SECURITY & PRIVACY FIRST
Privacy Policy
Last updated: October 8, 2026 • Effective immediately
Welcome to PSoft Authenticator (“the App”), developed by PVSoft (“we”, “our”, or “us”). We believe your passwords and two-factor authentication (2FA) tokens represent your most sensitive digital property. Our application is engineered from the ground up on the fundamental principle of Zero-Knowledge Architecture.
Key Guarantee: We do not know, store, or have access to your Master Password, your 2FA secret keys, or your stored credentials. All data is encrypted on your device using military-grade AES-256-GCM before any optional synchronization takes place.
1. Information We Do Not Collect
Because of our client-side Zero-Knowledge design:
- No Master Passwords: Your Master Password is never transmitted over the internet or saved to our servers in any form.
- No Plaintext Credentials: Your usernames, passwords, URLs, and custom fields are strictly client-encrypted.
- No Plaintext 2FA / TOTP Secrets: Your TOTP secrets and generated one-time codes remain exclusively on your device.
- No Personal Identity Tracking: We do not ask for or collect your real name, phone number, or contacts.
2. Information Processed During Synchronization
When you enable Online Mode (Cloud Sync), the app sends an encrypted envelope to our secure backend (authenticator.pvsoft.click):
- Encrypted Payload: A cryptographic blob encrypted with AES-256-GCM. Without your Master Password, this payload cannot be decrypted by anyone, including PVSoft and cloud infrastructure administrators.
- Technical Sync Metadata: Cryptographic IV (Initialization Vector), PBKDF2 salt, envelope version, and an anonymous device identifier necessary to detect conflicts across multiple devices.
- Item Count: Anonymous counts of TOTP and password items to verify synchronization integrity.
3. Offline Mode Guarantee
You may switch to Offline Only Mode at any time. When Offline Mode is active:
- All network communication related to your vault is halted 100%.
- Your vault items remain stored only within local encrypted storage on your physical device.
- You can independently purge all stored cloud envelopes at any time with a single click.
4. Device Permissions
PSoft Authenticator requests minimal permissions necessary for core operation:
- Camera: Used strictly to scan 2FA QR codes (otpauth://). QR code images are processed in real-time in memory and never stored or sent anywhere.
- Biometrics (Fingerprint / Face Unlock): Used locally through your operating system's secure hardware enclave (Keychain on iOS, Keystore on Android). Biometric data never leaves the hardware security module.
- Network Access: Used exclusively for optional cloud synchronization, app version verification, and error logging if enabled.
5. Data Retention & Deletion
You maintain complete ownership of your data at all times:
- You can export your unencrypted or encrypted vault to a standard JSON backup anytime.
- You can purge all synchronized data from the cloud server directly in Settings → Data & Cloud Sync → Purge Cloud Vault.
- Uninstalling the app in Offline Mode immediately removes all local vault data from your device.
6. Security Audits & Updates
We periodically review and update our cryptographic protocols. Any changes to this policy will be posted on this page and notified within the app release notes.
7. Contact Us
If you have any questions, concerns, or security disclosure reports regarding this Privacy Policy, please contact our security team:
Email: vutuyen120691@gmail.com
Website: https://pvsoft.click