Wallace Privacy Policy
Last updated: 1 October 2026. Applies to Wallace 1.0 and later.
1. Who is responsible
Benjamin Burk
Berliner Allee 47
64295 Darmstadt
Germany
Email: wallace@benpho.com
Benjamin Burk (“the publisher”) publishes Wallace and runs this website. He is the controller under the EU General Data Protection Regulation (GDPR) for the processing that he decides on, as described below.
2. In short
- Wallace has no sign-up, no user accounts, no analytics, no advertising, no tracking and no developer server.
- The publisher receives no data from Wallace: not your accounts, secret keys or codes, not how you use the app, and not your IP address.
- Your authenticator accounts are kept in Apple’s Keychain on your devices. If you use iCloud Keychain, Apple synchronizes them between your own devices.
- The only connection Wallace makes on its own is the optional download of a public breach list from Have I Been Pwned. It is off until you turn it on.
3. Data that stays on your devices
Wallace stores on your device:
- your authenticator accounts: service name, account name, secret key, code settings and, if you add them, service domains;
- accounts in Recently Deleted, until you delete them permanently;
- the progress of an import, the history of breach reports, and your settings (app lock, Auto-lock time, clipboard clearing, monitoring and notification choices, the date of your last backup);
- the public breach list, if you use breach monitoring, and a list of the last 20 network requests Wallace made or blocked.
None of this is sent to the publisher.
iCloud Keychain. If iCloud Keychain is turned on, your authenticator accounts, including those in Recently Deleted, are synchronized by Apple between the devices signed in to your Apple Account, with end-to-end encryption. Apple provides this service to you under its own terms and privacy policy. The publisher has no access to it. All other data listed above stays on the device where it was created.
Encrypted backup. When you export a backup, Wallace encrypts your accounts on your device with a passphrase and writes the file only where you choose to save it. The publisher never receives the file or the passphrase and cannot recover a lost passphrase.
Deleting your data. Delete an account in Wallace and then delete it permanently in Recently Deleted. Removing the app does not reliably remove accounts from the Keychain, so delete them in Wallace first. Turning breach monitoring off deletes the downloaded breach list.
4. Breach monitoring with Have I Been Pwned (optional)
Breach monitoring is off by default. If you turn it on and confirm, Wallace downloads the public list of reported data breaches from Have I Been Pwned (haveibeenpwned.com), a service of Superlative Enterprises Pty Ltd, Queensland, Australia. Wallace does this about once a day while it is open and unlocked, or when you choose Check now, and never more than 10 times in 24 hours.
- What is sent: an ordinary request for the public list. It contains none of your accounts, email addresses, service names, secret keys or codes. Wallace compares the list with your services only on your device.
- What Have I Been Pwned and its network can see: your device’s IP address, the time of the request, the app name “Wallace” in the request, and standard technical details that the operating system adds, such as the accepted compression and language. Have I Been Pwned delivers its content through Cloudflare.
- Purpose and legal basis: to provide the breach monitoring you asked for. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give when you turn monitoring on. You can withdraw it at any time by turning monitoring off; this does not affect requests already made.
- Outside the EU: Have I Been Pwned is based in Australia and Cloudflare operates worldwide. Your IP address may therefore be processed in countries for which the EU has not decided that data protection is adequate, and where your rights may be harder to enforce. By turning monitoring on, you consent to this (Art. 49(1)(a) GDPR).
- Have I Been Pwned processes this data under its own privacy policy: https://haveibeenpwned.com/Privacy
The publisher receives none of this data.
5. Camera, pictures, files, clipboard, notifications and device authentication
- Camera (iPhone and iPad): used only while you scan a QR code. Images are not saved or sent anywhere.
- Pictures you give to “Add from QR image”: read on your device and then discarded. Wallace does not ask for access to your photo library.
- Files you import: only read. Wallace does not change, copy or upload them.
- Clipboard: a code or backup passphrase you copy is kept on this device only and is not shared with your other devices. Wallace removes a copied code after 30 seconds if that setting is on, and a copied passphrase always after 60 seconds.
- Notifications (optional): created on your device. They say only “Wallace has new security information.”
- Face ID, Touch ID and passwords are handled by Apple’s system. Wallace only learns whether authentication succeeded.
6. App Store
You get Wallace from Apple’s App Store, and Apple processes data about your download under its own privacy policy. The publisher does not collect analytics, and Wallace contains no analytics or crash-reporting code. Independently of Wallace, Apple shows every app developer aggregated statistics, such as download numbers, and crash reports from users who chose to share them with developers. These do not identify you. You can turn this off on your Mac under System Settings → Privacy & Security → Analytics & Improvements → Share with app developers.
7. When you email the publisher
If you write to wallace@benpho.com, the publisher processes your email address, your message and anything you include, only to answer you. The legal basis is the publisher’s legitimate interest in answering enquiries (Art. 6(1)(f) GDPR), or Art. 6(1)(b) GDPR if your enquiry concerns a contract. Your email is deleted once your request has been dealt with, unless statutory retention periods require it to be kept longer. The publisher’s email provider processes messages on his behalf.
Never send secret keys, QR codes, codes, backup files or backup passphrases by email. The publisher will never ask for them.
8. This website
This website (wallace.benpho.com) is hosted on Cloudflare Pages by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you open a page, your browser sends your IP address, the time, the page requested and technical details such as the browser type and language. Cloudflare needs these to deliver the page and to protect the site against attacks, and may keep them in its logs for a short time. The publisher does not receive or evaluate these logs.
The website uses no cookies, no analytics and no content from other sites, such as fonts, scripts or images. Cloudflare may set a strictly necessary security cookie if it detects unusual traffic.
The legal basis is the publisher’s legitimate interest in delivering the website securely and reliably (Art. 6(1)(f) GDPR). Cloudflare processes the data on the publisher’s behalf under its data processing agreement. Cloudflare is certified under the EU-US Data Privacy Framework, for which the EU has adopted an adequacy decision (Art. 45 GDPR). Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/
9. Your rights
Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or deleted (Art. 17), to restrict its processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3)). Because the publisher receives no data from the app, such requests will mostly concern emails you have sent. Write to wallace@benpho.com.
Right to object (Art. 21 GDPR): Where processing is based on legitimate interests (Art. 6(1)(f) GDPR), namely delivering this website (section 8) and answering emails (section 7), you may object to it at any time on grounds relating to your particular situation. The publisher will then stop unless he can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Write to wallace@benpho.com.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU country where you live or work. The authority responsible for the publisher is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (Hesse Commissioner for Data Protection and Freedom of Information), Wilhelmstraße 7, 65185 Wiesbaden, Germany, https://datenschutz.hessen.de.
You are not required to provide any personal data to use Wallace. Wallace makes no automated decisions about you.
10. Changes
This policy is updated when Wallace or the law changes. The date at the top shows the latest version.