đź”’

Privacy Policy

Your privacy is our absolute priority. Learn how we protect your data with zero-knowledge encryption.

Last Updated: July 23, 2026

MFA Authenticator - Secure 2FA Privacy Policy

Who this policy applies to: This Privacy Policy applies to the mobile application "MFA Authenticator - Secure 2FA" (package name: com.twofa.authenticator.vault), published on Google Play by the developer star sevices ("we," "us," "our"). In this policy, the application is referred to as "MFA Authenticator," "the App," or "our Service."

At star sevices, privacy is not just a feature—it's our fundamental commitment to you. This Privacy Policy explains how we collect, use, protect, and handle your information when you use our 2FA authenticator and password manager application. By using MFA Authenticator, you agree to the practices described in this policy.

Our Privacy Promise: MFA Authenticator is built on a zero-knowledge architecture. This means we can never access, read, or decrypt your passwords, 2FA codes, vault contents, or any other sensitive data. Your master password never leaves your device, all encryption happens locally on your device, and even we cannot decrypt your data. Your privacy is absolute and non-negotiable.

1. Our Zero-Knowledge Architecture

1.1 What Zero-Knowledge Means

MFA Authenticator uses zero-knowledge encryption, which means:

  • Your Master Password Never Leaves Your Device: Your master password is never transmitted to our servers or stored anywhere except on your local device in an encrypted format.
  • Local Encryption Only: All data encryption and decryption happens exclusively on your device using your master password as the encryption key.
  • We Cannot Access Your Data: Even if compelled by law, we cannot provide access to your encrypted data because we do not have the ability to decrypt it.
  • No Backdoors: We do not build or maintain any backdoors into your encrypted data. There is no "master key" that can unlock your vault.
  • Cloud Storage is Encrypted: If you enable cloud sync, only your encrypted data is transmitted and stored on our servers. The encryption keys never leave your device.

1.2 How It Works Technically

When you create your MFA Authenticator account, your master password is used to generate encryption keys through a process called key derivation using PBKDF2 with SHA-256. These keys are used to encrypt all your data with AES-256 encryption before it leaves your device. Your encrypted data can then be safely stored locally or synced to the cloud, but without your master password, the data is completely unreadable—even to us.

2. Information We Collect

2.1 Information You Provide and We Cannot Access

The following information is stored encrypted and we cannot access it:

  • Master Password: Never transmitted or stored on our servers (stored only on your device in encrypted form)
  • 2FA Codes and Secrets: TOTP secrets and generated codes are encrypted and inaccessible to us
  • Passwords: All passwords stored in the password manager are encrypted locally before storage
  • Vault Contents: Files, photos, documents, notes, and any other data stored in your secure vault
  • Account Details: Usernames, website URLs, notes, and metadata associated with your saved accounts
  • Custom Categories and Tags: Any organizational structure you create is encrypted

2.2 Minimal Technical Information We Collect

To provide and improve our Service, we collect very limited technical information that does not compromise your privacy:

  • Email Address (Optional): Required only if you choose to enable cloud sync or account recovery options. We do not require an email address for local-only usage.
  • Device Information: Operating system version, device model, and App version (for compatibility and bug fixing purposes only)
  • Crash Reports: Anonymous crash logs that help us identify and fix technical issues. These do not contain any of your encrypted data.
  • Encrypted Data Sync Metadata: When you enable cloud sync, we store metadata such as sync timestamps and data size (but not the contents of your data)
  • Advertising Identifiers: Your device's advertising ID (Google Advertising ID on Android, IDFA on iOS where you grant permission) is collected by our advertising partner, Google AdMob, to serve and measure ads in the free version of the App
  • Analytics and Diagnostics Data: Through Google Firebase (Google Analytics for Firebase and Firebase Crashlytics), we collect app usage data (such as screens viewed, feature interactions, and session information), device identifiers, IP address, approximate location derived from IP address, crash logs, and performance data

2.3 Information We Explicitly Do NOT Collect

MFA Authenticator does NOT collect:

  • The contents of your encrypted vault, passwords, or 2FA secrets (these are end-to-end encrypted and inaccessible to us and to our advertising and analytics partners)
  • Precise (GPS) location data
  • Contacts or address book information
  • Social media connections
  • Information about which specific services you use 2FA for
  • Password strength or patterns
  • Photos, files, or messages outside the App

Important distinction: The advertising and analytics data described in Section 2.2 relates only to general app usage and your device. It never includes your encrypted vault contents, passwords, 2FA secrets, or master password.

