Privacy Policy & Disclaimer
Last updated: May 21, 2026
The Simplified Chinese version of this document shall prevail in the event of any discrepancy.
Important Disclaimer
EasyAuth is a free, open-source 2FA tool provided without any warranties of any kind (including but not limited to fitness for purpose, security, or uninterrupted operation).
This app is a local 2FA code generator. By default, all data is stored only on your local device. If you choose to configure WebDAV or S3 cloud backup, encrypted backup files will be stored on the third-party server you specify. In all cases, the developer cannot access, recover, or manage your data, and assumes no responsibility for the availability, security, or data integrity of cloud storage services you configure.
You are solely responsible for safeguarding your backup password and backup files. The developer assumes no liability if 2FA accounts cannot be recovered due to forgotten backup passwords, device loss, backup file corruption, or cloud storage service failures.
You are responsible for ensuring the security and availability of your chosen cloud storage services (WebDAV, S3, etc.). The developer makes no guarantees regarding the stability, security, or data integrity of third-party services.
The backup encryption uses industry-standard algorithms (AES-256-GCM), but no encryption technology is absolutely secure. The developer assumes no liability for data breaches resulting from cryptographic vulnerabilities, key compromise, or force majeure events.
The developer shall not be liable for any direct, indirect, incidental, special, or consequential damages arising from the use or inability to use this app, including but not limited to account inaccessibility, data loss, business interruption, or any other commercial loss.
Overview
EasyAuth ("the App") is a local two-factor authentication (2FA) application. We take your privacy seriously. This document explains how the App handles your data.
By default, all data is stored only on your local device. You may optionally configure cloud backup (WebDAV/S3), with encrypted backup files stored on the third-party server you specify. In all cases, the developer does not collect, upload, or access any of your 2FA secrets, passwords, or account information.
Data We Do NOT Collect
The App does not collect any of the following:
- 2FA secrets (TOTP/HOTP Secret)
- Account names and issuer info
- Backup passwords
- Cloud storage credentials (WebDAV/S3 config)
- Any personally identifiable information
Locally Stored Data
Stored only on your device (encrypted via Android Keystore/iOS Keychain):
| Data Type | Storage | Purpose |
|---|---|---|
| 2FA Account Info | Device secure storage | Generate OTP codes |
| Backup Password (hash) | Device secure storage | Encrypt backup files |
| Cloud Storage Config | Device secure storage | User-initiated backup/restore |
| Language Preference | Device secure storage | Display language |
User-Initiated Transfer
Backup is triggered only by you. Encrypted data is sent via HTTPS to your configured WebDAV or S3 server, encrypted with AES-256-GCM. Only you hold the key.
The developer cannot access your backup data as we do not have your backup password.
Permissions
| Permission | Purpose |
|---|---|
| Camera | Scan QR codes to add 2FA accounts |
| Biometric | App lock via fingerprint/face recognition |
| Network | User-initiated backup/restore |
Third-Party Services
The current version integrates no third-party analytics, advertising SDKs, or data collection services. If future versions incorporate crash reporting tools (e.g. Firebase Crashlytics), they will be used solely to improve app stability, will not collect personal information, and will be disclosed in an updated version of this document.
Data Security
- Local data encrypted via Android Keystore
- Backup files encrypted with AES-256-GCM
- App lock (biometric auth)
- Screenshot protection (Android)
Children's Privacy
Not designed for children under 13.
Your Rights
You can at any time:
- Uninstall to delete all local data
- Manage encrypted backups on your own cloud storage
Policy Updates
This document may be updated with new versions of the App.
Contact Us
If you have questions: