Your security. Your data. Your device. We built HackProof Authenticator on a single principle: we have no business knowing your business.
HackProof Authenticator ("the App," "we," "our") is a privacy-first security toolkit for iPhone and iPad. This Privacy Policy explains what data the App accesses, how it is used, and — critically — what we do not collect or share.
By using the App you agree to this policy. If you do not agree, please discontinue use and delete the App from your device.
Every tool in HackProof Authenticator operates locally on your device. No results, inputs, or scan data are ever uploaded to our servers.
Generates TOTP one-time passwords locally. Your secret keys never leave your device.
Stores and manages passwords in encrypted local storage on your device. Never synced externally.
Checks whether an email appears in known breach databases. See Section 04 for details on how this is handled privately.
Guides you through iOS system settings to enable call filtering. The App does not access your call log.
Walks you through Safari's built-in fraud protection and iCloud Private Relay. No browsing data is accessed by the App.
Measures your connection's download, upload, and ping on-device. Results are not transmitted anywhere.
Visualizes signal strength live using your device's Wi-Fi radio. No location or signal data is stored or sent.
Detects nearby BLE devices and potential trackers using your device's Bluetooth hardware. Scan results stay on your device.
Shows your public IP, ISP, TLS version, and VPN status by querying standard public network APIs. No results are stored by us.
Analyzes passwords for entropy, crack time, and pattern weaknesses entirely on your device. Your password is never transmitted.
Hides and protects your chosen media on-device. Captures intruder photos silently. No images are ever uploaded or stored by us. See Section 04.
Photo Vault stores all protected media exclusively on your device using iOS-level encryption. No images, thumbnails, or metadata are ever transmitted to our servers or any third party.
📷 Camera — Intruder Detection
When you lock HackProof Authenticator with a passcode or biometrics, the App can silently capture a photo of anyone who enters the wrong PIN — a feature designed to catch unauthorized access attempts on your device.
🖼️ Photo Library — Hide & Protect Media
Photo Vault lets you move photos and videos from your iOS Photo Library into a private, encrypted vault inside the App so they no longer appear in your standard gallery.
Deleting the App permanently removes all vaulted media from your device. We strongly recommend exporting any photos or videos you want to keep before uninstalling.
HackProof Authenticator offers an optional encrypted iCloud backup for your TOTP accounts, so you can seamlessly restore and use your 2FA codes across all your Apple devices (iPhone, iPad, Mac) without manually re-scanning QR codes.
Even with cloud backup enabled, your 2FA secret keys are mathematically inaccessible to us. The encryption happens entirely on your device. We cannot restore, read, or share your backup even if compelled to do so.
When you use the Breach Check tool, the App may use an email address you provide to query a third-party breach database (such as Have I Been Pwned).
The breach database API receives only an anonymized partial hash of your email — never the full address. This is a well-established privacy-preserving technique (k-Anonymity) used by leading security services.
Certain features of the App store data on your device to function:
Delete your data anytime. You have full control. Go to Settings → Delete Account inside the App to permanently erase all locally stored information. Deleting the App from your device also removes all data.
The App may request the following iOS permissions. Each is used only for the feature described — never for tracking:
All permissions are optional and can be revoked at any time from iOS Settings → HackProof Authenticator. Revoking a permission simply disables the related tool — the rest of the App continues to work normally.
HackProof Authenticator uses a minimal set of third-party services, listed below. None of them receive personal information about you:
We do not use any advertising SDKs, analytics platforms, or third-party tracking libraries. There are no ad networks, no cross-app trackers, and no data brokers involved with this App.
HackProof Authenticator is not directed at children under the age of 13. We do not knowingly collect any personal information from children. Because the App collects no personal information from anyone, it inherently does not collect information from minors. If you believe a child has provided information to the App, please contact us and we will investigate promptly.
Because we collect no personal data, most data-rights requests are satisfied automatically. For completeness:
All sensitive data (2FA keys, passwords) stored locally is protected by iOS Keychain encryption and device-level security (Face ID / Touch ID / passcode). The App does not implement its own cryptographic storage — it relies on the battle-tested security architecture built into iOS and iPadOS.
Because no data is transmitted to or stored on our servers, there is no server-side attack surface that could expose your information.
If we ever make material changes to this Privacy Policy, we will post the updated policy at this URL and update the "Effective" date at the top of the page. We encourage you to review this page periodically. Continued use of the App after a change constitutes acceptance of the updated policy.
Our commitment to not collecting your data is a core design decision, not a setting — any change to that principle would require explicit notice and would be a fundamental change to the App's identity.
We usually respond within 24–48 hours.