Effective Date: July 24, 2026
This policy explains how EasyMeta Pty Ltd (ABN 83 664 794 781) handles information in the Authloom app. Authloom is a local-first 2FA authenticator. EasyMeta does not create an Authloom account, show ads, operate behavioural analytics, or include a third-party crash-reporting SDK. The optional Google Drive feature uses Google’s sign-in SDK as described below.
Authloom processes the following information locally:
Portable data is stored in an AES-256-GCM encrypted vault. Its key is protected by iOS Keychain or Android Keystore. A recovery phrase used for on-chain backup is encrypted in device secure storage, and its signing key is derived locally.
QR images, recovery phrases, signing keys, and plaintext TOTP secrets are not sent to EasyMeta.
Cloud backup is off until you enable it. Authloom can store an encrypted backup in your private iCloud CloudKit database or Google Drive App Data folder. Apple or Google may process account identifiers, authorization details, and storage metadata under their own policies. Authloom does not read your Apple ID or Google password.
On iOS, the Google Sign-In SDK’s Apple privacy manifest declares these data types. On Android, Google Sign-In may return the selected account’s email, ID, display name, and profile-picture URL. Authloom uses only the email and account ID for Google Drive authorization and account-change detection. EasyMeta operates no server that receives this profile information.
iCloud uses a recovery key protected by iCloud Keychain. Google Drive uses a backup password that derives an encryption key on your device; the password is not uploaded.
When you enable this option, Authloom uses PublicNode RPC to access the Polygon or Ethereum network. PublicNode may process your IP address, on-chain address, and RPC requests under its own policy.
Submitting a backup permanently publishes an on-chain address, transaction details, and encrypted backup records. The ciphertext does not contain plaintext TOTP secrets, but the address, transactions, and ciphertext can be viewed, copied, and linked by anyone and cannot be deleted. The recovery phrase, signing key, and plaintext TOTP secrets are not sent to PublicNode or the blockchain.
Public records also reveal backup count, token creation timestamps, and favourite-state metadata; issuer, account name, and TOTP secret are encrypted.
A code is written to the system clipboard only when you copy it. Supported platforms mark it as sensitive and clear it after a short period. Deleted secrets remain recoverable for up to 30 days; after that, sensitive fields are removed and only a minimal deletion record remains to prevent an old device from restoring the token.
Authloom does not create an account, so there is no Authloom account-deletion process.
Authloom uses authenticated encryption and platform secure storage to reduce risk, but no system can eliminate every risk from a compromised device, screenshots, operating-system vulnerabilities, or disclosure of a password, QR code, or recovery phrase. Authloom is not directed to children and does not ask for age information.
We will update the effective date above when this policy materially changes.
The EasyMeta website uses cookie-free, self-hosted aggregate analytics. This does not change how the Authloom app handles data. See the EasyMeta website privacy policy.
For privacy questions, visit Authloom Support.