[BWA-234] Data Collection Concerns - Bitwarden Authenticator
- Dominant language
- Swift
- Stars
- 684
- Forks
- 154
- Avg merge
- 7d 2h
- Merged PRs (30d)
- 32
Description
### Steps To Reproduce
1. Go to the [release on the App Store](https://apps.apple.com/us/app/bitwarden-authenticator/id6497335175)
2. Scroll down to the "App Privacy" section
### Expected Result
No data should be collected.
Note that this is common practice in many other authenticators, such as [FreeOTP Authenticator](https://apps.apple.com/us/app/freeotp-authenticator/id872559395) and [Yubico Authenticator](https://apps.apple.com/us/app/yubico-authenticator/id1476679808).
### Actual Result
- "Contact Info" and "Identifiers" are collected as **Data Linked to You**
- "Contact Info" and "Diagnostics" are collected as **Data Not Linked to You**
I believe they are simply inherited from the main Bitwarden application, but that shouldn't be happening.
### Screenshots or Videos
### Additional Context
Furthermore, neither the description nor your Privacy Policy clearly states what specific data are collected and how they are used.
Despite this additional context, please note that I believe this data should not be collected at all. I am not arguing that you simply need to justify its collection.
This is merely an OTP generator, and therefore should not require any additional data to function; as demonstrated by the apps mentioned above.
### Build Version
2026.2.0
### What server are you connecting to?
N/A
### Self-host Server Version
_No response_
### Environment Details
_No response_
### Issue Tracking Info
- [x] I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
Contributor guide
Research direction
Begin with the App Store release's App Privacy section and the issue's privacy-policy context, then determine whether the listed Contact Info, Identifiers, and Diagnostics disclosures belong to Authenticator or inherited metadata. Done means the Authenticator release no longer reports unnecessary collection and its published privacy disclosures accurately describe the app.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ios, swift
- Domain
- authentication, mobile, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100