KAVRI Privacy Policy
Effective date: September 18, 2026
1. Overview
KAVRI is a two-factor authentication (TOTP) app for Windows and Android. KAVRI is built local-first: your accounts, codes, and backups are stored and encrypted on your own device by default, and no KAVRI account is required to use the app. KAVRI does not currently operate a server that stores your vault or your Google account data — see Section 8. This policy explains what information KAVRI stores, what it receives if you choose to connect a Google account for optional Sync, and how that information is used.
2. Information stored in KAVRI
KAVRI currently stores the following categories of data, all created by you inside the app:
- Authenticator accounts — the account name, issuer, and TOTP secret key needed to generate your two-factor authentication codes, along with any projects you use to organize them.
- App settings — preferences such as theme and app-lock configuration.
- Backup files — encrypted backups you create, and the Recovery Key material needed to restore them.
KAVRI also includes an in-development, local-only password storage module. It is not yet a finished feature: it does not sync, is not included in Backup, and does not yet support revealing or copying a saved password. Nothing about it is described further here because it is not a stable, released part of the product.
3. Local storage and encryption
Your KAVRI vault is encrypted on your device using AES-256-GCM. The encryption key itself is protected by your operating system's platform key storage — Windows DPAPI on Windows, and the Android Keystore on Android — and access to the unlocked app can be gated behind Windows Hello or your device's biometric lock. KAVRI works fully offline; no internet connection or account is required for the app's core functionality. No security system is completely immune to compromise, and KAVRI does not claim otherwise — it is designed with multiple independent layers to reduce risk.
4. Google account information
If you choose to connect a Google account to use KAVRI Sync, KAVRI requests access to your Google account's email address and display name only, so it can show you which account is connected. KAVRI does not request or store your Google profile picture, locale, or a persistent Google account identifier beyond what is needed to maintain the connection.
5. Google Drive / Google Sync
Connecting Google is entirely optional and is never required to use KAVRI.
- Why KAVRI requests Drive access: to store the encrypted data KAVRI needs to keep your accounts in sync across your devices.
- What is stored: KAVRI Sync writes a single encrypted file to a hidden, app-only area of your Drive (Google's "app data" folder) that isn't visible in your regular Drive file list, and that KAVRI cannot use to see, list, or touch any other file in your Drive.
- Encryption before upload: KAVRI encrypts your account data on your device with AES-256-GCM before it is ever uploaded. Google stores only the resulting encrypted file — it can see that the file exists and its size and modification time, but not its contents.
- Sync is user-initiated: Sync is off by default. You turn it on from KAVRI's settings, and KAVRI continues to work fully without it.
- Disconnecting: Turning off Sync removes that device's Google sign-in and sync keys locally and stops it from syncing. It does not automatically delete the encrypted file already stored in your Google Drive, and it does not revoke KAVRI's Google account access on Google's side — you can revoke that at any time from your Google Account's security settings.
6. How Google user data is used
Google account information and Drive access are used solely to provide the KAVRI Sync feature you choose to enable. KAVRI does not sell Google user data, does not use it for advertising, and does not use it to build advertising profiles.
7. Google API Services User Data Policy
KAVRI's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Data sharing
KAVRI does not currently operate a server that stores your vault or your Google account data. Your data is stored locally on your device and, when you enable Sync, encrypted application data is stored in your own Google Drive — sent there directly from your device using your own Google account authorization, never through a KAVRI server. KAVRI does not share your data with third parties.
9. Data retention and deletion
Local data stays on your device until you delete it — either by removing individual accounts inside KAVRI, clearing the app's local data, or uninstalling the app. If you used Sync, disconnecting Google as described in Section 5 removes local sync keys and sign-in but does not automatically delete the encrypted file already in your Google Drive; you can delete that file yourself from Google Drive, or revoke KAVRI's access entirely from your Google Account settings.
10. Security
KAVRI uses layered, industry-standard techniques — AES-256-GCM encryption, OS-level key protection, and biometric app-lock support — to protect your data. No software can guarantee absolute security, and KAVRI does not claim to be unhackable or immune to compromise. We aim to reduce risk through independent security layers rather than relying on any single one.
11. Children's privacy
KAVRI is not directed at, or specifically designed for, children, and we do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy as KAVRI's features change. Material changes will be reflected by updating the effective date above. Continued use of KAVRI after a change constitutes acceptance of the updated policy.
13. Contact
Questions about this policy or KAVRI's handling of your data can be sent to kavricontact@gmail.com.