The secret never has to leave the device
x2y Authenticator implements time-based one-time passwords exactly as RFC 6238 defines them: a shared secret plus the current clock, hashed into a six-digit code. That computation needs no network, and adding one would only create an attack surface and a business decision about where your codes live.
So there is no sync service, no recovery mailbox, no vendor database. If an authenticator app offers cloud backup, the honest question is not whether it encrypts the backup but who holds the key and what legal process can reach it. Here the answer is nobody but you.
Sealed by the platform, not by a password
Vault secrets are encrypted at rest using the Android Keystore, and unlock is gated by your PIN or fingerprint through the same hardware-backed path. The app asks for no permissions beyond local storage for the encrypted vault, and none at all for the core operation of producing codes.
A passphrase-only vault is vulnerable while the device is unlocked; a Keystore-backed vault is not readable by another app on the same phone. That distinction is the whole reason this is a native Android app rather than a cross-platform wrapper.
Stealth Mode and the duress scenario
A duress PIN opens a decoy vault containing accounts you chose to expose. It is a real mitigation for a specific, unlucky situation — being forced to unlock your phone — and it is deliberately described as a mitigation, not a guarantee. An attacker who can compel you to give the real PIN still wins; Stealth Mode only removes the free look.
We would rather under-promise here than sell you a magic button. The behaviour, the decoy setup and its limits are documented in the product reference.
Panic Backup that you physically control
Backups are encrypted and exported as a Master QR or a .x2y file. You decide whether that ends up in a safe, a bank deposit box or an encrypted drive. Losing the phone is survivable; losing both the phone and the backup is not — that is the cost of refusing to hold your recovery in our servers, and we think it is the right trade.
WiFi Companion without a relay
Typing six digits on a phone while a desktop login times out is the classic friction point. WiFi Companion streams the current code to a browser on the same local network over an encrypted LAN connection — no relay, no vendor server, and it can be switched off entirely.
Similarly, optional NTP time sync requests a timestamp only, so codes stay accurate after a long flight; disable it and your clock drift is your own business.