Privacy Policy
Effective October 10, 2026
The short version:
- Your codes, passwords and other items are stored on your device, not on our servers. We do not run a server that holds your data.
- If you turn on iCloud Sync, each item is encrypted on your device before it is uploaded to your private iCloud storage. Neither Apple nor we can read it.
- We do not show ads, use analytics, track you across apps or websites, or sell data.
- Subscription purchases are handled by Apple. Our subscription provider, RevenueCat, receives an anonymous ID and your purchase records so the app knows whether you have Premium.
This policy explains what information the 2FA Live app for iPhone, iPad and Apple Watch (the "App") handles, where it goes and what choices you have. "We", "us" and "our" refer to the developer of 2FA Live. If you have questions, email fengzy1024@outlook.com.
1. Information you store in the App
You can store two-factor account secrets, passwords, passkeys, payment card details, secure notes, Wi-Fi network details and folders in the App. We call these "your vault items".
- Where they are kept. Sensitive fields, such as two-factor secrets, passwords, card numbers, security codes, note contents and Wi-Fi passwords, are stored in the iOS Keychain with access limited to this device. Other details, such as account names and folder names, are stored in the App's local database on your device.
- Who can see them. Only you, on your device. We do not receive your vault items.
- Widgets and AutoFill. The App's widgets and its AutoFill extension read your vault items from shared storage on the same device so they can show codes or fill passwords. This data does not leave your device for this purpose.
- Apple Watch. If you use the Apple Watch app, your two-factor accounts are sent from your iPhone to your paired Apple Watch using Apple's WatchConnectivity framework and stored in the watch's Keychain.
- Passkeys. Passkey private keys are created inside your device's Secure Enclave. They cannot be exported, are never sent to us or to iCloud, and are not included in backups.
2. iCloud Sync (optional)
iCloud Sync is off until you turn it on. When it is on:
- Each vault item is encrypted on your device with AES-256-GCM before upload.
- The encryption key is generated on your device and stored in your iCloud Keychain, which Apple end-to-end encrypts. It is shared only with your own devices signed in to the same Apple ID.
- The encrypted items are stored in the private database of your iCloud account, using Apple's CloudKit service. They count toward your iCloud storage. Apple's handling of iCloud data is described in Apple's Privacy Policy.
- We cannot access your private iCloud database, and the data in it is unreadable without your key.
To delete synced data, turn off iCloud Sync in the App, then go to iOS Settings, tap your name, iCloud, Manage Account Storage, and delete the data for 2FA Live.
3. Encrypted backups
You can export a backup file. It is encrypted on your device with a key derived from a password you choose (PBKDF2 with SHA-256 and AES-256-GCM). You decide where the file goes, for example Files or AirDrop. We never receive your backup or its password, and we cannot open or recover it.
4. Password breach check
When you start a breach check, the App uses the Pwned Passwords service run by Have I Been Pwned. For each password, the App computes a SHA-1 hash on your device and sends only the first 5 characters of that hash. The service returns a list of matching hash endings, and the App compares them on your device. Your password and its full hash never leave your device. The request also asks the service to pad its responses so their size reveals nothing. Like any web request, it exposes your IP address to the service. See the Have I Been Pwned privacy policy.
Password health checks for weak, reused and old passwords run entirely on your device.
5. Subscriptions and purchases
Purchases are processed by Apple through your Apple ID. We do not receive your name, email address or payment details.
We use RevenueCat, Inc. to check whether you have an active subscription. To do this, the App sends RevenueCat:
- a random, anonymous identifier created by the App, which is not linked to your name or Apple ID;
- your App Store purchase and subscription records, such as product, purchase date and expiry date;
- technical details needed to handle the request, such as IP address, device model, operating system and App version, language and App Store country.
We use this information only to unlock Premium features, restore purchases and understand subscription totals. See the RevenueCat privacy policy.
RevenueCat processes this information on our behalf under a data processing agreement and must protect it to the same standard as this policy. Apart from the breach check described in section 4, we do not share information with any other third party, except where the law requires it.
6. Device permissions
| Permission | Why the App asks | What happens to the data |
|---|---|---|
| Camera | To scan QR codes when you add an account | Frames are read on your device and are not saved or sent anywhere |
| Photos (picker) | To read a QR code from a screenshot you select | Only the image you pick is read, on your device, and it is not saved |
| Face ID or Touch ID | To unlock the App and confirm AutoFill | Handled by iOS. The App only learns whether the check succeeded |
7. What we do not do
- We do not include advertising or advertising SDKs.
- We do not use analytics or tracking tools, and we do not track you across other companies' apps or websites.
- We do not sell or share personal information for advertising.
- We do not require you to create an account.
If you choose to share crash reports and analytics with app developers in iOS Settings, Apple may provide us with crash reports that do not identify you. We use them only to fix problems.
8. Support emails
If you email us, we receive your email address and whatever you include in your message. We use it only to reply and help you, and delete it when it is no longer needed. Please never send us your codes, passwords or backup passwords.
9. Retention and deletion
Your vault items stay on your device until you delete them or delete the App. Deleted items go to the trash for 30 days for Premium users, then are removed. Data in iCloud stays until you delete it as described in section 2. RevenueCat keeps purchase records for as long as needed to provide the service and meet legal obligations. To ask us to delete the RevenueCat records linked to your anonymous identifier, contact us.
10. Your rights
Depending on where you live, including the European Economic Area, the United Kingdom and California, you may have the right to access, correct, delete or move personal information, and to object to or limit its use. Because your vault items never reach us, you control them directly in the App. You can withdraw consent at any time: turn off iCloud Sync, stop using the breach check, or delete the App. For anything else, email fengzy1024@outlook.com and we will respond within 30 days. You may also complain to your local data protection authority.
11. Children
The App is not directed to children under 13, and we do not knowingly collect personal information from them.
12. Security
We protect your data with the iOS Keychain, on-device encryption, the Secure Enclave and optional app lock with Face ID, Touch ID or a PIN. No system is perfectly secure, so please keep your device passcode, Apple ID and backup password safe.
13. Changes to this policy
If we change this policy, we will update the effective date above. If a change affects how your information is handled in a significant way, we will tell you in the App before it takes effect.
14. Contact
Email fengzy1024@outlook.com.