In short: Authly is a two-factor authentication (2FA) code generator that runs entirely on your device. It does not have a server, does not create an account for you, and does not send your data anywhere. Everything you enter — account names, issuers, and secret keys — stays on your device unless you explicitly choose to export or share a backup yourself.
This Privacy Policy explains how Authly ("the App", "we", "our") handles information when you use it on Android, iOS, macOS, Windows, or Linux. Authly is developed and maintained by an independent developer. If you have questions, contact us at editor.techreels@gmail.com.
Authly does not use any analytics, advertising, or crash-reporting service. It contains no network code — the app does not make internet requests of any kind. As a result, we never receive, see, or store:
Everything Authly needs to function is stored locally, in your device's app-private storage, using standard on-device mechanisms:
| Data | Stored using | Purpose |
|---|---|---|
| 2FA accounts (issuer, name, secret key, category) | Local on-device database (Hive) | Generating your one-time codes |
| App PIN / lock preference | Encrypted secure storage provided by your OS (Android Keystore / iOS Keychain) | Optional App Lock feature |
| App settings (theme, language, sort order) | Local device preferences storage | Remembering your app configuration |
| Automatic local backups | A private folder inside the app's own document directory on your device | Letting you recover data if the app is reinstalled on the same device |
None of this data leaves your device automatically. It is not synced to any cloud service by Authly, and we have no access to it.
| Permission | Why it's requested |
|---|---|
| Camera | To scan a QR code when you add a new 2FA account. The camera feed is processed on-device only to read the QR code — no image or video is stored or transmitted. |
| Biometrics (Face ID / fingerprint) or device PIN | Optional App Lock feature. Authentication happens through your operating system; Authly never sees or stores your biometric data — it only receives a yes/no result from the OS. |
Authly lets you export your accounts to a JSON backup file, and optionally share that file (for example, by AirDrop, email, or saving it to cloud storage) using your device's native share sheet. This only happens when you actively choose to export or share — Authly does not do this automatically or in the background, and we do not receive a copy. Once you share an exported file, its handling is governed by whichever app or service you shared it to, not by this policy.
You can also import a previously exported backup file back into Authly, using your device's file picker.
Your data stays on your device for as long as Authly is installed. You can delete individual accounts or categories at any time from within the app. Uninstalling Authly removes the app's local database, secure storage entries, and local backup files from your device, subject to your operating system's normal app-uninstall behavior. Any backup files you've separately exported or shared outside the app (e.g. saved to cloud storage) are not affected by uninstalling Authly, and must be deleted separately by you.
Authly is not directed at children under 13, and we do not knowingly collect personal information from anyone, including children, because the app does not collect personal information from any user in the first place.
Because Authly does not transmit or store your data outside your own device, there is no remote copy of your data for us to access, correct, export, or delete on your behalf — you already have full, direct control over it within the app and your device's file system. If you have questions about how the app handles data on your device, contact us using the details below.
If this policy changes — for example, if a future version of Authly adds an optional cloud sync feature — we will update this page and revise the "Last updated" date above. Material changes affecting how your data is handled will be described here before they take effect in a new app version.
Questions about this policy or the app's data practices can be sent to editor.techreels@gmail.com.