Authly is built with a zero-knowledge architecture. Your TOTP secrets are encrypted on your device with a key derived from your master password. We never see, store, or transmit your unencrypted secrets.
What we collect
Account email, encrypted vault blob, minimal usage telemetry required to keep the service running, and device metadata (user agent, last seen) for the devices you sign in from.
What we don't collect
We do not collect your master password, your TOTP secrets in plaintext, or your generated codes.
Third parties
We rely on privacy-respecting infrastructure providers. If you sign in with Google, only your email and public profile are shared with us.
Your rights
You may export or delete your vault at any time from Settings.
