Skip to content

Privacy Policy — Taranac MFA

Last updated: 2026-06-24

Taranac MFA (“the App”) is a multi-factor authentication app: a TOTP/HOTP authenticator and a push-approval client for a self-hosted Taranac MFA server. This policy explains what data the App handles and why. The App is designed to keep your secrets on your device.

The App connects only to a Taranac MFA server that you or your organization operate. We (the App publisher) do not run a central backend, do not receive your accounts or secrets, and have no access to your authentication data. Your server operator is the data controller for anything you enroll against their server.

The following is stored only on your device, in the platform secure keystore (Android Keystore / iOS Keychain), and is never sent to us:

  • OTP secrets — the shared secrets for your TOTP/HOTP accounts.
  • Account metadata — issuer/label, OTP parameters, and per-account settings.
  • Push key material — an RSA private key per enrolled push token and the server’s public key.
  • App preferences — chosen language and the SSL trust setting.

This data never leaves your device except as described below (server enrollment, push notifications, crash reporting, and — if you keep it enabled — the optional cloud backup), and is removed when you delete the account or uninstall the App.

So that your accounts survive replacing your phone, the App backs up the data listed above (OTP secrets, account metadata, and push key material) to your own platform account within the same ecosystem:

  • iPhone — Apple iCloud Keychain.
  • Android — Google Block Store, backed up to your Google account.

This backup is end-to-end encrypted by the platform with your device lock and is held under your Apple/Google account — we never receive it, and it is never sent to any Taranac server or to us. Apple’s and Google’s handling of this data is governed by their respective privacy policies. The backup only moves between your own devices in the same ecosystem (iPhone→iPhone, Android→Android); it is not transferred across platforms.

You can turn this off at any time in Settings → Backup. Turning it off deletes the cloud copy from that device. When off, your secrets stay only on the current device and will not be recoverable if the device is lost.

When you enroll a push token against your Taranac MFA server, the App sends to that server only:

  • The device’s push notification (FCM) token, so the server can deliver approval requests.
  • Your RSA public key, so the server can verify your approvals.
  • Approve/deny responses (cryptographically signed) for login requests.

Push notifications (Firebase Cloud Messaging)

Section titled “Push notifications (Firebase Cloud Messaging)”

To receive push approval requests, the App uses Google Firebase Cloud Messaging (FCM). Google issues a device messaging token and routes notification payloads. Google’s handling of this data is governed by the Google Privacy Policy. The App does not use Firebase Analytics, advertising, or any other Firebase product beyond message delivery and the crash reporting described below.

To diagnose and fix stability problems, the App uses Firebase Crashlytics. When the App crashes, a diagnostic report is sent to Firebase containing technical information such as the error/stack trace, device model, OS version, and App version. These reports do not include your OTP secrets, push keys, account names, or any authentication data. Crash collection is disabled in debug builds. Google’s handling of this data is governed by the Google Privacy Policy.

If you enable biometric app lock, authentication (fingerprint/face) is performed entirely by the operating system on your device. The App never receives, stores, or transmits biometric data.

  • Internet — to communicate with your Taranac MFA server.
  • Notifications — to display push approval requests.
  • Biometric — optional app lock.
  • Camera — only while scanning an enrollment QR code; no images are stored or transmitted.
  • No analytics or advertising identifiers; no behavioural tracking.
  • No location data.
  • No contacts, photos, or files.
  • No data is shared with or sold to third parties.
  • Delete an individual account in the App to remove its secrets and keys from your device.
  • Uninstalling the App removes all locally stored data.
  • To remove server-side enrollment (your push token and public key), unenroll the token in the App, or ask your Taranac MFA server operator to delete it.

The App is a security tool not directed at children and does not knowingly collect data from children.

We may update this policy; the “Last updated” date reflects the latest version.

Questions about this policy: support@taranac.pro. For data held on a specific Taranac MFA server, contact that server’s operator.