3. How We Use Your Information

3.1 Core Functionality

The minimal information we collect is used exclusively for:

  • Providing the Service: Storing your encrypted data and enabling cloud sync if you choose to enable it
  • Account Management: Managing your optional account if you create one for cloud sync
  • Security: Protecting your account from unauthorized access and detecting unusual activity
  • Technical Support: Responding to your support requests and troubleshooting technical issues
  • Service Improvements: Fixing bugs and improving app performance based on crash reports and aggregate analytics
  • Advertising: Displaying advertisements in the free version of the App through Google AdMob, which may use your advertising identifier to serve personalized or non-personalized ads depending on your consent choices and device settings
  • Analytics: Understanding how the App is used in aggregate (via Google Analytics for Firebase) so we can improve features and user experience

3.2 What We Never Do With Your Information

We will never:

  • Sell your personal information for money
  • Attempt to decrypt or access your encrypted vault data, passwords, or 2FA secrets
  • Share your encrypted vault contents with anyone, including our advertising and analytics partners
  • Use the contents of your vault for advertising, profiling, or any other purpose

Please note that our advertising partner (Google AdMob) may use device identifiers to serve personalized ads and measure ad performance, which can involve activity across other apps and websites. You can limit this as described in Section 6.3 below.

4. Data Storage and Security

4.1 Local Storage

By default, all your data is stored locally on your device in an encrypted database. The encryption key is derived from your master password, which means your data cannot be accessed without your master password—even if someone gains physical access to your device.

4.2 Cloud Sync (Optional)

If you enable cloud sync:

  • Your encrypted data is transmitted securely over HTTPS/TLS to our servers
  • Only the encrypted data is stored on our servers—we never receive unencrypted data
  • Your encryption keys remain on your device and are never transmitted
  • We use industry-leading cloud infrastructure (AWS/Google Cloud) with enterprise-grade security
  • Data is replicated across multiple secure data centers for reliability
  • You can disable cloud sync at any time and delete all cloud-stored data

4.3 Encryption Standards

MFA Authenticator uses the following industry-standard encryption:

  • AES-256: Military-grade encryption for all stored data
  • PBKDF2-SHA256: Key derivation function with 100,000+ iterations
  • TLS 1.3: Latest secure transport protocol for all network communications
  • RSA-2048: For secure key exchange when applicable
  • Argon2: Modern password hashing algorithm for master password storage on device

4.4 Data Retention

  • Local Data: Retained on your device until you delete the app or manually clear data
  • Cloud Data: Retained until you disable cloud sync or delete your account
  • Crash Reports: Retained for up to 90 days for debugging purposes, then automatically deleted
  • Advertising and Analytics Data: Retained by Google (AdMob and Firebase) in accordance with Google's data retention policies; analytics identifiers are reset or deleted per Google's published retention controls
  • Email Address: Retained until you delete your account
  • Deleted Accounts: All data associated with deleted accounts is permanently removed within 30 days

5. Biometric Authentication

MFA Authenticator supports biometric authentication (fingerprint and face unlock) for convenient access to your vault. Important details about biometric security:

  • Biometric data never leaves your device and is never transmitted to our servers
  • We use Apple's and Google's secure biometric APIs (such as Android's BiometricPrompt), which keep biometric data in secure hardware enclaves
  • We do not store, collect, or have access to your biometric information
  • Biometric authentication simply provides an alternative to entering your master password
  • Your master password remains the primary authentication method

