← AuthNest

Privacy Policy

Last updated 9 September 2026

The short version. AuthNest has no server. Your passwords are encrypted on your phone before they go anywhere, and the encrypted result is stored in your own Google Drive. The developer cannot read your vault, cannot reset your master password, and receives no analytics about how you use the app.

There is no AuthNest account, no sign-up, and no marketing list.

Who this covers

This policy applies to the AuthNest app for Android and the AuthNest browser extension, published by Neh Patel. Contact: nehpatel.authnest@gmail.com.

What AuthNest stores, and where

Your vault holds what you put in it: site names, usernames, passwords, two-factor secrets, passkeys, notes, tags and website addresses.

Encryption happens on your device before any upload. Your master password is stretched with Argon2id into a key that unwraps your vault key; records are sealed with XChaCha20-Poly1305. What reaches Google Drive is ciphertext.

What the developer receives

Nothing. There is no AuthNest server. No vault content, master password, recovery key, email address, device identifier or usage data is transmitted to the developer or to any third party operating on the developer's behalf.

The developer cannot read your vault, cannot recover it, and cannot reset your master password. This is a property of how the app is built, not a promise about how we behave. If you lose both your master password and your recovery key, the vault cannot be opened by anyone.

Your Google account

AuthNest asks you to sign in with Google so it can use your own Drive for storage. It requests a single Drive permission:

Your Google account's email address is used to label the signed-in account in the app's interface and to make sure a vault is only ever opened by the account that owns it. It is kept on your device and is not transmitted to the developer.

Google API Services User Data Policy

AuthNest's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Connections the app makes

AuthNest requires internet access for two things only:

The app makes no other network connections.

Analytics, advertising and tracking

None. The app contains no analytics SDK, no advertising SDK, no crash-reporting service and no third-party tracking code of any kind. It does not collect an advertising identifier.

Google Play separately provides the developer with aggregate, anonymous statistics — install counts, country totals, crash rates. These come from Google Play itself, not from code inside the app, and they identify no individual.

This website

getauthnest.com sets no cookies, runs no analytics, and loads no fonts, scripts or images from third parties. Your visit is not tracked. Standard server access logs may be kept by the hosting provider for security and reliability.

Clipboard, screenshots and the lock screen

Deleting your data

You are in control of everything, because all of it is yours:

Because the developer holds no copy of your data, there is nothing to request deletion of and no account to close.

Children

AuthNest is not directed at children under 13 and does not knowingly collect any information from them. It collects no personal information from anyone.

Changes to this policy

If this policy changes, the revised version will be posted here with a new date at the top. Material changes affecting how your data is handled will also be noted in the app's release notes.

Contact

Questions about this policy or about how AuthNest handles data: nehpatel.authnest@gmail.com.