Privacy Policy
This Privacy Policy explains what data the Keythentic Android app ("Keythentic," "the app," "we," "us") touches, how it's protected, and what we can and cannot see. We've written it in plain language on purpose — if anything here is unclear, contact us and we'll clarify or fix it.
The short version
Keythentic is designed so that your vault — your two-factor codes, saved passwords, cards, notes, and passkeys — is encrypted on your device before it is ever written to storage or sent anywhere. It is locked with a master password that only you know. We do not have access to your master password or to the contents of your vault, whether it stays only on your device or you choose to back it up.
What data the app handles, and where it goes
Your vault (TOTP/HOTP secrets, passwords, cards, notes, passkeys)
Everything you store in Keythentic — authenticator secrets, saved logins, credit card details, secure notes, and passkeys — is encrypted on your device using a key derived from your master password before it is written to local storage. This encryption happens entirely on your phone. We never receive this data in a readable form, because we don't operate a server that your vault is sent to in the first place.
Your master password
Your master password is never transmitted anywhere and is never stored, by the app or by us, in a form that could be reversed back into the password. If you forget it, we have no way to recover it or your vault for you — see the Security page for why that's a deliberate design choice, not an oversight.
Optional Google Drive backup
If you turn on backup, Keythentic uploads your vault file — already encrypted, exactly as described above —
to a private, app-specific storage area of your own Google Drive account (Google's appDataFolder).
This area is not visible in your regular Google Drive file browser and is not accessible to other apps. The
file goes to your Google Drive, not to a server we operate. We never see the contents of this backup, and we
cannot decrypt it — only your master password can. You can also export an encrypted backup file locally,
entirely independent of Google, as a backup option that doesn't rely on any third party.
Biometric unlock
If you enable fingerprint or face unlock, that authentication is handled entirely by your device's own operating system and secure hardware via the Android Keystore. Your biometric data is processed and stored on your device by Android itself — it is never transmitted to Keythentic, and we never see it or store it anywhere.
Acting as an Autofill provider and passkey (Credential Manager) provider
If you choose to set Keythentic as your Android Autofill service, or as a Credential Manager passkey provider, Android grants the app the ability to read relevant on-screen fields of whatever app or website you're filling into (so it can offer a saved credential or a new suggested password), and to handle passkey creation/sign-in requests on your behalf. This access is entirely local to your device, is used only to provide the autofill/passkey functionality you asked for, is governed by Android's own permission system, and can be turned off at any time in your device's Settings. It does not involve sending this data to us.
Contact form messages (this website)
If you use the contact form on this website, we store the name, email address, and message you submit in our database so we can respond to you, and we may attempt to send ourselves an email notification of your message. We use this information only to respond to your inquiry.
Standard web server logs
Like most websites, our web server automatically logs basic technical information for security and operational purposes (such as IP address, browser user-agent, and request timestamps) when you visit keythentic.com. We don't use this for tracking or advertising, and this site does not use third-party analytics or advertising trackers.
What we don't do
- We do not sell your data.
- We do not share your vault contents or personal information with third parties for marketing or advertising purposes.
- We do not have a mechanism to decrypt your vault, with or without your cooperation — the encryption is designed specifically so that we can't.
- We do not run advertising or third-party analytics trackers on this website.
Deleting your data
Because Keythentic has no server-side account system, there's no "delete my account" request to send us — your data lives on your device and, optionally, in your own Google Drive. See our dedicated Data & Account Deletion page for exact steps.
Children's privacy
Keythentic is not directed at children, and we do not knowingly collect personal information from children.
Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date at the top of this page. We encourage you to review it periodically.
Contact
Questions about this policy or how your data is handled? Reach out through our contact form — we read every message.