WiraPass is an authenticator app. It stores two-step verification codes (TOTP and HOTP) and receives approval requests from other connected systems, for example when someone tries to sign in to such a system with your account. This policy covers the WiraPass app and its service at auth.wiracode.com (and its former address, auth.wiracode.my.id).
You can sign in with a Google account, with Apple (on iPhone), or with an email address and password. You can create an email account yourself in WiraPass: we send a 6-digit code to that email to make sure it is yours, and WiraPass keeps only a hash of your password (scrypt), never the password itself. Older email accounts made at our account service are still checked by that service: WiraPass forwards the email and password to be checked without storing them. The account service is run by the same operator.
1. Who Is Responsible
WiraPass is developed by WIRA Code Indonesia. WIRA Code Indonesia is the controller of your personal data and runs the WiraPass servers itself.
Questions and requests about personal data: support@wiracode.com.
2. Data We Process
| Data | What it includes |
|---|---|
| Account | Email address, the display name from the service you signed in with, when the account was created and when you last signed in. |
| Sign-in methods | For each way you sign in: the provider (Google, Apple or email), your account ID at that provider, the email the provider reports, and whether the provider guarantees that you own that email. If you sign in with Google, also the address of your Google profile photo, refreshed each time you sign in with Google, to show as your account photo in the app. Only the address is stored; the photo stays at Google. If you sign in with Apple, the email may be an Apple private relay address, and an Apple token is stored encrypted only to revoke WiraPass access in your Apple account when you delete your account. |
| Sign-in sessions | A random token stored on the server, when it was created and last used, a device label from the User-Agent (for example "WiraPass 0.5.0 · Android"), and the approval phone bound to that session. |
| Code vault | For each code entry you add: issuer, label, secret key, algorithm, number of digits, period, counter and when it last changed. Kept on the phone and backed up to the server in encrypted form (section 9). |
| Approval phones | Phone name, the phone’s public key, whether that key is protected by the screen lock, a Firebase Cloud Messaging token for notifications, status (pending, active, revoked), and when it was registered, activated, revoked and last active. |
| Approval requests | The requesting system, the title and the context that system sends (application name, account, IP address, location text, device text; all optional), then the status, times and the phone that answered. WiraPass itself also creates a request when a new phone asks to join your account. |
| Backup code | The secret of the 6-digit backup code that changes every 30 seconds, stored encrypted, with a marker of the last code used so each code works only once. The number of wrong attempts in a row is also recorded. |
| Security log | Important actions with the IP address and User-Agent: sign-in, sign-out, vault saves, data exports, registering, activating and revoking phones, requests and their answers, backup code use, and invalid phone signatures. |
| WiraPass email account password | Only a hash of the password (scrypt with a random salt per account), for as long as the account exists. The password itself is never stored or logged. The 6-digit code to sign up or reset the password is stored as a hash for at most 10 minutes. |
| Security emails | We email your account address when a new approval phone becomes active, when an "old phone lost" recovery starts, when the account is deleted, and when someone tries to sign up for a new account with your already registered email. These emails contain no codes and no sign-in links. A 6-digit code is only sent when you sign up or ask for a password reset yourself. |
| Account icons | To show an icon for each code entry, the app sends the service’s domain (for example github.com), or the image address from that entry’s QR code, to the WiraPass server. Account names, labels and secret keys are never sent. The server fetches the icon from that website and keeps a temporary copy (section 6) without recording who asked for it. The app also keeps the icon on the phone. |
| Camera | Only to scan authenticator QR codes. Scanning happens on the phone and the image is not sent to our server. |
Exporting codes as a QR code (Google Authenticator migration format) happens on the phone only, not through the server.
WiraPass does not access the phone’s location, contacts, SMS, call log, photos, the list of other apps or advertising IDs. A location shown in a request is text from the requesting system, not your phone’s location. The app has no ads, analytics, tracking or third-party crash reporting. Outside the app, only Brevo records when an email from WiraPass is opened (section 4).
3. Purposes and Legal Bases
We process data in line with Indonesia’s Law No. 27 of 2022 on Personal Data Protection (UU PDP), for:
- Providing the service: storing and restoring your codes, and delivering and recording approval requests (performance of a contract).
- Security: preventing account takeover and request flooding, checking phone signatures, keeping the security log and sending security emails (legitimate interest).
- Legal obligations, when a competent authority requires it.
Data is not sold and is not used for advertising or marketing profiles.
4. Who Receives Data
| Recipient | Data and reason |
|---|---|
| Integrated systems | Systems registered by the operator, each with an API key, to request approvals. Such a system learns whether your email uses WiraPass approvals, how many approval phones are active and signed in, whether a backup code is set up, the answers to its requests, and whether a backup code you type into it is right. It does not receive your codes, vault contents or phone keys. |
| Google LLC | Firebase Cloud Messaging delivers notifications. They carry only the requesting system’s name, the request title and the random ID of the target phone; the IP address and other context are not sent. Google Sign-In, if you sign in with Google; the app then loads your Google profile photo directly from Google’s servers, which therefore see your phone’s IP address. Google ML Kit scans QR codes on Android phones. According to Google, the library may send device and app information and usage metrics for diagnostics, without the scanned image. |
| Brevo (Sendinblue SAS) | Delivers WiraPass’s emails (security emails and 6-digit codes) to your account address. Brevo receives your email address and the content of that email, and keeps a record of its delivery. Brevo also puts a small invisible image in the email to record when it is opened, with the IP address and the mail app that opened it. |
| Apple Inc. | iPhone only, once the iPhone version is released. Sign in with Apple, if you sign in with Apple, including revoking its token when the account is deleted. Notifications to iPhones travel through the Apple Push Notification service with the same content as in the Google row. |
| Cloudflare, Inc. | Network and HTTPS encryption in front of auth.wiracode.com (and its former address, auth.wiracode.my.id). All app traffic and these pages pass through it. |
| Email account service | Only for older email accounts made at our account service: the email and password are sent to that service to be checked, with your IP address for attempt limits. This service is run by the same operator and only answers right or wrong, with the account ID and name. Email accounts made in WiraPass are never sent there. |
| Your services’ websites | For account icons, the WiraPass server contacts the service’s website, not your phone. It only asks for the site’s home page or its icon image, so the website sees the WiraPass server’s IP address instead of yours. WiraPass sends that website no data about you. |
| Competent authorities | If applicable law requires it. |
5. Server Location and International Transfers
The WiraPass servers, database and backups are in Indonesia and run by the operator. Off-server backup copies are kept on the operator’s own internal S3 storage, not on a third-party cloud service.
