Alpha Gateway Limited

Privacy and responsible product use

Privacy Policy

Effective Date: March 11, 2026

This Privacy Policy explains how Alpha Gateway Limited (“Alpha Gateway,” “we,” “us,” or “our”) handles information when you use Authenticator App • (the “App”).

The App is designed to help users manage authentication information and use related security tools. Because authentication credentials may provide access to third-party accounts, we treat authenticator secrets, one-time codes, QR code contents, and generated passwords separately from ordinary analytics and advertising data.

Authentication Information Stays on Your Device

The App may process authentication records that you add manually or through a QR code. These records may contain an account label, service name, authentication secret, recovery information, or other configuration data required to generate one-time verification codes.

Authentication secrets and one-time verification codes are intended to be processed and stored locally on your device. We do not intentionally transmit this content to Google Analytics for Firebase, Google Mobile Ads, or use it for advertising, user profiling, or behavioral analysis.

The App does not need your password for a third-party account in order to generate an authentication code. You should not enter third-party account passwords into the App unless a feature expressly requires and explains such use.

Unless a separate backup or synchronization feature is expressly presented to you, authentication records are not backed up to servers operated by Alpha Gateway. Removing an authentication record or deleting the App may therefore make the corresponding information unrecoverable. You are responsible for keeping recovery codes or another suitable account-recovery method where supported by the relevant third-party service.

Other Content Processed Through the App

Depending on the features you choose to use, the App may process:

This content is processed primarily on the device for the requested function. Passwords generated by the App are not intentionally uploaded to our analytics or advertising systems.

Website or domain assessments may rely on security rules or threat information retrieved through an internet connection. Unless a specific in-app notice states otherwise, website addresses submitted for assessment are not provided to analytics or advertising SDKs for advertising purposes.

The App is independent from the third-party services for which authentication records may be created. Adding a record associated with a third-party service does not give Alpha Gateway access to your account with that service.

Information Collected for App Operation

Separate from locally stored authentication content, we and our service providers may collect limited technical and usage information.

Identifiers

We may process a Device ID, User ID, app installation identifier, advertising identifier where permitted, or a similar pseudonymous identifier. A User ID used by the App does not necessarily identify you by name and may instead represent a particular user, device, or installation instance.

Device and network information

This may include IP address, device model, operating system and version, language, time zone, App version, network status, country or general region inferred from technical information, and similar system details.

We do not collect precise GPS location for the App’s core authentication functions. However, an IP address may provide an approximate geographic area.

App activity

We may collect events such as App launches, screen or feature interactions, button selections, session duration, advertising events, purchase-page interactions, and general feature usage.

Analytics events are configured not to include authentication secrets, one-time verification codes, generated passwords, or complete QR code contents.

Diagnostics

Crash reports, error logs, performance measurements, and other diagnostic information may be processed to identify technical problems and improve stability.

Purchase and subscription information

When you start a free trial, purchase a subscription, make a lifetime purchase, or restore a purchase, we may receive the product type, transaction identifier, purchase status, renewal or expiration status, and related validation information.

Payments are processed by the applicable app marketplace. We do not receive your complete payment-card or banking details.

Information you provide to us

If you contact us, we receive the information included in your message, such as your email address, device information, screenshots, and support request. You should remove authentication secrets, active verification codes, recovery codes, and passwords before sending diagnostic materials to us.

How Technical Information Is Used

The technical information described above may be used to:

Device ID, User ID, installation identifiers, and behavioral events may be associated with the same user, device, or App installation for these purposes. This association does not include authenticator secrets, one-time codes, generated passwords, or full QR code contents.

Device Permissions

The App only requests system access when it is relevant to a feature.

Camera

Camera access may be requested so that you can scan an authentication QR code. Camera images are used to recognize the code and are not intentionally sent to analytics or advertising services.

Photos

Photo-library access may be requested if you choose to import a QR code from an existing image. Where the operating system supports limited photo access, you may select only the image you want the App to process. The App does not need unrestricted access to your entire photo library for this purpose.

Tracking

The App may request permission through Apple’s App Tracking Transparency framework when an advertising or measurement activity qualifies as tracking across apps or websites owned by other companies. If you refuse permission, the App’s core authentication functions remain available, although advertising may be less relevant and some measurement may be limited.

Internet access

An internet connection may be used for analytics, advertising, subscription validation, security-rule updates, support, and related technical operations. Internet access does not mean that locally stored authentication secrets are uploaded.

