Last updated 9 September 2026
The short version. AuthNest has no server. Your passwords are encrypted on your phone before they go anywhere, and the encrypted result is stored in your own Google Drive. The developer cannot read your vault, cannot reset your master password, and receives no analytics about how you use the app.
There is no AuthNest account, no sign-up, and no marketing list.
This policy applies to the AuthNest app for Android and the AuthNest browser extension, published by Neh Patel. Contact: nehpatel.authnest@gmail.com.
Your vault holds what you put in it: site names, usernames, passwords, two-factor secrets, passkeys, notes, tags and website addresses.
Encryption happens on your device before any upload. Your master password is stretched with Argon2id into a key that unwraps your vault key; records are sealed with XChaCha20-Poly1305. What reaches Google Drive is ciphertext.
Nothing. There is no AuthNest server. No vault content, master password, recovery key, email address, device identifier or usage data is transmitted to the developer or to any third party operating on the developer's behalf.
The developer cannot read your vault, cannot recover it, and cannot reset your master password. This is a property of how the app is built, not a promise about how we behave. If you lose both your master password and your recovery key, the vault cannot be opened by anyone.
AuthNest asks you to sign in with Google so it can use your own Drive for storage. It requests a single Drive permission:
drive.appdata — access to a private application folder inside your
Google Drive. This scope cannot see your documents, photos or any
other file in your Drive. It can only read and write files AuthNest itself created
there.Your Google account's email address is used to label the signed-in account in the app's interface and to make sure a vault is only ever opened by the account that owns it. It is kept on your device and is not transmitted to the developer.
AuthNest's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.
AuthNest requires internet access for two things only:
/.well-known/assetlinks.json file from that website. This is a plain
request for a public file. It carries no vault content, no identifier and nothing about
you, and it exists to stop a malicious app claiming to be your bank.The app makes no other network connections.
None. The app contains no analytics SDK, no advertising SDK, no crash-reporting service and no third-party tracking code of any kind. It does not collect an advertising identifier.
Google Play separately provides the developer with aggregate, anonymous statistics — install counts, country totals, crash rates. These come from Google Play itself, not from code inside the app, and they identify no individual.
getauthnest.com sets no cookies, runs no analytics, and loads no fonts, scripts or images from third parties. Your visit is not tracked. Standard server access logs may be kept by the hosting provider for security and reliability.
You are in control of everything, because all of it is yours:
Because the developer holds no copy of your data, there is nothing to request deletion of and no account to close.
AuthNest is not directed at children under 13 and does not knowingly collect any information from them. It collects no personal information from anyone.
If this policy changes, the revised version will be posted here with a new date at the top. Material changes affecting how your data is handled will also be noted in the app's release notes.
Questions about this policy or about how AuthNest handles data: nehpatel.authnest@gmail.com.