🛡️
HackProof Authenticator

Privacy Policy

Your security. Your data. Your device. We built HackProof Authenticator on a single principle: we have no business knowing your business.

No data collected
Effective: July 8, 2026
🔒

Zero Data Collection

HackProof Authenticator does not collect, store, sell, share, or transmit any personal information about you. Everything the app does happens on your device.

Overview

HackProof Authenticator ("the App," "we," "our") is a privacy-first security toolkit for iPhone and iPad. This Privacy Policy explains what data the App accesses, how it is used, and — critically — what we do not collect or share.


By using the App you agree to this policy. If you do not agree, please discontinue use and delete the App from your device.

What We Do Not Collect

  • No name, email address, phone number, or any personally identifiable information
  • No browsing history, app usage analytics, or behavioral data
  • No device identifiers (IDFA, IDFV, serial numbers)
  • No location data, even approximate
  • No contact lists, photos, or any other media
  • No health or financial data
  • No crash reports sent to our servers
  • No advertising identifiers of any kind

Tools Tab — Features & Privacy

Every tool in HackProof Authenticator operates locally on your device. No results, inputs, or scan data are ever uploaded to our servers.

🔐

2FA Authenticator

Generates TOTP one-time passwords locally. Your secret keys never leave your device.

🔑

Password Manager

Stores and manages passwords in encrypted local storage on your device. Never synced externally.

🔍

Breach Check

Checks whether an email appears in known breach databases. See Section 04 for details on how this is handled privately.

📵

Spam Call Protection

Guides you through iOS system settings to enable call filtering. The App does not access your call log.

🌐

Safe Browsing

Walks you through Safari's built-in fraud protection and iCloud Private Relay. No browsing data is accessed by the App.

Wi-Fi Speed Test

Measures your connection's download, upload, and ping on-device. Results are not transmitted anywhere.

📡

Wi-Fi Heatmap

Visualizes signal strength live using your device's Wi-Fi radio. No location or signal data is stored or sent.

📶

Bluetooth Scanner

Detects nearby BLE devices and potential trackers using your device's Bluetooth hardware. Scan results stay on your device.

🕵️

Network Inspector

Shows your public IP, ISP, TLS version, and VPN status by querying standard public network APIs. No results are stored by us.

🧪

Password Strength

Analyzes passwords for entropy, crack time, and pattern weaknesses entirely on your device. Your password is never transmitted.

🖼️

Photo Vault

Hides and protects your chosen media on-device. Captures intruder photos silently. No images are ever uploaded or stored by us. See Section 04.

Photo Vault — Camera & Gallery

Photo Vault stores all protected media exclusively on your device using iOS-level encryption. No images, thumbnails, or metadata are ever transmitted to our servers or any third party.

📷 Camera — Intruder Detection

When you lock HackProof Authenticator with a passcode or biometrics, the App can silently capture a photo of anyone who enters the wrong PIN — a feature designed to catch unauthorized access attempts on your device.

  • The camera is activated only on a failed unlock attempt — never in the background or without your prior consent
  • Captured intruder photos are saved locally on your device only, inside the App's protected storage
  • No intruder photo is ever uploaded, transmitted, or accessible to us
  • You can view, download, or permanently delete these photos at any time from within the App
  • iOS will display a camera permission prompt the first time this feature is enabled — you remain in full control

🖼️ Photo Library — Hide & Protect Media

Photo Vault lets you move photos and videos from your iOS Photo Library into a private, encrypted vault inside the App so they no longer appear in your standard gallery.

  • Access to your Photo Library is requested only when you choose to import or export media — never automatically
  • You select exactly which photos or videos to protect; the App never scans or reads your full library
  • iOS grants access only to items you explicitly select, using Apple's privacy-preserving photo picker
  • Once imported, media is encrypted at rest and stored inside the App's sandboxed local storage
  • No media file, thumbnail, or EXIF metadata is ever sent off your device
  • You can restore media back to your Photo Library or delete it permanently from the vault at any time

Deleting the App permanently removes all vaulted media from your device. We strongly recommend exporting any photos or videos you want to keep before uninstalling.

Encrypted Cloud Backup for 2FA Codes

HackProof Authenticator offers an optional encrypted iCloud backup for your TOTP accounts, so you can seamlessly restore and use your 2FA codes across all your Apple devices (iPhone, iPad, Mac) without manually re-scanning QR codes.

