FlincByte Authenticator Privacy Policy
1Zero-Knowledge Principle & Core Summary
FlincByte Authenticator is architected from the foundation on the principle of Zero-Knowledge Privacy. The application functions completely offline on your physical device. We do not collect, capture, store, transmit, analyze, share, or sell any personal data, analytics, device identifiers, or cryptographic secrets.
Because the application does not request network access permissions, it is technically impossible for the application to transmit data over the internet or communicate with external servers.
2Information We Do NOT Collect
No Personal Identifiers
We never collect names, email addresses, phone numbers, IP addresses, or location data.
No 2FA Secrets or Codes
Base32 keys, issuer titles, and generated OTP codes never leave local hardware storage.
Zero Third-Party SDKs
No analytics libraries, advertising frameworks, crash trackers, or telemetry endpoints exist in the app.
Zero Cloud Infrastructure
We operate no remote databases or sync servers for this application, eliminating central point of failure risks.
3Device Permissions & Explicit Purpose
FlincByte Authenticator requests only the absolute minimum permissions strictly necessary for user-initiated core features:
Camera (`android.permission.CAMERA`)
OptionalUsed exclusively to scan standard 2FA QR codes (otpauth://totp/). The camera feed is processed in temporary volatile memory and is never recorded, stored, photographed, or transmitted.
Biometrics (`USE_BIOMETRIC` / `USE_FINGERPRINT`)
OptionalUsed exclusively to authenticate the user for Biometric App Lock and sensitive secret key reveal actions. Biometric scanning and matching are performed by the device operating system; raw biometric templates are never accessible to the application.
Vibration (`android.permission.VIBRATE`)
StandardUsed to provide subtle tactile haptic feedback when copying authentication codes to the clipboard or confirming QR code imports.
Internet Access (`INTERNET`)
NOT REQUESTEDThe app contains zero internet permission declarations in its Android Manifest. It is completely isolated from network interfaces.
4Data Storage, Encryption & Retention
- Hardware Keystore Isolation: Account metadata and encrypted secrets reside strictly within your device's isolated application sandbox and Android Keystore with AES-256-GCM hardware encryption.
- Backup Exclusion: The app enforces
android:allowBackup="false"to prevent automatic unencrypted uploads to Google Drive or extraction via USB debugging tools. - Atomic Data Deletion: When you delete an account within the app, its record and cryptographic secret are permanently and immediately purged from device hardware storage.
- Uninstallation: Uninstalling the application completely erases all application sandbox data and Keystore keys from your physical device.
5Security Inquiries & Contact
If you have any questions regarding this Privacy Policy or wish to report a security inquiry, please contact our security team:
Get FlincByte Authenticator
Available now on Google Play Store for Android.