Refers to the EU's General Data Protection Regulation.
Personal Data -- Any information that identifies, relates to, or can be reasonably linked to an individual. Under GDPR, this includes any data tied to your identity.
Secret Key -- The string a service gives you when two-factor authentication is switched on, usually inside a QR code. Every code the Application shows is calculated from it.
Service -- Refers to the "Authenticator App".
Service Provider -- Any individual or organization that processes data on behalf of the Company. This includes third-party partners who assist with delivering, improving, or analyzing the Service. Under GDPR, Service Providers are referred to as Data Processors.
Usage Data -- Information collected automatically through use of the Service, such as device diagnostics or interaction patterns.
You -- The individual or entity accessing or using the Service. Under GDPR, you may also be referred to as the User or Data Subject.
Your Secret Keys Stay on Your Device
When you add an account, the Secret Key behind it is written to the protected storage area that iOS gives the Application and stays there. It is not transmitted to us, not copied to our servers, and not included in any diagnostic report. We have no way of reading it, and no way of producing a code on your behalf.
The codes themselves are arithmetic. The Application combines your Secret Key with the current time and shows the result; nothing needs to be sent anywhere for that to work, which is why the Application keeps generating codes with the phone in airplane mode.
There is no account to create, no email to register, and no cloud copy of your entries. The consequence is worth stating plainly: if the device is lost, wiped, or replaced, and you have kept no backup of your own, the entries cannot be restored by us or by anyone else.
Collecting and Using Your Personal Data
Types of Data We Collect
Personal Data
While using our Service, we may kindly request certain information that helps us support, communicate with, or improve your experience. This may include:
- Email address
- Usage Data
Usage Data
We automatically collect Usage Data to help us understand how the Service performs and how we can make it better for you.
This may include information such as:
- Your device's IP address
- Time and duration of your visits
- Screens you access
- Unique device identifiers
- Diagnostic and performance data
When using the Service through an iOS device, additional details may be collected automatically, such as:
- Device model
- Operating system version
- App activity logs and performance diagnostics
None of it carries a Secret Key, an account name you added, or a code the Application displayed.
Information Collected Through the Application
To add an account by scanning, the Application asks for camera access. The camera is read on the setup screen only, and only for long enough to find a QR code in the frame. No photograph is taken, no video is recorded, and the viewfinder is not transmitted anywhere. Where you would rather not use the camera at all, a Secret Key can be typed in by hand and the permission never comes up.
The Application may also offer to lock itself behind Face ID, Touch ID, or a passcode. That check is performed by iOS, which answers only yes or no; biometric data belongs to the system and is never exposed to the Application or to us.
You can adjust or revoke these permissions at any time through your iOS settings.
How We Use Your Personal Data
We process your Personal Data to:
- Provide, maintain, and enhance the Service
- Fulfil contractual or pre-contractual obligations
- Communicate important updates, feature information, or security notices
- Respond to your requests or support inquiries
- Analyze usage patterns to improve performance and user experience
- Manage business activities such as restructuring, mergers, or acquisition assessments, where your data may be part of the transferred assets
We may share your information in circumstances such as:
- Business transactions, including mergers, acquisitions, or financing evaluations
Retention of Your Personal Data
We keep the limited data described above — your email if you contact support, and Usage Data — only for as long as it serves that purpose: typically for the length of an active support conversation, or a short diagnostic window after a crash or performance issue. We may hold certain records for longer where the law requires it, or where we need them to resolve a dispute or enforce our agreements.
Secret Keys are outside this arrangement entirely, since they are never in our possession to retain or to delete.
Transfer of Your Personal Data
Your data, including Personal Data, may be processed at the Company's headquarters or any other location where processing parties are located. This means your data may be transferred to and stored on computers outside your region, where privacy laws may differ.
By consenting to this Privacy Policy, you agree to this transfer. The Company will take all reasonable measures to ensure data security in line with this Privacy Policy. No transfer will occur unless adequate controls are in place.
Delete Your Personal Data
Any entry you added can be removed inside the Application, and removing the Application takes every entry with it. Both actions are immediate and final, and because nothing was ever mirrored on our side, there is nothing left for us to erase.
You can also contact us at help.info.stratadev@gmail.com to update or delete information you have sent us, such as support correspondence. However, we may retain data if legally obligated or permitted.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. You will be notified before any transfer subject to a new Privacy Policy.
