BD 2FA Authenticator Privacy Policy

Effective date: April 18, 2026 Last updated: April 18, 2026

BD 2FA Authenticator (“the App”) is a two-factor authentication (2FA) code generator published by BestDid (“we”, “us”). This policy explains what data the App handles, how it is stored, and what is and is not shared.

Summary

  • The App runs entirely on your device.
  • We do not operate a server for this App. We do not collect, receive, or store any of your data.
  • Your 2FA secrets never leave your device unless you explicitly export or email an encrypted backup.
  • The App contains no advertising, no analytics, and no tracking.

Information Stored on Your Device

The App stores the following only on your device, inside the platform’s secure keystore (Android Keystore / iOS Keychain, via expo-secure-store):

DataPurpose
TOTP account secrets, issuer, account label, algorithm, digits, periodGenerate 2FA codes
PIN hash and saltLock the App; the PIN itself is never stored
App settings (biometric toggle, auto-lock, backup email, backup password)Preserve your preferences
Your chosen backup email address and backup encryption passwordEnable encrypted backups

None of this data is transmitted to us or to any third party by the App.

Device Permissions

The App requests the following permissions. Each is used only for its described purpose.

  • Camera — to scan QR codes containing TOTP setup URIs. Camera frames are processed on-device and are never recorded or transmitted.
  • Biometric (Face Unlock / Fingerprint) — optional; used only to unlock the App. Biometric data itself is handled by the operating system and is never seen or stored by the App.

The App does not request microphone, location, contacts, storage beyond backup export, or network access for telemetry.

Backups

The App can create encrypted backups of your accounts:

  • Backups are encrypted with AES-256-CBC using a key derived from your chosen backup password via PBKDF2 (100,000 iterations, SHA-256). An HMAC-SHA-256 is attached for integrity.
  • Export to file writes the encrypted backup to a location you choose via your device’s share sheet. We never see this file.
  • Email backup opens your device’s mail composer with the encrypted backup attached, addressed to the email you configured. The email is sent through your device’s mail account, not through us. We do not receive a copy.
  • We do not have access to your backup password. If you lose it, we cannot recover your backups.

Data Sharing

We do not share, sell, rent, or transmit your information. There is no server-side component, no account system, and no third-party SDK that receives your data.

Children’s Privacy

The App is not directed at children under 13. We do not knowingly collect information from children.

Security

All secrets are stored in the OS-provided secure keystore. PINs are stored only as a salted SHA-256 hash. Backups are encrypted client-side before leaving the App.

No software is perfectly secure. We recommend: using a strong PIN, enabling biometric lock, and keeping your device’s operating system up to date.

Your Rights

Because we do not collect your data, there is nothing on our servers to access, export, or delete. To remove all App data from your device, uninstall the App or use Settings to clear its data.

Changes to This Policy

If we update this policy, we will change the “Last updated” date above and post the revised version at the same URL.

Contact

Questions about this policy: support@getbdshield.com

BestDid Published at: https://getbdshield.com/bd-2fa-privacy