Privacy

Last updated 16 September 2026 · AssuredAuth, by CircleRoll LLC

Your keys are stored on your phone, your codes are worked out on your phone, and your passwords are encrypted on your phone. Nothing about your accounts leaves it unless you turn on backup, which is one switch and starts off. There is no AssuredAuth account, so there is nothing of yours on our side to begin with. Everything that does leave, in any case, is set out below in full.

What stays on your device

All of it. Specifically:

WhatWhere it lives
The secret key for every account, and the codes worked out from it The system keychain on iPhone and the Android Keystore on Android, under a hardware key that cannot be exported; codes exist only while a screen shows them
The service name, the account name, the icon and the order of your accounts The app's own database on the device
Passwords, usernames, websites and notes in the vault The same database, each value encrypted under a key held in the phone's secure hardware
The private browser's tabs, bookmarks and favorites The same database, encrypted the same way. Its history, cookies and sign-ins are kept only until you clear them or leave the app
Your profiles, their names and photos, and your settings The same database and the app's private file storage
Camera frames while scanning a QR code Nowhere. They are read as they arrive and discarded. Nothing is recorded

What we collect

App crash reports, and a short list of usage events. Nothing else, and never a key, a code, an account name or a password. There is no advertising, no advertising identifier, no attribution or marketing software, and nothing is sold or shared with anyone for their own purposes.

The services are Google's Firebase Crashlytics, Firebase Analytics and Firebase Remote Config. Crashlytics tells us that the app fell over, on which model of phone, and at which line of code. Analytics tells us how many people finished setting the app up, added an account, saw the subscription screen, or bought one. Remote Config tells the app which of our subscription products to show and carries no information about you in either direction. That is how a bug gets found without waiting for somebody to write in, and how we can tell whether a change made the app better or worse.

There is a hard limit built into the app rather than promised on this page. The only events it is able to send are a fixed list — onboarding finished, lock enabled, account added, account deleted, code copied, paywall shown, purchase started, purchase completed, purchase failed, purchase restored, import finished, export shared, backup enabled, password saved, browser opened, support sent, profile added, profile switched, profile deleted — and the only detail any of them may carry is one word from another fixed list, such as which plan or whether an import came from a QR code or a file. There is no code path that can attach free text to any of them, so a key, a code, a service name or a password cannot reach us even by mistake.

You can turn all of it off. Open Settings → Privacy & data and switch off Diagnostics. Anything not yet sent is deleted, and nothing further is collected. With the switch off the reporting software is never started at all.

The services attach an identifier that belongs to this installation of the app, so two crashes can be recognized as coming from the same phone. It is not your name, your email, your device's advertising identifier, or anything that follows you into another app, and it is destroyed when you delete AssuredAuth.

Backup, if you turn it on

Off unless you switch it on. Your keys stay on your phone until you go to Settings → Backup and turn on Back up to iCloud on iPhone or Back up to Google Drive on Android. That is the moment anything about your accounts first leaves the device, and nothing before it does.

On iPhone the copy is your keychain items, marked to sync through iCloud Keychain, which Apple encrypts end to end: Apple holds the ciphertext and cannot read it, and neither can we. On Android the copy is an encrypted backup file in the app's own private folder on your Google Drive, which no other app and no person can list or open; Google holds the file and not the key. In both cases the copy contains your accounts and their keys, your passwords, and the browser's bookmarks; the browser's history, cookies and sign-ins are never backed up.

A backup file you write yourself — Settings → Backup → Back up to a file now, or Export & transfer — is sealed with a passphrase you choose and the app refuses a short one. The passphrase is stretched so that guessing it is slow, the file is encrypted with AES-256-GCM, and no hint is stored anywhere. Where you keep that file, and who can reach it, is up to you. Plain-text export exists for people who know what they are doing and sits behind a confirm sheet that says exactly what it is.

Turning backup off removes the copy. On iPhone the keychain items stop syncing and are removed from iCloud; on Android the file is deleted from Drive. The copy on your phone stays where it is.

The private browser

The browser inside AssuredAuth is a real web browser, and the sites you open in it see what any browser shows a site: your network address and the pages you ask for. Its history, cookies and sign-ins live only until you clear them with the Assured button or leave the app, unless you turn that off in the browser's settings. Address-bar suggestions send what you type to a search engine as you type it; that is on by default and the browser's settings switch it off. Bookmarks and favorites stay until you delete them, encrypted like your passwords.

