Skip to content
Human OTP
The threat How it works Safety Privacy
Get it free
← Back to Human OTP

Privacy Policy

Last updated: July 19, 2026

On this page

  1. The short version
  2. No accounts, no sign-up
  3. What lives on your device
  4. Pairing and the relay
  5. 2FA authenticator codes
  6. No analytics, tracking, or ads
  7. Device permissions
  8. Children
  9. Changes to this policy
  10. Contact

The short version

Human OTP is built so there is almost nothing to collect. You don't create an account. There is no profile of you on any server. Your contacts, your shared pairing secrets, and your two-factor (2FA) authenticator keys are stored only in the secure storage of the device you installed the app on. We don't sync them to a cloud, we don't back them up to our systems, and we don't have a copy.

There is one narrow exception worth being upfront about: during in-person pairing, if your device is online, the app automatically makes a brief connection to a pairing relay server that passes a tiny, disposable timing signal between the two phones to make the handshake smoother. It never receives your secret keys, your contacts, or your identity, and pairing works fully without it — but it isn't something you switch off in the app; to avoid it entirely, pair while your device is offline. The details are in Pairing and the relay.

No accounts, no sign-up

Human OTP has no user accounts. You don't register with an email address or phone number, you don't set a password with us, and there is nothing to log in to. Because there is no account, there is no account database — and nothing about you to breach, sell, or hand over.

The optional "display name" and other details you may enter about yourself (phone, email, note) are stored on your own device and are only ever shared when you show someone your pairing QR code in person. They are not transmitted to us.

What lives on your device

The information the app manages stays on your phone. On iOS, secret keys are held in the system Keychain (the operating system's encrypted secure storage), and contact details and settings are stored in the app's private storage on the device. This includes:

  • Your identity — the display name and any optional phone, email, or note you enter.
  • Your contacts — the people you've paired with and the labels you give them.
  • Shared pairing secrets — the per-contact secret keys used to compute the matching codes.
  • 2FA authenticator keys — the setup keys for any websites or apps you've added.
  • App settings — such as whether App Lock (passcode/biometric) is enabled.

If your device backs itself up (for example, an encrypted device or iCloud Keychain backup that you control), that backup is governed by your device and your operating-system settings, not by us. We never receive a copy.

Delete a contact and the secret is gone. Removing a contact erases its shared secret from the device. There is no server-side copy to fall back on — you'd pair again in person.

Pairing and the relay

You pair with someone by meeting in person and scanning each other's QR code. The shared secret passes directly between the two phones through the camera scan — it does not travel through any server.

What the relay does

To make the in-person handshake feel seamless, the app automatically uses a small pairing relay service when your device is online (currently hosted at emtanonapps.com). Its only job is a UX nicety: when one person scans the other's code, the relay lets the person showing the code know instantly, so their screen can flip from "show my QR" to "scan yours" without an extra tap.

What the relay does and doesn't carry

  • It carries a throwaway session identifier — a random one-time UUID generated for that single pairing attempt — plus the fact that a scan happened.
  • It does not carry your secret keys. The pairing secret is never sent to the relay.
  • It does not carry your identity or contacts — no name, phone, email, or contact list.
  • It holds nothing long-term. The session identifier is transient, used to coordinate a single handshake that lasts about a minute, and is not a durable record of you.

The relay is strictly best-effort and non-essential. It runs automatically during pairing when your device is online; there is no in-app switch to turn it off, but if you'd rather it never run, pair while your device is offline (for example, in airplane mode). If it is unreachable or your device is offline, pairing still works exactly the same way — you simply tap "Scan" yourself instead of the screen advancing automatically. No error is shown and nothing about the security of pairing changes.

As with any network request, the relay's hosting infrastructure may briefly process technical connection metadata (such as an IP address) to route the request, as is standard for internet services. The relay is not designed to log or retain this to build a profile, and it never links it to your identity — because your identity is never sent.

2FA authenticator codes

Human OTP can also act as a standard TOTP two-factor authentication (2FA) authenticator — the same kind of six-digit rotating code many websites offer. When you add an account, the app stores that service's setup key in your device's secure storage (the Keychain on iOS) and computes the codes locally on the device. These keys are treated exactly like your pairing secrets: they stay on your device, are never uploaded to us, and are removed from the device when you delete the account.

No analytics, tracking, or ads

We don't run third-party analytics or advertising SDKs in the app. We don't build a profile of who you talk to, we don't track your usage across other apps or websites, and we don't sell or share personal information — because we don't collect it in the first place. There are no advertising identifiers and no cross-app tracking.

Device permissions

The app requests the camera permission so you can scan QR codes when pairing with a person or adding a 2FA account. The camera is used only while a scanning screen is open, and the images are processed on your device to read the code — they are not stored or transmitted by the app. If you enable App Lock, the app may use your device's biometric (Face ID / Touch ID) or passcode through the operating system; that authentication is handled by the OS and never leaves your device.

Children

Human OTP is a general-audience security utility and is not directed to children. Because the app collects no personal information on a server and has no accounts, it does not knowingly gather data from anyone, including children.

Changes to this policy

If the way the app handles information changes, we'll update this page and revise the "Last updated" date above. Because there are no accounts, material changes will be communicated through the app or this website rather than by email.

Contact

Questions about this policy can be sent to support@humanotp.com.

Human OTP

Mutual human verification. Offline, private, and free.

The threat How it works Safety Get it Privacy Policy Terms of Service Support

© 2026 Human OTP. Codes stay on your device.