Privacy and personal data

Privacy policy (Rieck Authenticator)

Revised17 August 2026 In force from17 August 2026

Rieck Authenticator is the app that generates the six-digit one-time codes. It has no server, and your accounts and secret keys stay encrypted on the phone — the app sends them nowhere. This policy sets out what that means in practice, what we do process, and what you can require of us.

§ 1

The short answer

The app sends none of your information anywhere. Your accounts, your secret keys and the recovery codes you store stay on the phone, encrypted — and we have neither access to them nor any way of gaining it.

So we do not know which services you use the app for, and we cannot see when you unlock it or which codes it shows.

The app makes one network call, and it is not about you: it asks whether an update to the app itself is available. What that call contains is set out in section 4.

§ 2

Who is responsible

We are the data controller for the processing described in this policy. It covers Rieck Authenticator — the iPhone and Android app that generates one-time codes. If you use rieckflow.com, or if you are a debtor in a collection case, one of our other policies applies to you.

Company
Rieck Inkasso ApS
Address
Østergade 4, ground floor, 8370 Hadsten, Denmark
Company reg. no.
41645369
Phone
35 15 47 65

We are not required to appoint a data protection officer and have not done so. Questions about this policy and about your rights should therefore be directed to the address above.

§ 3

What the app stores on your phone

The app is built without a server. Everything you put into it stays on the device:

Account name and issuer
For example "Google" and your email address at that service, so you can tell your accounts apart.
The shared secret
The key the service gave you during setup. Without it the code cannot be calculated.
Recovery codes
Your services' own codes, if you choose to store them, so they sit alongside the account.
The key to the vault
In Keychain (iPhone) and Keystore (Android) — hardware-backed storage outside the app’s own file space.
Language and appearance
So the setting is remembered for next time.

The vault is encrypted with a key derived from your six-digit code. Both the vault and the key are marked as available only on this particular device and only while it is unlocked. They are therefore not included in iCloud backup, Google backup or transfer to a new phone, and on Android automatic cloud backup is switched off for the entire app.

We receive none of it. The processing takes place solely on your own device and under your own control, and we are not the data controller for that content — we have neither technical access to it nor a copy of it.

§ 4

What we actually process

The only places where we process information about you are support, the app stores' own tools and the update channel:

PurposePersonal dataLegal basisRetention
Answering your enquiry if you write to us about the appName, email address and whatever you writeArticle 6(1)(f) — our legitimate interest in supporting a product we publish24 months after the case is closed
Reading and replying to reviews in the App Store and Google PlayThe display name and review text the store makes availableArticle 6(1)(f) — our legitimate interest in understanding and improving the productFor as long as the review remains in the store. We keep no copy
Viewing aggregate crash and install statistics in the stores' developer consolesAggregate figures on operating system and device model. We receive no device identifier and cannot trace the figures back to a personArticle 6(1)(f) — our legitimate interest in detecting faults that affect usersThe store's own period
Delivering fixes to the app without waiting for store approvalThe app id, which version your phone has, and — as with any call over the internet — your IP address. Nothing about your accounts is sent, and nothing that says who you areArticle 6(1)(f) — our legitimate interest in being able to fix a security fault in an authenticator quicklyLogged by our update provider under their own retention period

The categories of personal data are therefore ordinary contact details and free text. In connection with the app we process no special categories of data, no national identity number and no criminal offence data.

§ 5

What we do not do

So that it is not left as an omission: the app contains no analytics tool, no third-party crash reporting, no advertising, no advertising identifier, no cross-app or cross-site tracking, no cookies and no user account.

There is no password to create with us, because there is nothing to log in to.

§ 6

The permissions the app asks for

Camera
Only to scan a QR code when you add an account. The image is read in memory and is not stored — on the device or anywhere else. The permission is optional; you can type the key in instead.
Face ID, Touch ID and fingerprint
Only to unlock the app. The face or fingerprint itself is handled by the operating system inside the device’s secure area and never becomes available to the app. We are only told whether the unlock succeeded.
Internet (Android)
Required for Android's WebView to start, and for the update call in section 4. The app makes no other calls.

