Halo Authenticator Privacy Policy

Effective date: January 1, 2022

Halo Authenticator is a local-first TOTP authenticator app. It does not require an account, does not operate a backend server for TOTP data, and does not upload TOTP seeds or one-time codes. The app includes Google Mobile Ads SDK for advertising features.

Data stored on your device

The app stores TOTP seeds, issuer or service names, account labels, and display preferences locally on your device. TOTP seeds are encrypted on the device with Android Keystore. App data is excluded from Android backup and device transfer.

Permissions

Camera access is used only when you choose to scan a TOTP QR code. Photo or gallery access is used only when you choose an image to import a QR code. Internet and network state access are used by Google Mobile Ads SDK and advertising features.

Ads and Google Mobile Ads SDK

The app includes AdMob through Google Mobile Ads SDK for advertising features. According to Google Mobile Ads SDK disclosures, the SDK may automatically collect and share IP address, user product interactions such as app launches and taps, diagnostic information, and device or account identifiers such as the Android advertising ID and app set ID. These data may be used for advertising, analytics, and fraud prevention, and are encrypted in transit with TLS.

Data sharing and tracking

The app does not sell, share, or transmit your TOTP seeds, account labels, or one-time codes. Advertising-related data may be collected and shared by Google Mobile Ads SDK as described above and is subject to Google policies.

Deletion and retention

You can delete any authenticator entry inside the app. You can also uninstall the app to remove its local data from the device. Because the app does not run a server account, there is no remote account data to delete.

Children

The app is not directed to children and does not knowingly collect personal information from children.

Google Play Data safety summary

Changes

This policy may be updated when app behavior or legal requirements change. Material changes should be reflected in the app and on this hosted privacy policy page.

Contact

For privacy questions, contact the developer at vault@flowxmail.com.