Skip to content

Data & privacy

What AuthPlus records, where it goes, and how long it stays. Read this before deploying the app to customers.

Every completed scan or transfer writes one permanent line to the audit trail:

RecordedDetailVisible to
What was scannedThe code, and the item it belongs to when it is recognisedThe code’s owner, administrators
The resultAuthentic, a warning, or the reason it failedSame
WhenServer timestampSame
WhoThe verifier profileSame
The deviceA stable device identifier, plus manufacturer, model and operating systemSame
WhereNetwork address, resolved town or city, and precise coordinates when location is usedSame
SourceWhen usedPrecision
Device location (GPS)When the verifier type requires it, and permission is grantedPrecise — the actual position of the scan
Network addressOtherwiseApproximate — typically the town or the internet provider’s location
  • Uploaded files — logos, product images, certified documents — are stored unchanged, in their original form. They are not resized or re-encoded, so any metadata they contain (including photograph location data) is preserved.
  • Certified content is additionally fingerprinted, and that fingerprint is what verification compares.
  • When you verify a file from your own device, the file is not uploaded — only its fingerprint is sent. Verifying a link is different: the server downloads the file to fingerprint it.

AuthPlus is built to preserve evidence. The audit trail, in particular, is never edited or removed by the application.

RecordCan be removed?
Operations (verifications and transfers)No — permanent
Brands, products, assets, contents, items, issuances, codesArchived only, never deleted
User accountsArchived only
WarningsClosed, not deleted
Verifier accountsArchived only
Code types, print templates, verifier typesArchived only
Generated label documentsYes — deleted along with the stored file
Prohibited-name entriesYes

Only two things can be removed outright, and neither is a record of anything: a generated PDF or CSV, which you can produce again at any time, and an entry on the prohibited-name blocklist. Everything else is archived.

Records are otherwise kept indefinitely: AuthPlus applies no automatic retention limit, and there is no self-service account deletion. Erasure requests are handled manually by the platform operator.

StoredWhy
A device identifierIdentifies the automatic verifier profile so scan history is continuous.
Verifier profiles and the active oneSo you do not re-enter credentials at every launch.
Sign-in tokensKeeps you signed in to the dashboard.
Language, theme, and the administrator’s owner filterPreferences, per device.

AuthPlus uses no analytics, no advertising and no tracking cookies, and loads no third-party fonts or scripts. The only external call made by the app is the location lookup described in How location is determined.

Removing a verifier profile in the app removes it from that device only; the account and its history remain on the server.

Codes can be exported as CSV per issuance (Labels & exports), and label sheets as PDF. There is no bulk export of operations, catalogue or account data from the interface — an operator with database access can produce one on request.