Law Enforcement
In specific circumstances, the Company may be required by law to disclose your Personal Data in response to requests from public authorities. A demand of that kind cannot reach your Secret Keys, because we do not hold them.
Other Legal Requirements
The Company may disclose your data in good faith if necessary to:
- Comply with legal obligations
- Protect the rights or property of the Company
- Prevent or investigate possible wrongdoing
- Protect the safety of Service users or the public
- Guard against legal liability
Security of Your Personal Data
We strive to protect your data, but no method of transmission or storage is entirely secure. While we apply industry-standard security, we cannot guarantee absolute protection.
Much of the security here rests with the device rather than with us. Keeping iOS current, using a device passcode, and switching on the Application's own lock does more to protect your codes than anything we can do from a distance.
Detailed Information on Data Processing
Our Service Providers may have access to your data for specific tasks, such as monitoring or analyzing Service usage.
Analytics
We use third-party analytics to track and analyze Service usage. These tools help us understand overall traffic patterns, general user behavior, and the performance of different features across the Service. Some analytics providers may also process this information as part of their broader platform ecosystem and may use aggregated, non-personal insights to support their own services.
You may opt out of certain data collection features through your device settings or by adjusting the privacy controls offered by your operating system. Additional information about how analytics partners handle data can typically be found in the privacy or policy sections provided by those service providers.
GDPR Privacy
Legal Basis for Processing Personal Data
The Company may process Personal Data under conditions such as:
- Consent provided by you
- Contractual obligations
- Legal requirements
- Vital interests protection
- Public interest tasks
- Legitimate business interests
Your Rights under GDPR
As a European resident, you have rights under this Privacy Policy, including:
- Accessing, correcting, or deleting your data
- Objecting to processing for legitimate interests
- Requesting data transfer
Withdrawing consent for data use
To exercise these rights, contact us directly. We may verify your identity before responding.
Exercising of Your GDPR Data Protection Rights
You can exercise your rights of access, rectification, cancellation, and opposition by contacting us. Please note that we may ask you to verify your identity before responding to such requests. We will make every effort to respond to your request as soon as possible.
You have the right to lodge a complaint with a Data Protection Authority regarding our collection and use of your Personal Data. For more information, if you are in the European Economic Area (EEA), please contact your local data protection authority in the EEA.
CCPA/CPRA Privacy Notice (California Privacy Rights)
This section applies only to California residents and supplements our main Privacy Policy.
Personal Information We Collect
We only collect the following categories of personal information:
- Identifiers: specifically, your email address.
- Internet or Network Activity: information about your interactions with the Service, including usage data and analytics.
We do not collect other categories of personal information unless you voluntarily provide them.
How We Obtain Personal Information
Personal information may come from:
- Your direct interactions with us, such as when you contact support or provide an email.
- Automatic collection, which occurs when you use the Service and certain technical data is gathered through analytics tools or similar technologies.
How We Use Personal Information
We may use the collected data for the following permitted business purposes:
- Operating, maintaining, and improving the Service
- Responding to inquiries and providing support
- Ensuring security and preventing misuse
- Complying with legal obligations and internal administrative needs
If our data practices change, we will update this notice.
Your CCPA/CPRA Rights
California residents have the right to:
- Notice: understand what we collect and why
- Access: request details about our data practices
- Correct: update inaccurate information
- Limit Use of Sensitive Data: not applicable, as we do not collect sensitive personal information
- Delete: request deletion of personal data unless exceptions apply
- Non-Discrimination: not be treated differently for exercising privacy rights
Exercising Your Rights
You or an authorized agent may contact us at help.info.stratadev@gmail.com or via our website to submit a request. Please provide enough information for identity verification.
Limiting the Use of Sensitive Personal Information
We do not collect sensitive personal information as defined under the CCPA/CPRA. If this changes, we will update this section accordingly.
Children's Privacy
The Application is not built for children under 13, and we do not knowingly gather personal information from that age group. Should you have reason to believe otherwise, write to us and the information will be removed.
Links to Other Websites
Our Service may contain links to sites we do not operate. If you follow a link to a third-party site, please review its privacy policy. We are not responsible for the privacy practices or content of external websites.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, the latest version will always be posted here. Please check this page occasionally to stay updated, as we do not send notifications about these changes.