Privacy Policy
SentinelAuth is a two-factor authentication (2FA) app for Windows. It was built on a simple principle: your secrets are yours, and they stay on your device. This policy explains exactly what the app and this website do — and, more importantly, what they don't.
The short version
- SentinelAuth has no user accounts and no cloud.
- Your 2FA secrets are stored only on your device, encrypted.
- The app collects no analytics or telemetry — nothing is reported back to us.
- We never see, receive, sell, or share your accounts, codes, or personal data.
What the app stores, and where
Everything you add to SentinelAuth — the services you protect, their secret keys, your
settings, and any icons you choose — is stored in an encrypted vault in your own Windows user
profile (%APPDATA%\SentinelAuthenticator). The vault is encrypted at rest with
AES-256-GCM, using a key derived from your master password with Argon2id. Your master password
is never stored. None of this data is transmitted off your device by the app.
The one optional network feature
SentinelAuth includes an optional icon catalog so you can give your accounts
their real brand logos. It is off until you choose to use it, and the first
time you open it the app asks for your consent. When you use it, the app contacts
sentinelauth.app for a list of available icons and a public content-delivery network
(jsDelivr) for the image you pick. These are ordinary web requests: like visiting any website,
they reveal your IP address to those servers. The app sends no information about you,
your accounts, or which services you use. Icons you choose are saved locally in your
vault. You can disable this feature at any time in the app's Security settings.
This website
The SentinelAuth website (sentinelauth.app) is a static informational site. It
sets no advertising or tracking cookies and runs no third-party analytics. Like virtually all
web servers, the hosting server keeps standard access logs (including IP addresses and requested
pages) for security and reliability; these logs are not used to profile visitors and are not
shared.
Distribution & payments
When SentinelAuth is offered through the Microsoft Store, your purchase, installation, and any payment are handled entirely by Microsoft under Microsoft's own terms and privacy policy. We do not receive your payment details.
Data sharing
We do not sell, rent, or share your personal data, because the app does not collect it in the first place. There is no profile, no account, and no server-side record of you.
Children
SentinelAuth is a general-purpose security tool and is not directed at children. It does not knowingly collect any information from anyone.
Changes to this policy
If this policy changes, we'll update the date at the top of this page. Material changes will be reflected here before they take effect.
Contact
Questions about privacy? Email support@sentinelauth.app.