ZeroOTP ZEROOTP
Home Privacy Security Terms Support
Privacy Policy

Privacy, without
surprises.

Effective date: April 27, 2026

ZeroOTP is a TOTP two-factor authenticator built to minimise data collection. ZeroOTP is operated by Mehmet Canhoroz. This policy explains what the app stores locally, what the sync backend needs to operate, and what we do not collect.

No Analytics Or Tracking

ZeroOTP does not include analytics SDKs, advertising SDKs, behavioral tracking, crash reporting tools, or third-party tracking pixels in our apps. We do not sell personal data. We do not share personal information for cross-context behavioral advertising.

Information Stored On Your Device

  • OTP records and categories: cached on device so your codes can load quickly. The local cache is encrypted before it is written to device storage.
  • Passcode-derived encryption material: stored using secure key storage provided by the operating system — iOS Keychain or Android Keystore — where available.
  • Settings: app preferences such as haptics, hide-codes, and biometric unlock are stored locally on your device.
  • Export files: when you export a backup, the file is created locally and shared or saved through the available system export flow. Export files contain plaintext OTP secrets, so store them carefully.

Biometric Data

Biometric authentication (Face ID, Touch ID, fingerprint) is processed entirely on-device by your operating system. ZeroOTP never accesses, stores, collects, or transmits your biometric data. We only receive a pass or fail result from the operating system.

Device Information

For device management and sync features, the app reads your device model, operating system version, app version, and device name. This information is used only to identify and display your connected devices in the account screen. We do not sell, share, or transmit this information to third parties for advertising or any purpose beyond operating the sync service.

Screen Capture Prevention

ZeroOTP prevents screenshots and screen recording while the app is open. This is a security measure to protect your displayed authentication codes from being captured.

Information Processed By The Server

If you use account or sync features, the backend may process and store your email address, user identifier, device identifier, device name, platform, operating system version, app version, session token, categories, and OTP records required to sync your vault across devices.

ZeroOTP requires passcode setup before vault use. OTP secrets are encrypted by the client before sync, and the server stores ciphertext for those secrets. Server-side data is used only to provide authentication, sync, device management, import, deletion, and related app functionality.

Email And Sign-In Codes

ZeroOTP uses email-based sign-in codes for account access. The backend stores short-lived verification code records with expiry and attempt limits. Production deployments encrypt verification codes at the application layer before storage. We use Resend (resend.com) to deliver verification emails. Resend processes your email address on our behalf solely to deliver those messages and is bound by appropriate data processing terms.

Permissions

  • Camera: used to scan TOTP QR codes. Not used for any other purpose.
  • Photo library: used when you import a QR code image. Not used for any other purpose.
  • Biometrics: used as an optional local access gate when enabled. Processed entirely on-device.

Sharing

We do not share your data with advertisers, data brokers, or third parties for marketing. We do not sell personal data. Data may be processed by infrastructure providers that host the app or backend, but only as strictly needed to operate the service.

Service Providers And Sub-Processors

We use the following third-party service providers to operate ZeroOTP. Each processes data only as needed for the purposes described:

  • Resend (resend.com) — email delivery for sign-in codes and account notifications.
  • Hosting and infrastructure providers — to run the backend API and database.
  • Apple App Store / Google Play — app distribution. Their privacy practices govern purchases and downloads made through their platforms.

Legal Requests And Business Transfers

We may disclose information if required by law, court order, or legal process, or to protect the rights, safety, and security of ZeroOTP, our users, or others. If ZeroOTP is acquired or its assets transferred, user data may be transferred as part of that transaction, subject to equivalent privacy protections.

International Data Transfers

Your data may be processed in countries other than your own, including countries where our service providers operate (such as the United States). When required by applicable law, we rely on appropriate legal mechanisms for those transfers, such as standard contractual clauses.

Website And External Assets

The ZeroOTP website loads fonts from Google Fonts and uses Tailwind CSS CDN. Those providers may receive standard browser request metadata (IP address, user agent, referrer). The website does not use advertising cookies or behavioural tracking cookies.

Retention

We keep server-side account and sync data while your account is active or as needed to provide the service. After account deletion, active account data is removed promptly. Backups, logs, security records, and operational records may be retained for up to 90 days unless a longer period is required for legal, fraud-prevention, security, dispute-resolution, or operational reasons. Local exports and files you create remain under your control.

Deletion

You can request account deletion from within the app. Deleting your account removes server-side account and sync data. Local exports or files you created remain under your control and must be deleted by you.

Your Privacy Rights

Depending on your location, you may have the right to access, correct, delete, restrict, object to processing of, or request a portable copy of personal data associated with your account. You may also have the right to lodge a complaint with a data protection supervisory authority in your jurisdiction. To make a privacy request, contact us at [email protected]. We may need to verify your identity before completing a request.

GDPR — European Users

If you are located in the European Economic Area, United Kingdom, or Switzerland, the following applies in addition to the above:

  • Data controller: ZeroOTP, operated by Mehmet Canhoroz. Contact: [email protected].
  • Legal basis for processing: where you use account or sync features, we process personal data on the legal basis of contract performance. Security logging and abuse prevention are based on legitimate interests. We do not rely on consent for core functionality.
  • Supervisory authority: you have the right to lodge a complaint with your local data protection authority.
  • Data transfers: where personal data is transferred outside the EEA, we rely on appropriate safeguards including standard contractual clauses.

California — CCPA Rights

If you are a California resident, you have the right to know what personal information we collect, request deletion, correct inaccuracies, and opt out of the sale or sharing of personal information. We do not sell personal information. We do not share personal information for cross-context behavioural advertising. To exercise your rights, contact [email protected].

Security Incidents

No service can guarantee perfect security. If we become aware of a data breach or security incident that requires user notice under applicable law, we will provide notice as required.

Children

ZeroOTP is not intended for children under the age of 13 (or the minimum age required by applicable law in your jurisdiction). If you believe a child has provided personal data to ZeroOTP, contact us so we can review and take appropriate action.

Governing Law

This Privacy Policy is governed by the laws of [JURISDICTION], unless mandatory consumer protection or data protection laws in your jurisdiction require otherwise.

Changes

We may update this policy when the app or service changes. The effective date above reflects when this version applies. Continued use after changes constitutes acceptance.

Contact

Privacy questions can be sent to [email protected].

Home Privacy Terms Security Licenses Support About © 2026 ZeroOTP Made with ♥ by Mehmet Canhoroz