Privacy Policy

Privacy Policy

Effective Date: August 9, 2026

We value your privacy and data security. This Privacy Policy explains what information Otterkey processes when you use the App, why and where it is processed, the third-party services that may be involved, and how you can manage or delete that information.

This Policy reflects the actual functionality of the current version of Otterkey. We will update it as appropriate if the App's features, data-processing practices, third-party services, or applicable legal requirements change.

Publication note: This is a draft product privacy policy and does not constitute legal advice. Before publication, you must complete the effective date, operator identity, contact email address, and any address required by applicable law, and have the policy legally reviewed for every country or region in which the App will be distributed.

1. Otterkey's Data-Processing Principles

Otterkey is a local-first account, subscription, and two-factor authentication (2FA) management tool. Core data is stored on your device by default. If you choose to enable iCloud synchronization, the App stores a client-side encrypted vault snapshot in your private iCloud database.

The current version does not provide an Otterkey-operated account system and does not include advertising SDKs, third-party behavioral analytics SDKs, or third-party crash-reporting SDKs. We do not track you across apps or websites for advertising purposes. We do not sell your personal information, and we do not upload your account passwords, 2FA secrets, notes, or complete subscription list to servers operated by us.

2. Information We Process

Information that you voluntarily enter, select, import, or generate while using Otterkey may include:

  • Account information: service name, category, username, password, email address, phone number, sign-in method, website, notes, icon, color, custom logo, linked items, and recently deleted records.
  • Subscription information: service name, plan name, amount, currency, billing cycle, start date, renewal or end date, trial period, payment method, linked account, category, notes, and reminder settings.
  • 2FA information: service name, account label, 2FA secret, algorithm, number of digits, period or counter, linked account, category, notes, icon, and custom logo.
  • Contact entries: email addresses and phone numbers that you save or associate within the App. Otterkey does not access your system address book for this purpose.
  • Images: an avatar or custom service logo that you choose, and brand or App Store icons downloaded and cached by the App for service display.
  • Settings and preferences: custom categories, payment methods, sign-in methods, selected currency, cached exchange rates, notification settings, default reminder time, Face ID unlock preference, iCloud synchronization state, and user-interface settings.
  • Otterkey Pro information: an anonymous app user identifier generated for subscription management, product and package identifiers, trial eligibility, purchase and subscription status, purchase and expiration dates, cancellation, refund, or billing-issue status, and related app, device, and network technical information.
  • Imported files: supported third-party CSV, JSON, XML, ZIP, text, and 2FA data files that you choose to provide to the App. For backward compatibility, the App can also process a legacy password-protected .otterkeybackup file that you select.

Unless you voluntarily enter or import it, Otterkey does not require your legal name, government-issued identification, system contacts, text messages, calendar information, health data, or precise location.

3. Where Information Is Stored

3.1 On Your Device

  • Accounts, subscriptions, 2FA entries, contact entries, recently deleted records, and related business settings are assembled into a vault snapshot and stored locally using AES-256-GCM encryption. The corresponding key is stored in the iOS Keychain.
  • 2FA secrets also receive local protection through the iOS Keychain.
  • When you manually select the in-app backup action, Otterkey creates or updates an encrypted local backup in the App's sandbox. The App generates the backup key and stores it in the iOS Keychain; you do not create or remember a backup password. The backup reflects the data present when you last performed the backup action and is not automatically refreshed after later changes.
  • Service icons and their source metadata are cached in the Application Support/Otterkey directory to reduce repeated network requests.
  • Cached exchange rates, certain interface preferences, service region, logo-preloading state, and certain custom categories, payment methods, and sign-in methods are stored in local preferences.
  • Your selected avatar is included in the encrypted vault snapshot. It is therefore included in encrypted local storage, in a local backup when you manually create or update that backup, and in the client-side encrypted snapshot synchronized through iCloud when iCloud synchronization is enabled.

