2. Information we process
Category:
Authentication data
Examples:
TOTP setup secrets, generated codes, issuer and account labels, backup codes, imported/exported vault data.
How it arises:
Created, scanned or imported by you, ordinarily stored on-device in the iOS Keychain. Transmitted only if you enable backup/sync or export/share it.
Category:
Password vault data
Examples:
Service names, logins, passwords, website addresses, notes and category labels.
How it arises:
Created or imported by you (including import from browser CSV exports); stored on-device in the iOS Keychain. Transmitted only if you enable iCloud Sync or export it.
Category:
Camera, image and QR data
Examples:
Camera frames, text recognised from them, images and documents you select (including PDF), and QR-code content.
How it arises:
Processed when you add an account by scanning a QR code, by pointing the camera at a printed setup key (the text in view is recognised on-device to find the key), or by importing a QR code from your photo library or files. Camera frames and imported images are processed entirely on your device and are neither stored nor transmitted; only the decoded setup key enters your vault.
Category:
Backup/sync data
Examples:
Your vault entries (2FA accounts and password entries) stored as encrypted fields, together with each record's type, identifier and last-modified timestamp.
How it arises:
Processed only if you sign in with Apple and enable iCloud Sync. Records are written to a private CloudKit database inside your own Apple account: Apple encrypts the entry content and controls the keys, and LOGIC FUSION, LLC operates no server for this feature and cannot read your entries. The record type and the last-modified timestamp are stored unencrypted so that your devices can merge changes.
Category:
Subscription data
Examples:
Product identifier, subscription status, purchase and renewal dates, purchase amount and currency, transaction or receipt identifiers, storefront, trial eligibility, and pseudonymous subscriber and attribution identifiers generated by RevenueCat and AppsFlyer.
How it arises:
Purchases are made through Apple's in-app purchase system. Apple processes your payment; we never receive card or other payment-instrument details. Subscription status and receipts are validated and stored by RevenueCat. So that we can measure which marketing campaigns lead to subscriptions, the App provides RevenueCat with your AppsFlyer attribution identifier, and RevenueCat sends subscription events — including the plan, the amount and currency and the transaction identifier — to AppsFlyer.
Category:
Device and diagnostics
Examples:
App version, operating-system version, device model, language, crash traces, performance data, pseudonymous identifiers generated by our analytics tools, coarse network information, and records of in-app actions such as screens opened, an account being added, a code being scanned or sync being switched on.
How it arises:
Generated whenever the App operates. Events are sent to Amplitude and Firebase (Analytics, Crashlytics, Remote Config). They record that an action happened, never its content: no authentication secrets, passwords, QR contents, account labels, URLs, search terms or page content are included. We do not attach your name or Apple Account e-mail to this data.
Category:
Advertising and attribution
Examples:
IDFA (only with your permission), IDFV, AppsFlyer ID, campaign identifiers, IP-derived approximate location, and install, session, trial, subscription and purchase events.
How it arises:
Collected by AppsFlyer, our attribution provider, to measure and optimise our acquisition campaigns. Install, session, device and identifier data is collected by the AppsFlyer SDK in the App. Trial, subscription and purchase events reach AppsFlyer from RevenueCat, matched to your attribution identifier, which the App provides to RevenueCat for this purpose. IDFA is used only if you allow tracking in Apple's App Tracking Transparency prompt; if you decline, attribution continues without it.
Category:
Browser/Web View data
Examples:
Search terms, URLs, page content, IP address, cookies, local storage, browser and device characteristics, information you submit to sites, and any saved login or one-time code you choose to fill into a page.
How it arises:
Processed within the WebView and by DuckDuckGo, the websites you visit, their content hosts and network providers. Every tab is private: the App stores no browsing history, and page addresses and titles are not saved. A built-in blocklist of known advertising and tracking hosts is applied on your device. If you choose to fill a saved login or one-time code, the App inserts it into the page you are on, and the website receives it when you submit the form.
Category:
Communications
Examples:
Your e-mail address and the display name configured in your mail account, together with anything you choose to include: the message itself, attachments, screenshots and diagnostic details.
How it arises:
Provided when you contact our support by e-mail, send feedback or make a privacy request. The App opens an empty message in your own mail application and attaches nothing automatically — no logs, identifiers or device information are added by us. Your message travels through your e-mail provider and ours.
Category:
Apple Account data
Examples:
The Apple user identifier and e-mail address returned by Sign in with Apple.
How it arises:
Provided by Apple if you choose Sign in with Apple, which is required before iCloud Sync can be switched on. Both values are stored only in the Keychain on your device and are never transmitted to us — we operate no account server. Signing out removes them from the device. There is no separate company account, password or account-recovery process.
We do not intend to collect authentication secrets, live codes, QR contents, account labels, browser history or page content through advertising, analytics, crash reporting or support tools. Do not send such data to support. If the implemented App handles these categories differently, this Policy and the product must be revised before launch.
We may receive limited campaign attribution and aggregated performance information from advertising and analytics partners. We do not receive your name, email address or authentication data from those partners. On iOS, the App will not access IDFA or track you across other companies' apps or websites without the permission required by Apple's rules.