Privacy Policy

Privacy Policy

Spot Auth is built to keep your authentication secrets on your device. We do not operate an account system or an analytics backend for the app.

Effective date: July 18, 2026

1. Overview

This Privacy Policy explains how Spot Auth (“the App”) handles information when you use the iOS application.

Spot Auth has no official application server of its own. We do not require you to create a Spot Auth account, and we do not sell your personal data.

2. Information stored on your device

Most information never leaves your device unless you explicitly use an optional feature that needs the network.

Authentication secrets

Your 2FA secret keys are encrypted with AES-256-GCM and stored only in the iOS Keychain. They are not written to SwiftData, UserDefaults, or app logs.

Account metadata

Service names, account labels, algorithm settings, sort order, brand colors, usage timestamps, and locally cached logos are stored on device (SwiftData / app storage).

Preferences

Settings such as grid column count, language, offline mode, lock behavior, and sync toggles are stored in UserDefaults on your device.

3. Information we do not collect

We do not collect advertising identifiers for tracking, do not embed third-party analytics or ad SDKs, and do not operate a Spot Auth cloud that receives your authenticator database by default.

4. Permissions and system features

  • Camera: scan QR codes to add accounts.
  • Face ID / Touch ID / Passcode: unlock the app and confirm sensitive actions locally via LocalAuthentication. We do not receive your biometric templates.
  • Photo library (system picker): optionally recognize QR codes from screenshots you select.
  • Clipboard: copy one-time codes so you can paste them elsewhere. iOS typically clears copied codes after about two minutes.

5. Optional network features

Some features use the internet only when you enable them or take an explicit action.

Service logos (Logo.dev)

If logo fetching is enabled, the App may request an icon using an inferred service domain. Verification codes and secrets are not sent. You can disable this feature; Offline Mode also turns it off.

iCloud sync (Pro, optional)

If you enable iCloud sync, an encrypted backup snapshot may be stored in your iCloud Drive under your Apple ID. Apple processes iCloud data under Apple’s privacy policy. Spot Auth does not operate a separate sync server for this feature.

WebDAV sync (Pro, optional)

If you configure WebDAV, encrypted sync data is sent to the server URL you provide. That server is controlled by you or your provider, not by Spot Auth.

App Store purchases

Pro unlocks are processed by Apple through StoreKit. We do not receive your full payment card details. Apple’s terms and privacy policy apply to the transaction.

Support email

If you email softspring@icloud.com, we receive the content of your message and your email address so we can reply.

6. Data retention

On-device data remains until you delete accounts, clear app data, or remove the App. Recently deleted entries may be kept locally for up to 7 days for recovery.

Encrypted sync files remain in your iCloud or WebDAV location until you delete them or turn off sync and remove those files.

Support emails are retained only as long as needed to handle your request.

7. Sharing

We do not sell personal information. Data may be processed by Apple (App Store / iCloud) or by a WebDAV provider you choose when you enable those features. Logo requests may be handled by Logo.dev when that option is on.

8. Children’s privacy

Spot Auth is a general-audience utility and is not directed at children under 13. We do not knowingly collect personal information from children through a Spot Auth server.

9. International processing

Because the App is local-first, your authenticator secrets are not uploaded to a Spot Auth-operated region. Optional services you enable (Apple iCloud, your WebDAV host, Logo.dev) may process data in the regions those providers use.

10. Your choices

  • Keep secrets on device only by leaving sync and logo fetching off.
  • Export or delete accounts from inside the App.
  • Disable camera, Face ID, or photo access in iOS Settings (some features will stop working).
  • Contact us to ask questions about this policy.

11. Changes

We may update this Privacy Policy from time to time. The effective date at the top of this page will change when we do. Continued use of the App after an update means you acknowledge the revised policy.

Contact

Need help or have a privacy question? Email us and we will respond as soon as we can.