§ 7

Are you obliged to provide the information

No. The app requires no name, email or account in order to work, and there is neither a statutory nor a contractual requirement to give us any information.

The information you enter into the app is necessary for it to calculate your codes — without a secret there is no code — but it is not handed to us. Writing to our support is voluntary; if you choose not to provide an email address, we simply cannot reply.

§ 8

Who receives the information

The app's content is not disclosed, because we do not hold it. For support and store access, the recipients are:

Our email provider
As data processor for support correspondence. The provider processes the data on our instructions and appears on our list of sub-processors.
Ionic (Appflow)
As data processor for the update channel. They are who the phone asks whether a new version of the app is available, and they therefore see the app id and your IP address. They see nothing about your accounts — there is nothing for them to see.
Apple and Google
As independent data controllers for what they themselves collect when you download, pay for or review an app. That happens in their systems under their own policies, and we have no influence over it.

We do not sell personal data and we do not disclose it for marketing purposes. We disclose information to public authorities where we are legally obliged to do so.

§ 9

Transfers outside the EU/EEA

The app transfers none of your information. The update call, on the other hand, goes to our update provider, which is American, so your IP address is processed outside the EU/EEA.

Support correspondence may likewise be processed outside the EU/EEA if our email provider does so.

Both transfers rely on the European Commission's standard contractual clauses or on an adequacy decision, and you can obtain a copy of the safeguards by writing to us.

§ 10

How long the information exists

On the phone
Your accounts remain until you delete them yourself. Deleting the app deletes both the encrypted vault and the key in Keychain/Keystore. There is no copy anywhere else — including with us.
Support
We delete correspondence once it no longer serves a purpose, and no later than 24 months after the case is closed.

§ 11

How we protect the information

Secrets are encrypted on the device with a key derived from your code through 600,000 iterations, and the vault key is held in Keychain and Keystore rather than in the app’s own files.

The app switcher and screenshots are blocked inside the app, so the phone does not keep an image of your valid codes in the file system.

The app can update itself between store releases, so a security fault can be fixed the same day rather than in a week. That path is closed in three ways: the update must be signed with our own key or the phone rejects it; it is fetched in the background and only put to use while the app is locked; and it can change only the app’s own code — it can never have the vault handed to it.

§ 12

Automated decision-making and profiling

We make no automated decisions producing legal effects or similarly significant effects for you, and no profiling takes place — neither in the app nor in connection with support.

§ 13

Your rights

You have the right of access to the personal data we process about you, and the right to have inaccurate data rectified, to have data erased, to have processing restricted, and to data portability. You may object to processing based on our legitimate interest — that covers everything in section 4. Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

Write to us at the address in section 2 to exercise a right. We reply within one month.

§ 14

Complaints

If you are unhappy with how we process your data, we would like to hear from you first. You may always complain to Datatilsynet:

Authority
Datatilsynet (the Danish Data Protection Agency)
Address
Carl Jacobsens Vej 35, 2500 Valby, Denmark
Phone
33 19 32 00

§ 15

Children

The app is not directed at children and does not knowingly collect information about children. As the app collects no information at all, no age limit attaches to its use.

§ 16

Changes to this policy

If we change the app so that it processes information differently, we will update this page before the change takes effect. Material changes are noted in the app stores’ release notes.

This policy was last updated on 17 August 2026.

Questions about your data

If you want to know what we hold on you,
ask — and we will find it.

Access, rectification, erasure or an export: write to us, and we will get started. The law gives us a month; we answer sooner.

Contact us

Call on any business day or write — we reply within 2 hours on any business day.

35 15 47 65 rieck@rieckflow.com

Complain about data protection

If you are unhappy with the way we process your information, you can complain to Datatilsynet (the Danish Data Protection Agency).

datatilsynet.dk

Request your data

Access, rectification or erasure — we have written down how you ask, and what happens next.

Request your data
  • 30 days free
  • No payment card
  • One day's notice