Official Zero-Knowledge Privacy Policy

FlincByte Authenticator Privacy Policy

ProductFlincByte Authenticator
Package Identifiercom.flincbyte.authenticator
Effective DateSeptember 29, 2026
Architecture100% Offline / Zero-Cloud

1Zero-Knowledge Principle & Core Summary

FlincByte Authenticator is architected from the foundation on the principle of Zero-Knowledge Privacy. The application functions completely offline on your physical device. We do not collect, capture, store, transmit, analyze, share, or sell any personal data, analytics, device identifiers, or cryptographic secrets.

Because the application does not request network access permissions, it is technically impossible for the application to transmit data over the internet or communicate with external servers.

2Information We Do NOT Collect

No Personal Identifiers

We never collect names, email addresses, phone numbers, IP addresses, or location data.

No 2FA Secrets or Codes

Base32 keys, issuer titles, and generated OTP codes never leave local hardware storage.

Zero Third-Party SDKs

No analytics libraries, advertising frameworks, crash trackers, or telemetry endpoints exist in the app.

Zero Cloud Infrastructure

We operate no remote databases or sync servers for this application, eliminating central point of failure risks.

3Device Permissions & Explicit Purpose

FlincByte Authenticator requests only the absolute minimum permissions strictly necessary for user-initiated core features:

Camera (`android.permission.CAMERA`)

Optional

Used exclusively to scan standard 2FA QR codes (otpauth://totp/). The camera feed is processed in temporary volatile memory and is never recorded, stored, photographed, or transmitted.

Biometrics (`USE_BIOMETRIC` / `USE_FINGERPRINT`)

Optional

Used exclusively to authenticate the user for Biometric App Lock and sensitive secret key reveal actions. Biometric scanning and matching are performed by the device operating system; raw biometric templates are never accessible to the application.

Vibration (`android.permission.VIBRATE`)

Standard

Used to provide subtle tactile haptic feedback when copying authentication codes to the clipboard or confirming QR code imports.

Internet Access (`INTERNET`)

NOT REQUESTED

The app contains zero internet permission declarations in its Android Manifest. It is completely isolated from network interfaces.

4Data Storage, Encryption & Retention

  • Hardware Keystore Isolation: Account metadata and encrypted secrets reside strictly within your device's isolated application sandbox and Android Keystore with AES-256-GCM hardware encryption.
  • Backup Exclusion: The app enforces android:allowBackup="false" to prevent automatic unencrypted uploads to Google Drive or extraction via USB debugging tools.
  • Atomic Data Deletion: When you delete an account within the app, its record and cryptographic secret are permanently and immediately purged from device hardware storage.
  • Uninstallation: Uninstalling the application completely erases all application sandbox data and Keystore keys from your physical device.

5Security Inquiries & Contact

If you have any questions regarding this Privacy Policy or wish to report a security inquiry, please contact our security team:

Get FlincByte Authenticator

Available now on Google Play Store for Android.

GET IT ONGoogle Play