Authenticator⁺ — Privacy Policy

Your codes stay on your device

Last updated: September 17, 2026

Authenticator⁺ ("we," "our," or "us") is a two-factor authentication (2FA) app operated by Pluriventures LLP. It generates the one-time verification codes (TOTP/HOTP) you use to sign in to other services, and it can also store your website passwords. This Privacy Policy explains what happens to your information when you use the app on iOS.

The short version: your 2FA secrets and passwords are never sent to us, and we operate no server that receives them. If you turn on iCloud sync, they travel only through your own iCloud, end-to-end encrypted. By using Authenticator⁺, you agree to the practices described below. If you do not agree, please do not use the app.

1. Your 2FA Secrets and Passwords Stay on Your Device

When you add an account (by scanning a QR code, entering a setup key, or importing from another authenticator), the secret key for that account is stored in the iOS Keychain on your device, protected so that it is available only after you have unlocked your device and never leaves it in an unencrypted device backup.

The app can also store your website logins in its Passwords tab, which includes a password generator. Like your 2FA secrets, saved passwords are kept in the iOS Keychain on your device.

We do not operate a server that stores your accounts, and your secrets, the codes generated from them, and your saved passwords are never transmitted to us or to any third party. Code generation happens entirely on your device, offline. We never log a secret, a code, or a setup ("otpauth") URI.

2. Information We Do Not Collect

3. Analytics and Crash Diagnostics

To understand how the app is used and to fix crashes, Authenticator⁺ uses privacy-preserving analytics and error monitoring. When you first open the app, it generates a random, anonymous device identifier that is not linked to your name, email, or any personal identity. This data is not used to track you and is never used for advertising.

  • PostHog: product analytics (which screens are used, whether a subscription was started). PostHog derives an approximate location (city and country) from your IP address for analytics. Any session replay masks all text and all images, so your accounts, secrets, and codes are never captured. PostHog Privacy Policy
  • Sentry: crash and error reporting, plus sampled performance data, so we can find and fix bugs and slow screens. Reports contain technical diagnostics, not your 2FA codes or passwords. Sentry Privacy Policy

These events describe how the app behaves, never the contents of your vault.

4. Subscriptions and Purchases

If you subscribe to the paid plan, your purchase is processed through Apple (App Store). We use RevenueCat to verify your subscription status via an anonymous RevenueCat user ID. We do not receive or store your payment details, credit card number, or billing address — all payment processing is handled entirely by Apple and RevenueCat. RevenueCat Privacy Policy

5. Encrypted Backups

Authenticator⁺ can create an optional, encrypted backup of your accounts so you can move them to a new device. Backups are encrypted on your device with a password that you choose, using AES-256-GCM. Only the encrypted file ever leaves the app, and only when you choose to save or share it — for example to your own iCloud Drive or Files.

We never receive your backup file or your backup password, and we cannot read your backup or recover your password if you lose it. Keep your backup password somewhere safe.

6. iCloud Sync, AutoFill and Widget

iCloud sync (optional, Pro)

If you turn on iCloud sync, your codes, passwords and folders sync between your own devices through your own iCloud account. The file stored in iCloud Drive is encrypted with AES-256-GCM using a random 32-byte key. That key travels only through iCloud Keychain, which is end-to-end encrypted, so neither Apple nor we can read the file. We never receive it.

AutoFill (Pro)

The iOS AutoFill extension offers your saved passwords, and on iOS 18 and later your 2FA codes, inside Safari and other apps. It reads them from the Keychain entirely on your device. Nothing is sent to us.

Home Screen widget (Pro)

The widget shows your codes by reading them from the Keychain on your device. Nothing is sent to us.

7. Camera and Photos

The app requests camera access only so you can scan a 2FA QR code when adding an account. The camera is used on-device to read the code; images are not stored and are never transmitted. You can also add accounts by typing a setup key instead.

You can also pick a screenshot of a QR code from your Photos. The picked image is read on your device to find the QR code, then discarded. It is never stored or transmitted.

8. Face ID / Passcode

You can optionally require Face ID (or your device passcode) to open the app. This uses Apple's on-device authentication; the result is a simple pass/fail on your device. We never receive your biometric data — it never leaves the Secure Enclave on your iPhone.

9. Data Retention

Because we do not operate a server that stores your accounts, there is no personal vault held by us to retain or delete. Your accounts live on your device; if you uninstall the app, they are removed from your device. If you used iCloud sync, an encrypted copy stays in your own iCloud storage after you turn sync off or delete the app. You can remove it from your iCloud storage settings on your iPhone. Anonymous analytics and crash events are retained by our processors for a limited period and then purged.

10. Children's Privacy

Authenticator⁺ is not directed at children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect information from children. If you have concerns, please contact us at the email below.

11. Your Rights

Depending on your jurisdiction, you may have rights regarding your data, including the right to access, correct, or delete information. Because we collect only an anonymous device identifier and do not hold your 2FA data, exercising these rights is limited to that anonymous analytics data. If you have questions or requests, please reach out to us.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: contact@pluriventures.com

Entity: Pluriventures LLP