Personal information
Saved usernames or email addresses, vault item names, and website metadata are displayed so you can choose an item and fill it.
Authsia keeps credential processing on your devices. This policy covers the Authsia apps and Authsia Autofill for Chrome.
Effective Date: August 3, 2026
The short version
Authsia is an independently developed software project. Its developer does not collect or store personal data or in-app usage events on Authsia-operated servers. There are no ads, tracking pixels, data brokers, or analytics SDKs in the app. The download service keeps anonymous aggregate counts for release requests.
Authsia stores app data locally by default. If you enable iCloud Keychain Sync, Authsia also stores syncable copies in your personal iCloud Keychain. The Chrome extension communicates with the installed Authsia app through Chrome native messaging; it does not use that permission to contact a remote Authsia service.
When an initial macOS DMG request is made, the download service records only the distribution channel, Authsia version, allowlisted website placement, request outcome, two-letter country code, coarse operating-system family, coarse browser or client family, referrer domain, and a count of one. Unknown or invalid values use fixed fallback categories.
The event does not contain an IP address, raw user agent, full referrer URL or its path and query, cookie, account ID, device ID, or another persistent identifier.
A served outcome is an approximate download start; other outcomes distinguish missing or unavailable requests. These events are not unique-user, completed-download, installation, launch, or feature-usage counts. Measurement failure never blocks a download.
Authsia Autofill processes the following categories locally to match and fill a credential you select:
Saved usernames or email addresses, vault item names, and website metadata are displayed so you can choose an item and fill it.
A selected password or one-time verification code is retrieved after Authsia authorizes the request and is inserted into the selected field.
The current page hostname and URL are used to match saved items to the website requesting autofill.
The extension identifies login and verification-code form fields and writes the value you select into them.
Extension data is used only for credential matching and autofill. The current URL and detected field information are processed transiently in the browser and by the local native messaging host. A short-lived in-memory match result may be kept for the current page.
The extension does not record browsing history, monitor keystrokes, sell user data, use it for advertising or creditworthiness, or send it to Authsia-operated servers. Field focus and clicks may open the autofill interface, but are not retained as user-activity tracking.
We may update this policy to reflect changes in Authsia's practices. Material changes will be identified by updating the effective date at the top of this page.