Privacy Policy
Effective Date: August 19, 2026 | Last Updated: August 19, 2026
This Privacy Policy explains how GZ Medi Group (HK) Company Limited ("we", "us", "our") collects, uses, stores
and protects your information when you use the Authenticator App: 2FA Auth mobile application ("the App"). This
policy is intended to comply with applicable U.S. privacy laws, including CCPA/CPRA, COPPA, FTC privacy
guidelines and the Apple App Store Review Guidelines.
Important Notice: Authenticator App: 2FA Auth is designed as a local-first security utility.
Your 2FA account names, secret keys, one-time passwords, app lock settings, backup codes and related
authenticator data are generally processed and stored on your device. We do not sell your personal information
or use your authentication data for advertising.
Please read this policy carefully before using the App. By continuing to use the App, you confirm that you have
read and understood this policy.
1. Information We Collect and Use
We process information only in line with the principles of lawfulness, fairness, transparency and necessity.
1.1 Core Authentication Data (On-Device First)
- 2FA accounts and secret keys: Account labels, issuer names, secret keys, one-time password
records, backup codes and related authenticator data you add to the App are generally processed and stored
locally on your device.
- App lock and security settings: Passcode settings, Face ID/Touch ID preferences, auto-lock
settings, export options and similar security settings may be stored locally to provide App features.
- Time-based codes: The App generates one-time passwords using locally stored secret keys and
the current device time. Accurate device time is important for correct code generation.
1.2 System Permissions
We may request the following permissions to deliver features. You may withdraw or change permissions at any time
in your device settings:
- Camera: for scanning QR codes to add 2FA accounts.
- Photos: optional, for importing QR codes or setup images from your photo library.
- Face ID / Touch ID: optional, for unlocking the App through Apple's local biometric
authentication framework. We do not collect or store biometric data.
- Network: for Firebase Analytics, App Store purchase processing, Adapty subscription
management, crash diagnostics, customer support and security-related operations.
- Notifications: optional, for service notices, subscription status messages or App-related
reminders.
1.3 Purchase and Subscription Information
If you purchase a subscription or other in-app product, payment is handled by Apple through your Apple ID and
subscription access may be managed with Adapty SDK. We do not receive your full payment card number, billing
address or Apple ID password. We may receive limited purchase information such as product identifier,
transaction status, subscription status, renewal status, entitlement status and non-sensitive transaction
identifiers solely to unlock paid features, prevent fraud, provide support and comply with platform
requirements.
1.4 Analytics and Technical Data
We use Firebase Analytics (Google) to understand app usage and improve stability, performance and user
experience. We may collect de-identified or aggregated technical data such as device model, iOS version, app
version, crash logs, diagnostic events, general region, language setting, session duration, screen views,
feature usage statistics, subscription events and network status. We do not use this data to identify you as an
individual.
2. Third-Party Services and SDKs
We use third-party services only where reasonably necessary for App functionality, subscription processing,
analytics, crash reporting or customer support. These providers are subject to security and data protection
review.
- Apple App Store / StoreKit
- Purpose of processing: Process in-app purchases, subscriptions, renewals, cancellations and refund
handling through Apple.
- Categories of data processed: Apple-managed purchase and subscription information, transaction
identifiers, product identifiers and subscription status.
- Third-party privacy policy: https://www.apple.com/legal/privacy/
- Firebase Analytics (Google)
- Purpose of processing: Collect aggregated app usage analytics, event metrics and engagement data to
improve the App.
- Categories of data processed: De-identified device information, app events, session data, crash or
performance-related diagnostics, general region and network status.
- Third-party privacy policy: https://firebase.google.com/support/privacy
- Adapty SDK (Adapty, Inc.)
- Purpose of processing: Manage paywalls, subscription access, receipt verification, entitlements and
subscription analytics.
- Categories of data processed: Device identifiers, app events, product and subscription identifiers,
receipt-related information, entitlement status and subscription analytics.
- Third-party privacy policy: https://adapty.io/privacy/
3. How We Use Information
- To provide authenticator account storage, QR scanning, one-time password generation, app lock and related
security features.
- To save your preferences and improve App performance.
- To process purchases and manage subscription access.
- To diagnose crashes, fix bugs, prevent abuse and maintain security.
- To respond to your support requests and legal requests where required.
4. Data Storage and Cross-Border Transfers
- Storage: Core authenticator data is generally stored on your device. Purchase data may be
processed by Apple and Adapty. De-identified analytics or crash data may be stored by our service providers.
- Backup responsibility: You are responsible for maintaining backups of important 2FA secret
keys and recovery codes. If data is stored only on your device and the device is lost, damaged, reset or the
App is deleted, we may be unable to recover it.
- Cross-border transfers: As the App may be distributed globally, limited technical and
de-identified data may be transferred to servers outside your country or region. We use reasonable
safeguards designed to protect such data in accordance with applicable law.
5. Your Privacy Rights (U.S. Consumers)
If you are a consumer located in the United States, you may have the following rights under applicable U.S.
privacy laws:
- Right to Know: Request details of the personal information we process about you.
- Right to Delete: Request deletion of personal information we hold, excluding data stored
only on your device or data retained where legally required.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: We do not sell your personal information. We do not share
personal information for cross-context behavioral advertising as defined by California law.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal
information for purposes that require a limitation right under California law.
- Right to Non-Discrimination: We will not discriminate against you for exercising your
privacy rights.
6. Children's Privacy (COPPA)
The App is not intended for children under the age of 13. We do not knowingly collect personal information from
children under 13. If we become aware that we have collected personal information from a child under 13, we will
delete it as required by law.
7. Data Security
We use reasonable administrative, technical and organizational measures designed to protect information processed
by the App. However, no method of transmission or storage is completely secure. You are responsible for keeping
your device, Apple ID, authenticator accounts, backup codes and local App access secure.
8. Authenticator Accuracy Notice
The App generates one-time passwords using locally stored secret keys and the device clock. Codes may be invalid
if the device time is incorrect, if a third-party service changes its authentication requirements, or if the
account secret key is deleted, reset or no longer matches the service provider's record. You should always keep
recovery methods and backup codes in a safe place.
9. Changes to This Privacy Policy
We reserve the right to update this policy as required by law or for operational reasons. The latest version will
be posted in the App or on the relevant policy page with an updated "Last Updated" date. Your continued use of
the App after changes take effect constitutes your acceptance of the revised policy.
10. Contact Us
If you have questions, complaints or requests regarding this Privacy Policy or your personal data, you may contact
us:
We will respond to valid requests within the time limits required by applicable law.