SentryKey is a two-factor authentication (TOTP) app for Garmin watches with Android and iOS companion apps. This policy explains what the apps do and don't do with your data.
SentryKey does not collect, transmit, or sell any personal data. Everything stays strictly on your local devices and your personal VPS backup host.
.skbackup format.We do not operate any centralized backend server. Your secrets are never shared with us or any third party. Any data transmission is either a direct Bluetooth sync to your Garmin watch or an upload to your private VPS.
otpauth:// format. You are fully responsible for where you send or store these files.To stop automated abuse, the SentryKey website (the sign-in and account-recovery pages at sentrykey.app) uses Google reCAPTCHA v3. When those pages load, Google's reCAPTCHA script runs and may collect device and usage signals to tell humans from bots; this is subject to Google's Privacy Policy and Terms of Service. reCAPTCHA never receives your master password or 2FA secrets — those are processed entirely in your browser before anything is sent. The Garmin watch app and the Android/iOS apps do not use reCAPTCHA. If you self-host SentryKey, reCAPTCHA is off unless you choose to enable it on your own server.
Updates to this policy will be posted on this page and in the project's repository.
Questions? Open an issue at github.com/chrisdfennell/SentryKey/issues.