Privacy Policy
Last updated: September 1, 2026
Overview
Muha Authenticator ("we", "our", or "us") is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data.
Information We Collect
- Account information: Username, email address, and hashed password when you create an account.
- Encrypted vault data: Your authenticator entries are encrypted client-side. We store only the encrypted ciphertext and cannot read your secrets.
- Usage data: Device information, IP addresses, and session metadata for security and sync purposes.
- Security events: Login attempts, password changes, and other security-related actions.
How We Use Your Information
- Provide and maintain the Muha Authenticator service
- Authenticate your identity and manage sessions
- Sync your encrypted vault across devices
- Detect and prevent fraud and abuse
- Improve our products and services
Data Security
We implement industry-standard security measures including TLS encryption in transit, Argon2id password hashing, and a zero-knowledge architecture for vault data. Your master password and encryption keys never leave your device.
Your Rights
You may access, update, or delete your account at any time through the dashboard. You can revoke devices and sessions, export your data, and request account deletion by contacting support.
Contact
For privacy-related inquiries, contact us at privacy@muha-authenticator.com.