Back to Authsia

Privacy Policy

Authsia keeps credential processing on your devices. This policy covers the Authsia apps and Authsia Autofill for Chrome.

Effective Date: July 28, 2026

The short version

Authsia is an independently developed software project. Its developer does not collect or store your personal data on Authsia-operated servers. There are no analytics, ads, tracking pixels, or data brokers. Authsia processes credentials, page context, and form fields locally only to provide the feature you request.

1. Overview

Authsia stores app data locally by default. If you enable iCloud Keychain Sync, Authsia also stores syncable copies in your personal iCloud Keychain. The Chrome extension communicates with the installed Authsia app through Chrome native messaging; it does not use that permission to contact a remote Authsia service.

2. Chrome Autofill data

Authsia Autofill processes the following categories locally to match and fill a credential you select:

Personal information

Saved usernames or email addresses, vault item names, and website metadata are displayed so you can choose an item and fill it.

Authentication information

A selected password or one-time verification code is retrieved after Authsia authorizes the request and is inserted into the selected field.

Web browsing activity

The current page hostname and URL are used to match saved items to the website requesting autofill.

Website content

The extension identifies login and verification-code form fields and writes the value you select into them.

3. Use and retention

Extension data is used only for credential matching and autofill. The current URL and detected field information are processed transiently in the browser and by the local native messaging host. A short-lived in-memory match result may be kept for the current page.

The extension does not record browsing history, monitor keystrokes, sell user data, use it for advertising or creditworthiness, or send it to Authsia-operated servers. Field focus and clicks may open the autofill interface, but are not retained as user-activity tracking.

4. Data storage

  • Secrets: OTP seeds, passwords, secure notes, certificate and SSH private keys, and passphrases are stored in Apple Keychain. Storage is local by default.
  • Metadata: Names, issuers, folders, settings, and list-safe vault fields are stored in Keychain. A local macOS CLI cache contains non-secret list metadata only.
  • Optional sync: If you enable iCloud Keychain Sync, Apple processes synchronizable Keychain data under your Apple account.

5. Sharing and third parties

Authsia does not sell or transfer user data to data brokers, advertisers, or unrelated third parties. It does not use analytics or advertising services.

When you direct the extension to fill a website, that website receives the values placed in its form and handles them under its own privacy policy. Optional iCloud Keychain Sync is handled by Apple under your Apple account.

6. Permissions

  • Native messaging: communicates with the locally installed Authsia app.
  • Website access: recognizes credential fields, matches the current hostname or URL, and fills the item you select on HTTPS sites and local development pages.
  • Camera: the app uses camera access only when you scan a QR code. Images are not sent to a server.

7. Changes to this policy

We may update this policy to reflect changes in Authsia's practices. Material changes will be identified by updating the effective date at the top of this page.