3.2 In iCloud

If you enable "Sync with iCloud":

  • Otterkey stores a client-side encrypted vault snapshot, including your selected avatar, in the CloudKit private database associated with your Apple Account. The uploaded data consists of ciphertext and synchronization metadata—such as the version, hash, key identifier, and revision—rather than directly readable plaintext business records or image data.
  • The cloud synchronization key used to decrypt the snapshot is stored through synchronizable iCloud Keychain. We do not store that decryption key on servers operated by us.
  • CloudKit and iCloud Keychain are provided by Apple and are processed under Apple's terms and privacy policy.

Disabling iCloud synchronization stops future automatic synchronization, but it does not automatically delete an Otterkey encrypted snapshot already stored in iCloud. You may use "Delete all data" within the App to delete the cloud snapshot managed by Otterkey, or use the iCloud management options provided by Apple.

4. How We Use Information

Otterkey processes information only as necessary to provide the following functionality:

  • Display, create, edit, link, search, sort, restore, and delete accounts, subscriptions, and 2FA items.
  • Generate one-time authentication codes locally on your device.
  • Calculate subscription spending, billing cycles, renewal dates, trial end dates, and reminder times.
  • Deliver local notifications relating to subscription items that you configure.
  • Store custom categories, payment methods, sign-in methods, avatars, logos, currencies, and other preferences.
  • Synchronize or restore a client-side encrypted vault through iCloud.
  • Manually create, update, and restore an encrypted local backup, import data that you select, or export third-party-compatible data at your direction.
  • Find and cache service icons using service identity, service name, App Store ID, bundle identifier, region, or a trusted canonical domain.
  • Retrieve exchange rates for a selected base currency.
  • Retrieve Otterkey Pro products and trial eligibility, process purchases through Apple, and determine current subscription entitlement status through RevenueCat.

We do not repurpose this information for advertising, data brokerage, user profiling, or cross-app tracking. If the purpose of processing changes materially, we will update this Policy and obtain renewed consent where required by law.

5. Device Permissions and System Capabilities

Otterkey may use the following system permissions and capabilities:

  • Camera: Used only when you open the 2FA QR-code scanner to recognize otpauth:// content locally on your device. The current implementation does not save camera footage or upload it to us.
  • Photos: Used to select an avatar or custom service logo. The App processes images that you choose. Service logos use the system photo picker, while the avatar feature uses the system image-selection interface. Otterkey does not create or upload a copy of your entire photo library for these purposes.
  • Notifications: Used to provide local reminders for subscription renewals, trial endings, expiration dates, and similar events. Notification content may include a service name, amount, or date and is handled by the iOS local notification system.
  • Face ID, Touch ID, or device passcode: Used to unlock Otterkey and to authenticate the device owner before exporting data containing passwords or 2FA secrets. Authentication is performed by Apple's LocalAuthentication framework. Otterkey does not receive or store facial templates, fingerprint templates, or other biometric data; it receives only the authentication result.
  • iCloud and Keychain: Used for optional encrypted synchronization, key protection, and cross-device recovery.
  • Files: Used only when you choose a file to import, export data, or use the system share interface.

You can manage camera, photo, notification, and other permissions in iOS Settings. You can also disable Face ID unlock or iCloud synchronization within Otterkey. Refusing or withdrawing a permission does not affect unrelated functionality, but the corresponding feature may become unavailable.

6. Network Requests and Third-Party Services

Otterkey may make network requests to the following services when necessary to provide App functionality:

6.1 Apple Services

  • CloudKit and iCloud Keychain: Used for encrypted data synchronization, key synchronization, and recovery that you choose to enable.
  • Apple iTunes Search API (itunes.apple.com): Used to query application identities and icons using an App Store ID, bundle identifier, or service name. A request may include a service name, App Store ID, bundle identifier, and region code.
  • Apple icon resources, generally hosted on mzstatic.com: Used to download and cache App Store icons.
  • Apple App Store and StoreKit: Used to display and process Otterkey Pro purchases, renewals, subscription management, and refunds under Apple's terms and privacy policy.