Google, Apple (on iPhone), Cloudflare and Brevo (France) may process the data in section 4 outside Indonesia. Cloudflare decrypts HTTPS on its network and encrypts it again towards our server, so data in transit, including the vault backup, passes through the Cloudflare network.
These transfers are covered by the providers’ data processing agreements (Firebase Data Processing and Security Terms, Cloudflare Data Processing Addendum, Brevo Data Processing Agreement, and Apple’s terms), which include standard contractual clauses. Each service receives only the data it needs, and everything is encrypted in transit, in line with Article 56 of UU PDP.
6. How Long Data Is Kept
| Data | Kept for |
|---|---|
| Account, sign-in methods, vault backup, backup code | As long as the account exists. Deleted at once when the account is deleted. |
| Sign-in sessions | End exactly 30 days after sign-in and are not extended by use. They end sooner when you sign out or delete the account. |
| Approval requests | Deleted 90 days after creation. |
| Approval phones | Until revoked. A revoked phone is deleted 90 days after revocation. |
| Security log | Deleted 180 days after it was written, or at once with the account. After deletion only one record remains that an account was deleted, with no ID, email or IP address. |
| Account icons on the server | Icon copies are kept for 7 days and a note that a website has no icon for 24 hours, then they are deleted automatically. These copies are not linked to anyone’s account. |
| Codes on the phone | Until you sign out of WiraPass, delete the account from the app, or uninstall the app. |
| Database backups | Encrypted (GPG, AES-256). Hourly backups are kept for 48 hours, daily backups for 30 days on the server, and the off-server copy for 90 days. Data from a deleted account can stay in these backups until they are removed, at most 90 days, and is only used for disaster recovery. |
7. Your Rights
Under UU PDP, you have the right to:
- access and get a copy of your personal data, right in the app under Settings, Download my personal data (a JSON file you can take to another service). Codes can be moved with Move to another app;
- correct inaccurate data;
- delete your account and data at any time (section 8);
- withdraw consent, for example by turning off notifications or revoking an approval phone;
- restrict or object to certain processing;
- sue for and receive compensation for violations in the processing of your personal data (Article 12 of UU PDP);
- complain to the personal data protection authority.
Rights that are not in the app can be exercised through support@wiracode.com. We handle requests to access, correct, stop, pause or restrict processing, and delete within 3 × 24 hours of receiving a valid request.
8. Deleting Your Account and Data
You can delete your WiraPass account at any time in the app under Settings, Delete WiraPass account. The account, sign-in methods, vault backup, approval phones, requests, backup code, security log and all sessions are deleted at once. If your account has an active approval phone, the deletion must be confirmed from that phone. Full instructions, including when a phone is lost or you cannot sign in, are on the account deletion page.
9. Security
- The vault backup on the server is encrypted with AES-256-GCM using a server key and is bound to your account. This is server-side encryption, not end-to-end encryption: the operator, who holds the server key, can technically decrypt it.
- On the phone, codes are kept in the system’s secure storage (Android Keystore, or the iPhone Keychain marked this device only) and are left out of the system’s cloud backup.
- Each approval phone creates its own key pair in the phone’s secure hardware. The private key never leaves the phone; the server keeps only the public key to check signatures. If your account has an approval phone, the vault is only opened for a session bound to that phone, so a stolen password alone is not enough.
- Approve only works while the phone is unlocked. At most 3 requests wait for an answer at once. "Not me" denies the other requests from that system and holds its new requests for 15 minutes.
- The backup code locks after 10 wrong attempts in a row until it is replaced from an active phone. A new phone recovered without the old one becomes active only after 24 hours, and the old phones are told first.
- On Android, screenshots and screen recordings of the app are always blocked. All traffic between the app and the server uses HTTPS.
- If a personal data protection failure happens, we notify you and the personal data protection authority in writing within 3 × 24 hours, stating the data exposed, when and how it happened, and the steps taken (Article 46 of UU PDP).
10. Children
WiraPass is meant for users aged 18 and over. We do not knowingly process children’s data.
11. Device Permissions
| Permission | Used for |
|---|---|
| Camera | Scanning authenticator QR codes on the phone. |
| Biometrics | The app lock (fingerprint, face or screen lock) and unlocking the phone key when approving. Biometric data stays on the phone and never reaches us. |
| Notifications | Showing approval requests. |
| Internet and network state | Connecting to the WiraPass server. |
| Install updates | Only in the Android APK shared directly, not the Google Play version: installing updates you download. |
12. Changes to This Policy
Changes appear on this page with the date they were made. We announce important changes in the app.