Effective date: July 15, 2026
Fuzzy Auth is an offline authenticator app by Fuzzyhead. This policy explains how the app handles information on Android.
Fuzzy Auth does not collect, transmit, sell, or share personal data. The app has no account system, backend service, analytics SDK, advertising SDK, or third-party tracking SDK.
Authenticator account names, issuers, folders, and one-time-password secrets are stored locally on your device. Secrets are stored using Android encrypted storage backed by the Android Keystore. One-time codes are generated on your device and are not sent to Fuzzyhead or any third party.
Fuzzy Auth may request camera permission so you can scan QR codes for authenticator setup or migration import. QR code scanning is processed on your device for the purpose of importing authenticator entries. Camera images are not uploaded, stored by Fuzzyhead, or shared with third parties.
Fuzzy Auth can use Android biometric or device credential prompts to protect access to your authenticator codes. Biometric data is handled by Android and is not accessible to Fuzzy Auth or Fuzzyhead.
If you create an export or backup, the file is created locally on your device. You control where that file is saved or shared.
Fuzzy Auth is not directed to children under 13 and does not knowingly collect information from children.
Fuzzyhead may update this policy if the app changes. The effective date above will be updated when material changes are made.
If you have questions about this privacy policy, contact hello@fuzzyhead.net.