Legal
Privacy Policy
How NexKey processes data across the NexKey apps, encrypted synchronization and this website.
Effective 25 August 2026
Draft for legal review. This document sets out the structure and the factual description of how NexKey works. The binding legal wording — the controller entity, lawful bases, retention periods and jurisdiction — must be confirmed by counsel before launch. Nothing here should be published as a legal commitment until that review is complete.
Overview
NexKey is an authenticator application for iOS, Android and macOS. It generates one-time passwords on your device. This policy describes what data NexKey processes, why, and what choices you have.
Two things are true of NexKey by design, and the rest of this policy follows from them:
- One-time codes are generated on your device, not on a server.
- If you turn on synchronization, your authenticator data is encrypted on your device before it leaves it.
Data we process
We process the smallest amount of data needed to run the service:
- Account data — if you create a NexKey account for synchronization, the identifier you register with and the credentials needed to authenticate you.
- Encrypted vault data — if synchronization is enabled, the ciphertext of your authenticator vault.
- Device records — the trusted devices you have enrolled, so you can review and revoke them.
- Diagnostics — if you opt in, technical information about crashes and errors.
- Website data — standard server request logs for this website.
Authentication data
Your authenticator secrets — the shared keys that produce your one-time codes — are stored in platform secure storage on your device: Keychain on Apple platforms and the Android Keystore on Android.
We do not receive readable authenticator secrets, and we do not receive the one-time codes NexKey generates.
This website does not generate one-time codes, does not accept authenticator secrets, and stores no authentication data in your browser.
Device information
When you enroll a device for synchronization we record what is needed to manage that relationship: a device identifier, a device name you can recognise, the platform, and the time it last synchronized. This exists so that you can review your trusted devices and revoke any of them.
Diagnostics
Diagnostic reporting is optional and off unless you enable it. When enabled, it is limited to technical information about failures.
Diagnostics never include authenticator secrets, generated one-time codes, the names of the services you hold accounts with, or the contents of your vault.
Encrypted synchronization
Synchronization is optional.
When it is enabled, your authenticator data is encrypted on your device before upload. Our backend stores and transfers that ciphertext. Decryption happens on your trusted devices.
You can disable synchronization at any time, which keeps your authenticator data local to each device.
Website
This site is a product and marketing website. It sets no advertising cookies and no cross-site tracking cookies.
Analytics is disabled by default. Where a deployment enables it, it is configured not to collect OTP-related data, account identifiers, secrets or the values you type into forms.
If you contact support through this website, we process the name, email address and message you send in order to answer you.
Retention
To be confirmed in legal review. Retention periods must be stated per data category — account data, encrypted vault data, device records, diagnostics, support correspondence and server logs — before publication.
Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing.
To be confirmed in legal review: the exact rights, the response window and the supervisory authority to which complaints may be directed.
Changes to this policy
If we make material changes to this policy we will update the effective date above and, where appropriate, notify you in the app.
Contact
Questions about this policy, or a request relating to your data, can be sent to our support address. Contact details are listed on the support page.