The core features described in this Policy do not ordinarily require access to your contacts, microphone, videos, Bluetooth, or local network. If a future feature needs additional permission, the App will request it through the operating system and explain its purpose before access is granted.

You can review or revoke permissions at any time through your device settings. Some optional features may stop working after the related permission is withdrawn.

Analytics and Advertising Services

The App uses the following Google services:

Google Analytics for Firebase

Google Analytics for Firebase helps us understand App usage, feature interactions, device characteristics, session activity, and technical performance. It may process pseudonymous identifiers, IP address, device information, App activity, and related analytics events.

Google Mobile Ads

Google Mobile Ads is used to display and measure advertisements. Depending on your device settings, consent choices, location, and applicable law, it may process advertising identifiers, Device ID, IP address, device information, ad impressions, ad interactions, and related measurement information.

Google may process information in countries outside your place of residence and retains information under its own terms, privacy policies, account settings, and legal obligations. More information is available in Google’s Privacy Policy and its explanation of how Google uses information from partner apps.

We do not permit these services to receive authenticator secrets, active verification codes, generated passwords, or complete QR code contents through our configured analytics events.

Advertising, Tracking, and Data Sharing

We do not sell authentication secrets, verification codes, generated passwords, or QR authentication data.

We do not sell personal information in exchange for money. However, the transmission of device identifiers or advertising activity to advertising providers may be treated as “sharing,” “targeted advertising,” or a “sale” under certain privacy laws, even when no money is exchanged.

Where required, we rely on your consent or device permission before using information for cross-app tracking or personalized advertising. You can limit these activities by:

Non-personalized advertising may still use limited contextual, device, network, and ad-delivery information.

Retention and Deletion

Authentication records and other functional content stored locally remain on your device until you delete the relevant record, reset the App, or remove the App. We generally cannot recover locally deleted authentication information.

Information controlled directly by Alpha Gateway, including identifiers, behavioral events, diagnostic information, and related technical records, is generally retained for no longer than seven days, after which it is deleted or de-identified unless a longer period is required to investigate fraud, resolve a security incident, comply with law, or establish or defend legal claims.

Information processed by Google, Apple, or another independent platform may be retained according to that provider’s own policies and configuration. Transaction and subscription records maintained by the app marketplace are not controlled by Alpha Gateway and are not covered by our seven-day operational retention period.

Support correspondence may be retained for as long as reasonably necessary to respond to the request, document its resolution, and comply with applicable obligations.

Your Privacy Choices

Depending on where you live, you may have the right to request access to, correction of, deletion of, or restriction on certain personal information, or to object to or withdraw consent for particular processing.

Because most authentication content remains on your device, you can usually manage that content directly within the App. Deleting information from the App does not cancel or disable two-factor authentication on the relevant third-party account. You should first follow that service’s instructions for changing or removing its authentication method.

For information held by Alpha Gateway, you may submit a privacy request to [email protected]. We may need limited information to confirm the request and identify the relevant App installation or support record.

You may also:

Security Responsibilities

We use reasonable administrative and technical measures intended to protect information under our control. Nevertheless, no device, storage system, or transmission method can be guaranteed to be completely secure.

Authentication records can provide access to important third-party accounts. You should protect your device with a passcode or biometric lock, avoid sharing QR codes or recovery keys, maintain independent recovery methods, and promptly remove authentication records from devices you no longer control.

A phishing or website-security result is an informational assessment rather than a guarantee that a website is safe. Threat information may be incomplete, delayed, or inaccurate, and you should independently evaluate suspicious requests for passwords, payment information, or verification codes.

International Processing

Technical, analytics, advertising, and support information may be processed in countries other than the country where you live, including locations in which Alpha Gateway or its service providers operate. Where required, we use legally recognized safeguards for international transfers.

Locally stored authentication information does not leave your device merely because analytics or advertising services operate internationally.

Children’s Privacy

The App is not directed to children under 13 or the minimum age required by local law to independently consent to data processing. We do not knowingly collect personal information from children in violation of applicable law.

If you believe a child has provided personal information to us, contact us so that we can review and, where appropriate, delete it.

Policy Changes

We may update this Privacy Policy when the App, its data practices, legal requirements, or service providers change. Material changes will be communicated through the App, the App’s store listing, or another reasonable method before they take effect where required.

The effective date shown at the beginning identifies the current version.

Contact

For privacy questions, requests, or complaints, contact:

Alpha Gateway Limited

Email: [email protected]