bitwarden / bitwarden/ios

[BWA-234] Data Collection Concerns - Bitwarden Authenticator

Open
#2,363 3 comments 0 reactions 0 assignees View on GitHub
app:authenticator bug
Dominant language
Swift
Stars
684
Forks
154
Avg merge
7d 2h
Merged PRs (30d)
32

Description

### Steps To Reproduce

1. Go to the [release on the App Store](https://apps.apple.com/us/app/bitwarden-authenticator/id6497335175)
2. Scroll down to the "App Privacy" section

### Expected Result

No data should be collected.

Note that this is common practice in many other authenticators, such as [FreeOTP Authenticator](https://apps.apple.com/us/app/freeotp-authenticator/id872559395) and [Yubico Authenticator](https://apps.apple.com/us/app/yubico-authenticator/id1476679808).

### Actual Result

- "Contact Info" and "Identifiers" are collected as **Data Linked to You**
- "Contact Info" and "Diagnostics" are collected as **Data Not Linked to You**

I believe they are simply inherited from the main Bitwarden application, but that shouldn't be happening.

### Screenshots or Videos

Image

### Additional Context

Furthermore, neither the description nor your Privacy Policy clearly states what specific data are collected and how they are used.

Despite this additional context, please note that I believe this data should not be collected at all. I am not arguing that you simply need to justify its collection.
This is merely an OTP generator, and therefore should not require any additional data to function; as demonstrated by the apps mentioned above.

### Build Version

2026.2.0

### What server are you connecting to?

N/A

### Self-host Server Version

_No response_

### Environment Details

_No response_

### Issue Tracking Info

- [x] I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.

Contributor guide

Open the contributing guide

Research direction

Begin with the App Store release's App Privacy section and the issue's privacy-policy context, then determine whether the listed Contact Info, Identifiers, and Diagnostics disclosures belong to Authenticator or inherited metadata. Done means the Authenticator release no longer reports unnecessary collection and its published privacy disclosures accurately describe the app.

Written by the indexing model from the issue text.

Assessment

Tech stack
ios, swift
Domain
authentication, mobile, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.