6.2 Brandfetch

When you search for or select a service, Otterkey may send the service search term that you enter to the Brandfetch Search API (api.brandfetch.io) to obtain candidate brand names, canonical domains, and logos. The App may then request an icon from the Brandfetch Logo CDN (cdn.brandfetch.io) using a canonical domain and the App's configured public client identifier. These requests do not include an account password, username, 2FA secret, note, or complete subscription list. Do not enter sensitive credentials as a service search term.

6.3 Exchange-Rate Service

Otterkey uses open.er-api.com to retrieve exchange rates. A request generally includes only the base currency code and does not include specific subscription names, subscription amounts, or a complete subscription list.

6.4 RevenueCat

Otterkey uses the RevenueCat SDK to retrieve Otterkey Pro products and offerings, determine trial eligibility, initiate purchases processed by Apple, restore purchases, and determine current subscription entitlement status. Requests may be routed through the configured RevenueCat backup API at api.rc-backup.com.

RevenueCat and its service infrastructure may process an anonymous app user identifier generated by the SDK, product and package identifiers, trial eligibility, purchase and subscription status, purchase and expiration dates, cancellation, refund, or billing-issue status, and technical information needed to operate the service, such as app version, operating-system version, device type, IP address, request time, and service logs. Otterkey does not send RevenueCat the account passwords, usernames, 2FA secrets, notes, contact entries, third-party subscription records, or imported files stored in your vault.

These services may process technical information necessary to complete a network request under their respective privacy policies, such as an IP address, request time, User-Agent, requested domain or parameters, and service logs. We use third-party services only to the extent necessary to provide the functionality described above and select or require them, under applicable law and their published terms, to provide protection for processed data that is equivalent to the protection described in this Policy. If we cannot ensure appropriate protection, we will stop transmitting relevant user data to the service or implement other lawful safeguards.

7. Data Sharing, Disclosure, and Tracking

Except for the iCloud processing and functional network requests described in Sections 3 and 6, we do not actively disclose your business data to third parties, except when:

  • You use a system share, export, or file-saving feature to send data to an app, service, device, or recipient that you select.
  • Disclosure is necessary to comply with applicable law, a court order, or a lawful request from a competent authority, and we are legally and technically capable of providing the relevant information.
  • Disclosure is necessary to protect users, the public, or our lawful interests and has a valid legal basis.

Otterkey currently does not use advertising identifiers, integrate advertising networks, request App Tracking Transparency permission, or combine data from the App with data collected by other companies from their apps, websites, or offline properties for targeted advertising or advertising measurement.

8. Backups, Imports, Exports, and Sharing

  • A local backup is created or updated only when you manually select the backup action. It is encrypted with an App-generated key stored in the iOS Keychain and includes the selected avatar and other vault data present at the time of your most recent manual backup. Later changes are not included unless you perform the backup action again.
  • Restoring a local backup requires the backup data and its corresponding Keychain key and may replace the current vault. Clearing the App's sandbox or Keychain data, uninstalling the App, resetting the device, or moving to another device may make that local backup unavailable or impossible to restore.
  • The current version does not create a portable backup for which you set a password. For backward compatibility, if you voluntarily import a legacy password-protected .otterkeybackup file, the App may request the password originally used for that file.
  • The current export function produces a plaintext Universal CSV migration file from the current vault, not an exported copy of the encrypted local backup. The file may contain accounts, passwords, email addresses, phone numbers, subscriptions, notes, and 2FA secrets. Otterkey authenticates the device owner and displays a warning before export, but it cannot control where an exported file is stored, with whom it is shared, or how a receiving service handles it.
  • Third-party import files are processed only after you select them. An import may add to or replace local data, as described in the confirmation interface shown for that operation.
  • Otterkey cannot delete external copies that you have copied, shared, or saved in Files, another app, another device, or a third-party service. You must delete those copies from their respective locations.

