1. Overview
This Privacy Policy explains how Matech Mobile (“Matech Mobile,” “we,” “us,” or “our”) handles information when you use the Authenticator & Secure VPN Android application (the “App”) and this website.
The App provides two-factor authentication, password organization, encrypted cloud backup, VPN connection, Wi-Fi security, and related security features. Some data stays on your device, while optional features and third-party services require limited data processing as described below.
2. Information we process
Information stored on your device
Depending on the features you use, the App may store account labels, 2FA setup secrets and parameters, generated-code counters, notes, backup codes, password entries, folders, preferences, and VPN settings on your device. This information is used to provide the features you request.
Diagnostics, analytics, advertising, and attribution
The App uses service providers for analytics, crash reporting, remote configuration, notifications, advertising, and install or purchase attribution. These providers may process device and app identifiers, advertising identifiers where permitted, approximate location derived from IP address, device model and operating system, language, app interactions, ad events, install source, purchase or subscription events, crash logs, diagnostics, and network information.
Purchases
Google Play processes in-app purchases and subscriptions. We may receive purchase status, product, transaction identifiers, and related validation information, but we do not receive your full payment-card details.
VPN and network features
When you activate a VPN connection, network traffic must pass through the selected VPN infrastructure to provide the service. Technical information such as your source IP address, destination information, connection time, and transferred data may be processed transiently as necessary to establish and operate the connection, protect the service, and address abuse or reliability issues. Network requests are also made when the App retrieves configuration, advertising, analytics, and other online content.
Support communications
If you contact us, we process your email address and the contents of your message, including any diagnostic information you choose to send, to respond and provide support.
Website data
Our hosting infrastructure may process standard request logs such as IP address, requested page, browser type, referring page, and date and time for security, reliability, and troubleshooting.
3. Google user data and Cloud Backup
Cloud Backup is optional. If you choose to connect a Google account, the App requests these OAuth scopes:
openidanduserinfo.emailto identify and display the Google account you selected.drive.appdatato create, list, download, restore, and delete backup files in the App’s private Google DriveappDataFolder. The App cannot use this scope to browse your normal Drive files.
The App may also display the selected account’s profile image when available through Google Drive account information.
How backup content is protected
A backup may contain your 2FA credentials and parameters, HOTP counters, account labels, notes, backup codes, password entries, and folders. Before upload, backup content is encrypted on your device using AES-256-GCM with a user-controlled recovery key. The recovery code is never uploaded to Google or Matech Mobile. You must keep it safe; neither Google nor Matech Mobile can recover it for you.
Use, sharing, and retention of Google user data
Google account information is used only to authorize the selected account, show it in the App, and provide the backup features you initiate or enable. Encrypted snapshots remain in your Google Drive app-data folder until you delete them. Google authorization tokens are handled by Google’s authorization services and are not intentionally logged by the App.
We do not use Google user data for advertising, creditworthiness, or personalized marketing; sell it; or transfer it to data brokers. We do not allow humans to read Google user data unless you give affirmative permission for a specific support or security purpose, doing so is necessary to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
Authenticator & Secure VPN’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deleting backups
You can delete individual snapshots from Cloud Backup in the App. Disconnecting your Google account revokes the App’s authorization and disables automatic backup, but does not automatically delete existing encrypted snapshots. You may delete them before disconnecting or remove the App’s hidden data from your Google Drive settings. You can also revoke access from your Google Account security settings.
4. Device permissions
- Camera: scan QR codes to add compatible 2FA accounts.
- Location and Wi-Fi information: inspect the connected Wi-Fi network and provide Wi-Fi security features where supported by Android. Android may require location permission to access Wi-Fi details.
- Biometrics: ask Android to authenticate you before protected actions. The App does not receive your fingerprint or face data.
- Notifications: deliver service and app notifications where you allow them.
- Network and VPN: access the internet, check connectivity, and create a system-managed VPN connection when requested.
You can manage permissions in Android settings. Some features may not work if their required permission is denied.
6. Retention and security
On-device information remains until you delete it, clear App data, or uninstall the App, subject to Android backup settings. Encrypted Google Drive snapshots remain until you delete them. Support messages and operational records are retained only as long as reasonably necessary for support, legal, security, and business purposes. Third-party providers apply their own retention periods.
We use technical and organizational safeguards designed to protect information, including authenticated encryption for Cloud Backup. However, no storage or transmission system is completely secure, and we cannot guarantee absolute security. Keep your device, recovery code, and account credentials protected.
7. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, or to withdraw consent. You can manage local App content directly, reset advertising choices in Android, manage Google authorization in your Google Account, and delete cloud snapshots in the App.
To make a privacy request, email us. We may need to verify your request. Because we do not operate an account database for your local 2FA and password data, we generally cannot retrieve or delete information stored only on your device or decrypt your cloud backups.
8. Children
The App is not directed to children under 13, or the minimum age required by local law to consent to data processing. We do not knowingly collect personal information from children in violation of applicable law. Contact us if you believe a child has provided information improperly.
9. International processing
Our providers may process information in countries other than where you live. Where required, we rely on appropriate safeguards for international transfers.
10. Changes to this policy
We may update this Policy to reflect changes to the App, providers, or law. We will publish the revised version here and update the effective date. Material changes may also be communicated in the App where appropriate.
11. Contact us
For privacy questions or requests, contact:
Matech MobileEmail: contact.matechmobile@gmail.com
Website: authenticator.matechmobile.com