The short version
- You can use Rotor without an account and without giving us anything. By default, Rotor uses no server of ours at all.
- Your codes are encrypted on your device. On iPhone, iPad and Mac they’re also kept in your own iCloud, encrypted, and sync between your Apple devices automatically.
- Our server is involved only if you choose it: to create the free Rotor account for Windows and Android, or to get security alerts by email. Even then it stores only encrypted data it can’t read.
- No ads, no trackers and no analytics, in the apps or on this site.
On your devices
Your accounts, their setup keys and codes, and their names are kept in an encrypted database on each device. The key that unlocks it stays in your device’s secure storage (Keychain, Android Keystore or Windows Hello), and Face ID, Touch ID, a fingerprint or Windows Hello can be required to use it.
Encrypted backup files you create are protected by a password only you know. We never see the file or the password.
Apple and iCloud
On iPhone, iPad and Mac, Rotor keeps your encrypted codes in your own iCloud (the app’s private CloudKit database) and its key in iCloud Keychain, which Apple encrypts end to end. That is how your codes reach your other Apple devices and come back after a reinstall. This data is in your Apple account, under Apple’s terms. We can’t read it or reach it.
If you sign in to the free Rotor account with Apple, we receive an identifier Apple creates for Rotor and the email address Apple shares, which can be a private relay address. If you allow notifications for new-device requests, our server keeps your device’s Apple push token; Apple can see that a notification was sent, and its content is only a request number.
If you choose our server
| If you… | We store |
|---|---|
| Do neither of the below | Nothing. Rotor doesn’t contact our server. |
| Create the free Rotor account | Your email address, the language of our emails and your sign-in method; for email sign-in, a keyed hash (HMAC, made with a secret only our server holds) of a key derived from your password, never the password itself; your encrypted accounts and encrypted keys; how many there are, their size and when they change; your devices’ platforms and when each was last seen; a record of sign-ins, devices joining or removed, and recovery, with the device’s platform and, for 30 days, its IP address |
| Add an email for alerts | The address, the language of our emails, when you confirmed it, whether you chose news and offers, and which wording you agreed to |
| Use either of the above | Server logs with IP addresses, the address of each request and the app version, kept for 30 days. Email addresses, codes, tokens and encrypted data are masked in the logs. |
| Use either of the above | A nightly backup copy of the data above, on our server, kept for 7 days. Your accounts in it are still encrypted. |
What we never see
- Your codes and setup keys, or the services and account names they belong to
- Your password, your recovery kit, or the keys that decrypt your accounts
- Your device names, vault names, notes and icons (they’re encrypted too)
- Whether your backup is on: backup reminders are notifications on your device, never email
Giving us an email address is optional, and Rotor works the same without it. We ask you to confirm the address from a link before we keep it (double opt-in).
- Security alerts and important updates: for example, that a new device joined your Rotor account.
- News and offers, including from ColossusCloud.com, only if you ticked that separate box.
Every email has a link to stop news and offers or all email, and mail apps can unsubscribe in one click. It takes effect at once.
Who else is involved
- Apple holds your iCloud data and delivers push notifications, as described above.
- Cloudflare serves this site and, if you use our server, carries its traffic. It sees what our server sees, including IP addresses.
- SendGrid delivers our email. It sees the address and the message.
- The app stores (Apple, Google, Microsoft) handle downloads and updates under their own policies.
We don’t sell or rent your data, and we don’t share it with anyone else.
Deleting your data
- Codes on a device: delete them in Rotor, or delete the app. Deleted accounts wait 30 days in Recently deleted, then disappear from every device.
- Your iCloud copy: remove Rotor’s data in your Apple account’s iCloud storage settings.
- Your Rotor account: delete it in Rotor, under Settings › Backup and sync › Rotor account. This removes the encrypted copy on our server and signs out your other devices; the codes on your devices stay. Without the app, you can ask for a deletion link by email instead. If you also gave an email for alerts, that stays until you remove it.
- Your email address: stop all email from the link in any message, or remove the address in Rotor, under Settings › Security › Email for alerts. To have it erased from our records, write to us.
After a deletion, two things stay for a short time. Server logs and the record of sign-ins and device events about the account stay for up to 30 days, without your email address. Our nightly backups keep a copy for up to 7 days. Then it’s all gone.
Getting a copy
With a Rotor account, Rotor can download everything our server holds about it: your account, your email choices, your devices (their names stay encrypted), how many vaults and accounts you have, and 90 days of security events, with IP addresses for the last 30. It never includes your codes: our server can’t read them, and they’re already on your devices.
Contact
Rotor is provided by ColossusCloud.com. [Operator’s legal name and address, to be added in legal review.] Questions about this policy: support@rotor2fa.com.