This page explains how AuthGeek handles your two-factor secrets and every other piece of data it touches. It applies to AuthGeek 1.0.0 and later. Last updated 26 September 2026.
The short version
- Your OTP secrets, account names, issuers and any QR pictures you import never leave your computer.
- There is no account, no server, no sync, no telemetry, no analytics and no crash reporting.
- AuthGeek uses no third-party processors. The only network request it can make is the update check, and only when you click Check for updates.
- TechyGeeksHome never receives, sees or stores any of your data.
What stays on your computer
- The vault. Every account lives in one file,
%LOCALAPPDATA%\TechyGeeksHome\AuthGeek\accounts.authgeek. It is encrypted with AES-256-GCM using a key derived from your master password with Argon2id. Your master password is never stored; the key is held in memory only while the vault is unlocked and is dropped when it locks, on request or after the idle timer. - The previous vault. Each save keeps the version before it as
accounts.authgeek.bakin the same folder, encrypted in exactly the same way, so a failed save cannot lose your accounts. - QR pictures. When you add an account from a picture of a QR code, AuthGeek reads the picture where it already is on your disk. It does not copy, upload or keep the picture.
- The error log.
error.login the same folder is written only when something goes wrong. It never contains a secret, a code or an account name, and it never leaves your computer.
Backups and exports you create
- Encrypted backup: the same encrypted format as the vault, saved wherever you choose. It opens only with AuthGeek and the password.
- Plain text export: one
otpauth://link per line, saved wherever you choose. It is not encrypted. Anyone who can read that file can generate your codes, so store it somewhere safe and delete it when you no longer need it. - AuthGeek keeps no copy of either file and does not track where you saved them. Deleting them is up to you.
Copying a code
Copying a code puts it on the Windows clipboard. AuthGeek does not send it anywhere, but if you have turned on Windows clipboard history or clipboard sync across devices, Windows itself may keep or sync it. Codes expire within seconds, but if that matters to you, leave those Windows features off.
Checking for updates
AuthGeek never checks for updates on its own. When you click Check for updates, it makes one unauthenticated request to GitHub’s public API (api.github.com) to read the latest release number and compare it with the version you are running. GitHub receives your IP address and a user agent of the form TechyGeeksHome-Updater/1.0.0, the same as if you opened the releases page in a browser. No secrets, account details, file names or usage data are sent. If a newer version exists AuthGeek offers to open the release page; it never downloads or installs anything itself. GitHub handles the request under the GitHub General Privacy Statement.
Deleting your data
- Delete an account inside AuthGeek and it is removed from the vault on the next save.
- To remove everything, delete the folder
%LOCALAPPDATA%\TechyGeeksHome\AuthGeek. That removes the vault, the.bakcopy and the error log. - Uninstalling AuthGeek deliberately does not delete the vault, because it holds secrets that may exist nowhere else. Export or back up first if you need to, then delete the folder yourself.
- There is no copy anywhere else and no way for anyone, including TechyGeeksHome, to recover a lost master password or vault.
Questions
The source code is public, so every statement on this page can be checked. Open an issue on GitHub or use the contact page. Back to the AuthGeek product page.