  • iCloud backup is strictly opt-in — it is off by default and you must explicitly enable it in Settings
  • All TOTP secret keys are end-to-end encrypted on your device before being written to iCloud — we never see the plaintext keys
  • The encryption key is derived from your device credentials and never leaves your Apple account's secure enclave
  • iCloud sync is governed by Apple's iCloud privacy policy — we have no access to your iCloud storage
  • Only your 2FA account names and encrypted secrets are backed up — no passwords, vault media, or personal information are included
  • You can disable iCloud backup and delete the backup data at any time from Settings → 2FA Backup → Disable & Delete

Even with cloud backup enabled, your 2FA secret keys are mathematically inaccessible to us. The encryption happens entirely on your device. We cannot restore, read, or share your backup even if compelled to do so.

Email Address & Breach Check

When you use the Breach Check tool, the App may use an email address you provide to query a third-party breach database (such as Have I Been Pwned).

  • Your email address is hashed or anonymized before the query is sent — the raw address is never transmitted over the network
  • The email is used solely and only for the single breach lookup you initiate
  • We do not store, log, or retain your email address on any of our servers
  • Your email is never used to contact you, market to you, or identify you
  • You are in complete control — you choose when and whether to run a breach check

The breach database API receives only an anonymized partial hash of your email — never the full address. This is a well-established privacy-preserving technique (k-Anonymity) used by leading security services.

Local Storage & Your Data

Certain features of the App store data on your device to function:

2FA Secret Keys On-device only
Saved Passwords On-device only
App Preferences On-device only
Breach Check History On-device only
Wi-Fi / BT Scan Results On-device only
Vaulted Photos & Videos On-device only
Intruder Capture Photos On-device only
2FA Backup (opt-in) Encrypted iCloud only
Data sent to our servers None

Delete your data anytime. You have full control. Go to Settings → Delete Account inside the App to permanently erase all locally stored information. Deleting the App from your device also removes all data.

Device Permissions

The App may request the following iOS permissions. Each is used only for the feature described — never for tracking:

📷 Camera Scan 2FA QR codes & capture intruder photos on failed unlock
🖼️ Photo Library Import/export vault media — only items you select, never auto-scanned
☁️ iCloud Encrypted 2FA backup across Apple devices (opt-in only)
📶 Bluetooth Bluetooth Scanner tool only
📡 Local Network Wi-Fi scan and heatmap tools
🔔 Notifications Optional security alerts (local, never remote-pushed)
🌐 Internet Access Breach Check and Network Inspector only

All permissions are optional and can be revoked at any time from iOS Settings → HackProof Authenticator. Revoking a permission simply disables the related tool — the rest of the App continues to work normally.

Third-Party Services

HackProof Authenticator uses a minimal set of third-party services, listed below. None of them receive personal information about you:

Breach Database API k-Anonymity hash only — no raw email
Network Info APIs Public IP & ISP lookup (Network Inspector tool)
Apple IAP / StoreKit In-app purchase validation — governed by Apple's privacy policy
iCloud (optional) Encrypted 2FA backup — opt-in, governed by Apple's iCloud privacy policy
Firebase (optional) Used for optional account features only if you opt in. Governed by Google's privacy policy.

We do not use any advertising SDKs, analytics platforms, or third-party tracking libraries. There are no ad networks, no cross-app trackers, and no data brokers involved with this App.

Children's Privacy

HackProof Authenticator is not directed at children under the age of 13. We do not knowingly collect any personal information from children. Because the App collects no personal information from anyone, it inherently does not collect information from minors. If you believe a child has provided information to the App, please contact us and we will investigate promptly.

Your Rights & Control

Because we collect no personal data, most data-rights requests are satisfied automatically. For completeness:

  • Access. All data the App holds is stored on your own device — you already have full access.
  • Deletion. Use Settings → Delete My Data in the App, or simply delete the App from your device.
  • Portability. Your 2FA accounts and passwords are stored in standard formats — you can export them from Settings.
  • Opt-out of notifications. Revoke notification permission at any time in iOS Settings.
  • GDPR / CCPA. We do not collect personal data, so there is nothing for us to process, sell, or disclose. These regulations are satisfied by design.

Security

All sensitive data (2FA keys, passwords) stored locally is protected by iOS Keychain encryption and device-level security (Face ID / Touch ID / passcode). The App does not implement its own cryptographic storage — it relies on the battle-tested security architecture built into iOS and iPadOS.


Because no data is transmitted to or stored on our servers, there is no server-side attack surface that could expose your information.

Changes to This Policy

If we ever make material changes to this Privacy Policy, we will post the updated policy at this URL and update the "Effective" date at the top of the page. We encourage you to review this page periodically. Continued use of the App after a change constitutes acceptance of the updated policy.


Our commitment to not collecting your data is a core design decision, not a setting — any change to that principle would require explicit notice and would be a fundamental change to the App's identity.

Contact Us

✉️

Send us a message

We usually respond within 24–48 hours.