9. Data Retention, Deletion, and Withdrawal of Consent

  • Local business data is retained until you delete the relevant item, use an in-app deletion feature, uninstall the App, or iOS removes the App's data.
  • A deleted account may first be moved to "Recently Deleted" and retained there for up to approximately 30 days, during which it may be restored using the App's functionality. It is removed from Recently Deleted after the retention period expires.
  • Icon caches, exchange-rate caches, and preferences are retained until an App update or system action clears the cache, you change the relevant setting, or you uninstall the App.
  • Certain custom categories, payment methods, and sign-in methods are not currently deleted by the in-app "Delete all data" action. We will update this Policy if this behavior changes in a later version.
  • The in-app "Delete all data" action attempts to delete Otterkey's local encrypted vault, including the selected avatar, the local encrypted backup, Otterkey Keychain keys and 2FA secrets, and the Otterkey encrypted snapshot stored in your CloudKit private database. If cloud deletion fails, the App asks you to retry.
  • Deleting App data, disabling iCloud, or uninstalling Otterkey does not cancel an Otterkey Pro subscription and does not automatically delete purchase or subscription records retained by Apple, RevenueCat, or their service providers under their applicable terms, privacy policies, or legal obligations. Manage or cancel the subscription through Apple. You may contact us regarding a privacy request involving information under our control.
  • Uninstalling the App generally deletes files and preferences in its sandbox, but Keychain and iCloud retention remain subject to Apple's system behavior and the state of your iCloud account. If you want to delete both the cloud snapshot and keys managed by Otterkey, we recommend using "Delete all data" in the App and confirming that the operation completes before uninstalling it.
  • Disabling iCloud synchronization or Face ID unlock, or revoking a system permission, withdraws permission for the corresponding optional processing. It does not affect processing lawfully completed before withdrawal.

Because the current version does not provide an Otterkey-operated user account or an operator-accessible vault backend, we generally cannot use an email address alone to locate, read, or export content stored on your device or in your iCloud private database. You can access, correct, export, or delete your data directly within the App. If a feature does not work as expected, contact us using the information in Section 14.

10. Security Measures

Otterkey uses measures including the iOS app sandbox, file protection, Keychain, LocalAuthentication, and AES-256-GCM client-side encryption to protect data. Network requests use HTTPS. We also make reasonable efforts to limit third-party request parameters and avoid sending account passwords, 2FA secrets, notes, or complete subscription lists to icon or exchange-rate services.

However, no storage or transmission method can guarantee absolute security. Account passwords, 2FA secrets, recovery codes, Keychain-protected backup keys, and plaintext export files are highly sensitive. You should protect your device with a strong passcode, handle screenshots, screen recordings, notification previews, backups, and exported files carefully, and avoid storing sensitive credentials on a jailbroken, managed, or otherwise untrusted device.

11. Children's Privacy

Otterkey is not designed for children and is not listed in the App Store Kids category. We do not knowingly collect children's personal information through servers operated by us. If you believe that the App's data-processing activities do not comply with applicable children's privacy law, contact us using the information in Section 14.

12. Your Privacy Rights

Depending on the laws applicable where you live, you may have rights to access, correct, delete, restrict processing of, withdraw consent to, or obtain a portable copy of your personal information, and to submit a complaint. For information stored locally on your device or in your iCloud private database that we cannot read, use the App's editing, export, and deletion features to exercise those rights where possible.

If a request concerns information that we control, you may submit it using the contact information in Section 14. To protect security, we may verify the requester's identity and the scope of the request to the extent permitted by law.

13. Changes to This Policy

We may update this Policy because of changes to the App, third-party services, legal requirements, or the App's operator. If a change materially affects your rights or introduces a new use of data, we will provide notice through an in-app notice, publication page, or other appropriate method as required by applicable law, and obtain renewed consent where required.

The effective date at the top of this Policy identifies when the current version takes effect.

14. Contact Us

Contact email: hello@otterkey.app

If you have questions about this Policy, Otterkey's data-processing practices, or your privacy rights, contact us using the information above.