Fuzzy Auth Privacy Policy

Effective date: July 15, 2026

Fuzzy Auth is an offline authenticator app by Fuzzyhead. This policy explains how the app handles information on Android.

Data collection

Fuzzy Auth does not collect, transmit, sell, or share personal data. The app has no account system, backend service, analytics SDK, advertising SDK, or third-party tracking SDK.

Authenticator secrets and codes

Authenticator account names, issuers, folders, and one-time-password secrets are stored locally on your device. Secrets are stored using Android encrypted storage backed by the Android Keystore. One-time codes are generated on your device and are not sent to Fuzzyhead or any third party.

Camera access

Fuzzy Auth may request camera permission so you can scan QR codes for authenticator setup or migration import. QR code scanning is processed on your device for the purpose of importing authenticator entries. Camera images are not uploaded, stored by Fuzzyhead, or shared with third parties.

Biometric and device unlock

Fuzzy Auth can use Android biometric or device credential prompts to protect access to your authenticator codes. Biometric data is handled by Android and is not accessible to Fuzzy Auth or Fuzzyhead.

Backups and exports

If you create an export or backup, the file is created locally on your device. You control where that file is saved or shared.

Children

Fuzzy Auth is not directed to children under 13 and does not knowingly collect information from children.

Changes

Fuzzyhead may update this policy if the app changes. The effective date above will be updated when material changes are made.

Contact

If you have questions about this privacy policy, contact hello@fuzzyhead.net.