This policy explains how the Authier project (“Authier”, “we”, or “us”) collects, uses, shares, and protects information when you visit authier.pm or use Authier’s browser extensions, web vault, mobile clients, API, and related services. Authier operates from Czechia.
By using the service, you acknowledge the practices described here. This policy replaces the policy previously published for authier.ml.
1. Definitions
- Account means an account created to use Authier.
- Device means a browser, computer, phone, tablet, or other client that accesses the service.
- Personal data means information relating to an identified or identifiable person.
- Service means the Authier website, applications, extensions, vault, API, and related systems.
- Service provider means a third party that processes data to help us operate the service.
- Usage data means technical and activity information generated when the service is used.
2. The public website
The public marketing website does not use advertising trackers or behavioral analytics. It does not set its own analytics cookies. Cloudflare, which hosts and protects the website, may process request data such as IP addresses, browser information, timestamps, and security signals to deliver the site and prevent abuse.
3. Cookies and local storage
The marketing site does not set first-party analytics or advertising cookies. Authier’s interactive products use browser storage, session storage, and essential authentication tokens to keep you signed in, retain encrypted local state, remember settings such as theme or language, and complete billing flows. Refusing essential storage may prevent parts of the service from working.
Authier does not use Flash cookies. We do not place marketing pixels in the public website or use email beacons to build advertising profiles. Infrastructure providers may set narrowly scoped security cookies or process request signals under their own policies.
4. Information used to provide Authier
Depending on the feature you use, Authier may process:
- Account information, such as your email address and account identifiers.
- Encrypted vault payloads, containing credentials or TOTP data encrypted by your client before synchronization.
- Device and security information, such as device identifiers, platform, approval state, recent IP address, approximate location derived from network data, and security-event timestamps.
- Autofill-field metadata, such as a page URL with its query string removed, hostname, field type, DOM selector, and the account that submitted the record.
- Subscription information, such as the product selected, subscription state, and Stripe customer or checkout identifiers. Authier does not receive full payment-card numbers.
- Support and diagnostic information that you submit or that applications generate when something fails.
- Usage data, which can include request time, IP address, browser or operating-system information, pages or API operations used, and diagnostic or abuse-prevention signals.
5. Vault encryption
Authier clients encrypt vault items before they are sent to the API. The service stores encrypted payloads for synchronization. Your master password is used locally to derive an encryption key and is not sent to the Authier API as plaintext.
Encryption reduces what the service can learn from stored vault content, but it does not make all account or network metadata invisible. Device records, account identifiers, billing status, and operational logs may still be processed as described in this policy.
6. Shared autofill metadata
Authier maintains a shared corpus of login and TOTP form selectors so the extension can recognize fields on a site even when your account has not used that form before. These records can be returned to other authenticated Authier users for the same host. They contain page and field structure, not the username, password, or TOTP secret entered into the field.
Query strings are removed before a page URL is stored because they can contain sensitive values. The extension provides controls for removing matching autofill records. Abuse-prevention limits may delay or rate-limit deletion, including a one-week waiting period for newer free accounts.
7. Why information is processed
We use information to:
- create and operate accounts;
- synchronize encrypted vault data;
- authenticate users and approve, manage, or remove devices;
- process subscriptions and provide billing support;
- learn reusable, non-secret form selectors and improve autofill;
- detect abuse, investigate security events, and protect the service;
- diagnose failures and improve reliability; and
- comply with legal obligations and respond to valid legal requests.
We may also contact you about account verification, device access, security, subscriptions, support requests, or material service changes. If optional promotional communication is introduced, it will include the choices required by applicable law.
8. Service providers and disclosure
Authier relies on infrastructure and specialist providers where necessary to operate the service. These may include Cloudflare for hosting and network security, Stripe for subscription payments, Firebase for device notifications, and error-monitoring or email-delivery providers. Those providers process data under their own terms and privacy commitments.
We do not sell personal information and do not use vault content for advertising. We do not share personal data with business partners for their independent promotions.
Information may also be disclosed:
- with your direction or consent;
- to comply with a valid legal obligation, court order, or request from a competent public authority;
- to investigate wrongdoing, protect users or the public, defend Authier’s rights or property, or address legal liability; and
- in connection with a merger, financing, reorganization, asset transfer, or similar transaction, with notice where required.
9. Retention
Account information and encrypted vault data are retained while an account is active and as needed to provide the service. Billing and transaction records may be kept for legal, accounting, and fraud-prevention obligations. Security and operational logs are retained only for as long as reasonably needed for reliability, abuse prevention, and incident investigation.
Shared autofill-field metadata may remain useful after the contributing account is closed unless it is removed, anonymized, or no longer needed. Backups can retain deleted data for a limited period before routine rotation. We may retain records longer when law, fraud prevention, litigation, or enforcement of agreements requires it.
10. International processing
Providers may process data in countries outside your own. Where required, transfers are handled through applicable contractual or legal safeguards.
11. Security
Authier uses technical and organizational measures intended to protect information, including client-side encryption for vault contents, authenticated transport, device controls, access restrictions, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. A compromised master password, unlocked client, endpoint, recovery channel, or implementation flaw can still put data at risk.
12. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal data, and to complain to a data protection authority. You can also remove devices and manage subscription status through the product where those controls are available.
To exercise a privacy right, contact us using the address below. We may need to verify your identity and account authority before responding. You may also have the right to complain to your local data-protection authority.
13. Account and data deletion
Product controls can be used to remove vault items, devices, and supported autofill records. Contact us if you need help deleting an account or making a privacy request. Some billing, security, backup, and legal records may be retained as described above.
14. Children
Authier is not directed to children under 13, and we do not knowingly collect personal data from children under 13. Local law may require a higher age threshold.
15. Links to other websites
The service links to extension stores, GitHub, Stripe, community services, and other websites we do not operate. Their privacy practices are governed by their own policies. Authier is not responsible for third-party content or privacy practices.
16. Changes to this policy
We may update this policy when the product, providers, or legal requirements change. The date at the top of the page indicates the current version. Material changes may also be announced in the service or by email when appropriate.
17. Contact
Privacy questions or requests can be sent to authier.ml@gmail.com. Security vulnerabilities should follow the responsible-disclosure process in the Authier security policy.