ZTAuth
Privacy Terms

ZTAuth

Privacy Policy

Last updated: August 7, 2026

ZTAuth is designed to keep your authenticator vault encrypted and under your control. This policy explains what the service processes and why.

Information we process

When you create a key account, ZTAuth processes the public authentication keys needed to verify your sign-in. When you use Google sign-in, Google provides account information such as your email address, display name, and provider identifier so we can create and maintain your account.

ZTAuth stores an encrypted vault envelope and the metadata needed to synchronize and protect it from concurrent writes. The vault contents are encrypted before they leave your browser. Google-authenticated vaults use a key kept in this browser; key accounts use credentials derived from your recovery phrase or private key.

The service and its hosting providers may also process technical information such as request timestamps, IP addresses, user-agent data, error details, and security logs for operation, abuse prevention, and debugging.

Google Drive

If you enable Google Drive sync, ZTAuth stores an encrypted vault file in Google Drive's private application-data area. ZTAuth requests only the Google Drive scope needed for that sync. Google handles that data under its own privacy policy and terms.

How we use information

  • To authenticate you and maintain your session.
  • To store, retrieve, synchronize, and integrity-check encrypted vault data.
  • To secure, monitor, troubleshoot, and improve the service.
  • To respond to support, privacy, and security requests.

Sharing and service providers

We do not sell your personal information. The service relies on infrastructure and integrations such as Netlify, MongoDB Atlas, Google authentication, and optional Google Drive sync. Those providers process information only as needed to provide their services, subject to their own terms and policies.

Retention and deletion

Account, session, encrypted vault, and audit data may remain while your account is active or as needed for security and operational records. To request account or data deletion, contact hello@azralabs.tech with enough information for us to identify the request. Deleting browser storage can permanently remove the only key capable of opening a Google vault; keep a trusted browser profile and any key-account recovery credentials safe.

Security limitations

No online service is completely secure. ZTAuth cannot recover a Google vault if its browser-held key is lost, and ZTAuth cannot recover a key-account vault without the recovery phrase or private key. Do not place secrets in support messages, logs, screenshots, or public issue reports.

Changes to this policy

We may update this policy as the service changes. The date above identifies the latest version. Material changes should be communicated through the project or service where practical.

Back to ZTAuth
Questions about these terms or your data? hello@azralabs.tech