Privacy Policy for OTP Safe
Privacy Policy for the iOS App OTP Safe according to GDPR
Privacy Policy for OTP Safe
Effective Date: September 2026
1. Controller
Mathias Todisco
Schleswiger Ufer 5
10555 Berlin
Germany
Email address: hello [at] todisco [dot] de
Phone: +49 179 8174113
Imprint: Imprint
2. Introduction
OTP Safe is an iOS app for securely managing two-factor authentication codes (TOTP and HOTP). The protection of your personal data is important to us. This privacy policy informs you about the processing of your data when using our app.
3. Data Processing
3.1 Local Data Storage
OTP Safe is a completely local app. We collect and process the following data:
- OTP Accounts: Service name, username, secret key, algorithm, time interval
- Categories: Self-created categorizations of your accounts
- App Settings: Sorting, view preferences
Important:
- All data is stored exclusively locally on your device
- No cloud synchronization by the app - Your secrets are never transmitted to us or third parties. They are part of your encrypted iOS backup (iCloud Backup or an encrypted backup on your Mac/PC) and are transferred when you move to a new iPhone, so they are not lost
- No trackers or analytics tools - We do not collect any usage data for advertising or marketing purposes
- No advertising - The app is ad-free
3.2 Security Features
- iOS Keychain: Sensitive data is stored encrypted in the iOS Keychain
- Biometric Authentication: Face ID / Touch ID / Optic ID to unlock the app
- Encrypted Export: AES-256 encryption for backup files
3.3 Camera Access (optional)
If you allow camera access, OTP Safe can scan QR codes to add new accounts. The scanned data is only processed locally and not transmitted.
3.4 File Access (optional)
When importing or exporting backups, the app accesses local files. This data is only processed locally.
3.5 Feedback Function (optional)
If you use the optional feedback function, the following data is transmitted to our server (api.todisco.de):
- Required information: Category, subject, message, timestamp, language setting
- Optional information: Email address (only if you provide it)
- Device information (optional): Device model, iOS version, app version (only if you consent to transmission)
Important:
- The feedback function is completely optional
- Your OTP secrets and account data are never transmitted
- The data is used exclusively to process your feedback
- Processing takes place on servers in Germany
3.6 Error Reports (Crash and Error Telemetry)
To be able to fix bugs and crashes, the app transmits technical error reports in release builds to our self-hosted GlitchTip server at tip.todisco.de (hosted in Germany, no third-country transfer).
What is transmitted:
- Crash reports: Stack traces, threading information, affected modules/functions
- Error events: Error type, error message, timestamp, context tag (e.g. “BackupService.decrypt”)
- Device context: Device model, iOS version, app version, free/available memory, language setting
- Performance samples: ~1% of all app transactions (screen load times, navigation performance)
- Breadcrumbs: Anonymized navigation steps (e.g. “Settings opened”, “Backup started”), to provide error context
What is NOT transmitted:
- No OTP secrets (never part of an error report)
- No account names (issuer/service name/username remain local)
- No unique device IDs beyond what Sentry/GlitchTip automatically hashes (device-app-hash, no IDFA)
Technical details:
- Based on the Sentry Cocoa SDK (open source)
- Backend: GlitchTip (open-source alternative to Sentry), self-hosted by us in Germany
- Session tracking is disabled
- In DEBUG builds (development builds), events are tagged with environment “debug” and treated separately
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in a functional, error-free app).
Retention: Error reports are stored for a maximum of 90 days and then automatically deleted.
Opt-out: In DEBUG builds, telemetry can be disabled via the environment variable OTP_DISABLE_TELEMETRY=1. For release builds, telemetry is active by design; if you do not want this, please uninstall the app.
4. Legal Basis for Processing
The processing of your data is based on the following legal grounds:
- Art. 6 para. 1 lit. b GDPR (Contract fulfillment): Provision of app functions
- Art. 6 para. 1 lit. a GDPR (Consent): Use of the optional feedback function
- Art. 6 para. 1 lit. f GDPR (Legitimate interest): Error reports to ensure app functionality
5. Data Sharing
Your OTP data is not shared with third parties. Network communication only occurs with our own servers in Germany: api.todisco.de (feedback) and tip.todisco.de (error reports). Your OTP secrets and account data are never transmitted.
6. Data Storage and Deletion
6.1 Storage Duration
Your data is stored locally on your device as long as you use the app. You have full control over your data at all times.
6.2 Deletion
You can delete your data at any time:
- Individual Accounts: Delete in the app
- Categories: Delete in the app
- All Data: Uninstall the app from your device
7. Your Rights
You have the following rights:
- Right of Access (Art. 15 GDPR): All data is directly viewable in the app
- Right to Rectification (Art. 16 GDPR): Edit accounts directly in the app
- Right to Erasure (Art. 17 GDPR): Delete data directly in the app
- Right to Data Portability (Art. 20 GDPR): Export your data encrypted
- Right to Lodge a Complaint: With the competent data protection supervisory authority
8. Data Security
We take appropriate technical and organizational measures to protect your data:
- Local storage under iOS security mechanisms
- Encrypted storage in iOS Keychain
- Biometric protection (Face ID / Touch ID / Optic ID)
- AES-256 encrypted backups
- Minimal network communication (only optional feedback function)
iOS Security: Your data benefits from iOS sandboxing and device encryption.
9. No Profiling
There is no automated decision-making or profiling according to Art. 22 GDPR.
10. Changes to this Privacy Policy
We reserve the right to update this privacy policy to reflect changes in law or app features. The current version can always be found at:
https://todisco.de/en/otp-privacy
11. Contact
For privacy questions, contact us at:
Email: hello [at] todisco [dot] de
Address: Mathias Todisco, Schleswiger Ufer 5, 10555 Berlin, Germany
Note for users outside the EU:
This privacy policy is primarily based on the EU General Data Protection Regulation (GDPR). Users from other regions may have corresponding rights under local privacy laws.