With Premium+, the private connection sends the browser's traffic through servers we run, so the sites you open there see our address, not yours. It applies to the browser inside the app only, never to the rest of your phone, and it is switched on by you, per session; it never turns itself on. Those servers keep no logs: no record of who connected, when, or to what. The connection is issued against your store receipt and withdrawn when the subscription ends. What we hold for it is the fact that a subscription is active, and nothing about where it was used.

The desktop extension

The AssuredAuth browser extension lets a paired computer ask your phone for a code. The two are paired by scanning a QR code with the app, which exchanges keys between them; from then on every message is encrypted end to end, and the mailbox in the middle — Firestore, in the same Firebase project — holds sealed envelopes it cannot read, each deleted the moment it is read and swept after it expires. A push notification wakes the phone when a site asks; it carries no code and no site name. Your keys never leave the phone: the computer only ever receives the six digits, sealed for that computer alone, and only when the phone says so — either by your tap, or because you switched on always allow for that site on that computer, which Settings → Desktop lists and revokes.

The times something leaves your device

1. When you turn on backup

Set out in full above. Off until you switch it on, and removed from iCloud or Drive when you switch it off.

2. When you export or share

Only when you tap. A transfer QR is shown on your screen and read by another phone's camera; a backup file, a 2FAS-format file or a plain-text file goes wherever you send it through the share sheet. None of it passes through us.

3. When you use the private browser

The sites you open see a browser, as described above. With the private connection on, they see our servers' address instead of yours.

4. When a paired computer asks for a code

Described above. A sealed envelope through the mailbox and a push that wakes the phone, and six digits back, sealed for that computer.

5. When you write to us

The Help screen composes a message in your phone's own mail app, addressed to hello@assuredauth.com, with the app name and a ticket number in the subject and your phone model, system version and app version in the body. Nothing is sent until you press send, and what you send is exactly what you can see. Writing from this website is the same: the Contact page opens your own mail app. We keep messages for as long as it takes to answer them and up to twelve months afterwards, so a follow-up question has context.

6. When you buy a subscription

Purchases are handled entirely by Apple's App Store or Google Play. They tell the app whether a subscription is active; they do not tell us who you are, and we never see or handle your payment details. Their own privacy policies cover that transaction.

7. When the app checks the clock

Help → The code is not accepted has a Check the clock button. It asks a public web server for the time and compares it with your phone's, so a code that is refused because the clock is wrong can be explained. It sends nothing but the request, and it runs only when you tap it.

8. When the app crashes, or you use a screen

Described in full above. Crash diagnostics and a short list of usage events go to Google Firebase, acting for us as a processor under its own terms. No key, code or password is included, no advertising identifier is collected, and the switch in Settings → Privacy & data stops it.

Accounts

There are none. AssuredAuth has no sign-up, no sign-in and no email address of yours. A subscription is recognized by the store account that bought it, and a backup by the iCloud or Google account already on your phone; we see neither.

Watches and widgets

The watch app receives your accounts and their keys from the phone over Apple's WatchConnectivity or Google's on-device wearable link, and stores them in the watch's own keychain so codes can be worked out on the wrist. A widget reads the phone's keychain and is redacted while the phone is locked. Both are connections between devices you own. Neither goes through us.

Children

AssuredAuth is a general-purpose utility, and we do not knowingly collect anything from anyone, of any age. It has no account and asks for no date of birth because it has no reason to.

Your rights

Because your data is on your device rather than in our hands, most of these are things you can simply do, without asking us:

If you are in the UK, EU, California or anywhere else with a statutory right of access or erasure and you would like it exercised against the one thing we do hold — a support email you sent us — write to hello@assuredauth.com and we will act within 30 days.

Changes

If this policy changes in a way that affects what happens to your data, the app will say so before the change takes effect rather than quietly updating this page. The date at the top always reflects the current version.

Contact

CircleRoll LLC · hello@assuredauth.com

AssuredAuth generates codes. It does not hold your accounts. Two-step verification is turned on and off on each service's own website, and that service is the one that can let you back in if a phone is lost without a backup. See the terms for what that means in practice.