6. Third-Party Services

6.1 Services We Use

MFA Authenticator integrates with the following third-party services:

  • Google AdMob (Advertising): Displays advertisements in the free version of the App. AdMob may collect and process your device's advertising identifier, IP address, approximate location derived from IP, and ad interaction data to serve and measure ads. See Google's Privacy Policy and AdMob's ad technology partners.
  • Google Analytics for Firebase (Analytics): Collects app usage and interaction data, device information, and identifiers to help us understand how the App is used in aggregate. See Firebase Privacy and Security.
  • Firebase Crashlytics (Diagnostics): Collects crash logs, stack traces, and device state at the time of a crash to help us fix bugs.
  • Cloud Storage (AWS/Google Cloud): For optional encrypted data sync. These providers only receive encrypted data.
  • App Store Services: Apple App Store and Google Play Store for app distribution and in-app purchases.

What third parties never receive: None of these services receive your master password, vault contents, stored passwords, or 2FA secrets. That data is encrypted on your device with keys only you possess.

6.2 Data Sharing with Third Parties

We share the following categories of data with the third-party services listed above, solely for the purposes described:

  • Device or other identifiers (advertising ID, app instance ID) — shared with Google AdMob and Firebase for advertising, analytics, and app functionality
  • App interaction data (screens viewed, features used, session data) — shared with Firebase for analytics
  • Crash logs and diagnostics — shared with Firebase Crashlytics
  • Approximate location (derived from IP address, not GPS) — processed by AdMob and Firebase

6.3 Your Advertising Choices

You can limit ad personalization and tracking at any time:

  • Android: Settings → Google → Ads → "Delete advertising ID" or "Opt out of Ads Personalization"
  • iOS: Settings → Privacy & Security → Tracking → disable "Allow Apps to Request to Track"; and Settings → Privacy & Security → Apple Advertising
  • In regions requiring consent (e.g., EEA/UK): You will be shown a consent prompt before personalized ads are served, and you can change your choice in the App's settings

7. Your Privacy Rights and Controls

7.1 Access and Control

You have complete control over your data:

  • Export Your Data: Export all your vault data in encrypted or unencrypted format at any time
  • Delete Your Data: Delete individual items, clear entire categories, or delete your entire vault
  • Disable Cloud Sync: Stop cloud syncing and delete all cloud-stored data
  • Delete Your Account: Permanently delete your account and all associated data from our servers
  • Request Information: Contact us to request information about what data we have (minimal technical data only)

7.2 Account Deletion

To delete your account and all associated data:

  1. Open MFA Authenticator and go to Settings → Account
  2. Select "Delete Account"
  3. Confirm deletion by entering your master password
  4. All cloud-stored data will be permanently deleted within 30 days
  5. Local data on your device will remain until you uninstall the app

8. Children's Privacy

MFA Authenticator is not intended for use by individuals under the age of 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at immajnualex@gmail.com, and we will promptly delete such information.

9. International Data Transfers

If you use cloud sync, your encrypted data may be transferred to and stored on servers in different countries where our cloud infrastructure providers operate. Because your data is encrypted with keys that only you possess, international transfer does not pose a privacy risk—your data remains unreadable regardless of where it's stored.

We implement appropriate safeguards for international transfers, including:

  • Standard contractual clauses with our cloud providers
  • End-to-end encryption that makes data location irrelevant to privacy
  • Compliance with GDPR, CCPA, and other privacy regulations

10. California Privacy Rights (CCPA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request disclosure of what personal information we collect (email address and minimal technical data only)
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out of Sale/Sharing: We do not sell personal information for money. However, the use of advertising identifiers by Google AdMob for personalized advertising may be considered "sharing" for cross-context behavioral advertising under the CCPA/CPRA. You may opt out via your device settings (see Section 6.3) or by contacting us
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

To exercise your CCPA rights, contact us at immajnualex@gmail.com with "CCPA Request" in the subject line.

11. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

  • Legal Basis for Processing: We process minimal data based on:
    • Your consent (for optional cloud sync and for personalized advertising in regions where consent is required)
    • Performance of our contract with you (providing the Service)
    • Legitimate interests (security, service improvement, crash diagnostics, and non-personalized advertising where permitted)
  • Right of Access: Request a copy of your data (email and minimal technical metadata)
  • Right to Rectification: Correct inaccurate information
  • Right to Erasure: Request deletion of your data
  • Right to Restrict Processing: Limit how we process your data
  • Right to Data Portability: Export your data in a portable format
  • Right to Object: Object to certain types of data processing
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

Contact us at immajnualex@gmail.com with "GDPR Request" in the subject line to exercise these rights.

12. Security Measures

In addition to zero-knowledge encryption, we implement comprehensive security measures:

  • Secure Infrastructure: Enterprise-grade cloud infrastructure with physical and digital security
  • Regular Security Audits: Periodic third-party security audits of our infrastructure and code
  • Secure Development: Security-first development practices and code review processes
  • Incident Response: Rapid response procedures for any security incidents
  • Employee Access Controls: Strict limits on employee access to any systems (employees cannot access encrypted user data)
  • Penetration Testing: Regular testing to identify and fix vulnerabilities

13. Data Breach Notification

In the unlikely event of a data breach affecting our systems, we commit to:

  • Promptly investigate and assess the scope of the breach
  • Notify affected users within 72 hours of discovery
  • Report the breach to relevant authorities as required by law
  • Provide detailed information about what data may have been affected
  • Take immediate steps to secure systems and prevent future breaches

Important Note: Because of our zero-knowledge architecture, even in the event of a server breach, your encrypted data would remain completely secure and unreadable without your master password.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make changes:

  • We will update the "Last Updated" date at the top of this policy
  • For material changes, we will notify you via email or in-app notification
  • You will have the opportunity to review changes before they take effect
  • Continued use of MFA Authenticator after changes are posted constitutes acceptance

We will never make changes that compromise our zero-knowledge architecture or reduce your privacy protections without explicit consent.

15. Master Password Recovery

Critical Information About Master Password Loss:

Due to our zero-knowledge architecture, we cannot recover, reset, or provide access to your account if you forget your master password. This is a security feature, not a limitation. If you lose your master password, you will permanently lose access to your encrypted data.

We strongly recommend:

  • Choose a strong but memorable master password
  • Write down your master password and store it in a secure physical location
  • Set up account recovery options in the app (recovery kit, trusted contacts)
  • Never share your master password with anyone
  • Do not store your master password in plain text on your device

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your privacy rights, please contact us:

Developer: star sevices

App: MFA Authenticator - Secure 2FA (com.twofa.authenticator.vault)

Email: immajnualex@gmail.com

Subject Line: Privacy Inquiry - MFA Authenticator

Response Time: We aim to respond to all privacy inquiries within 48 hours

For data subject requests (access, deletion, correction, portability), please include:

  • Your email address associated with your account (if applicable)
  • Detailed description of your request
  • Device information to help us locate any relevant technical data
  • Your country/region of residence

17. Commitment to Privacy

Our Unwavering Promise: At star sevices, we believe privacy is a fundamental human right. We've built the App around protecting your sensitive data with zero-knowledge encryption. The free version of the App is supported by advertising, and premium subscriptions fund ongoing development—but your encrypted vault contents are never part of that equation and can never be accessed by us or by any advertising partner. Your trust is our most valuable asset, and we are committed to earning and maintaining that trust every day.

Key Principles:

  • Zero-knowledge architecture ensures we can never access your vault data, passwords, or 2FA secrets
  • Advertising and analytics data is strictly separated from your encrypted vault—partners never see your sensitive data
  • We never sell your personal information
  • Transparent about what data we collect and why
  • Your data is yours—export or delete it anytime
  • Regular security audits and updates
  • Compliance with all major privacy regulations (GDPR, CCPA, etc.)

Thank you for trusting MFA Authenticator with your security and privacy.