TOORCE MFA (“the App”) is a companion authenticator for organizations that use TOORCE gateways. It provisions a device and displays a one-time MFA code from your organization’s server.
Data we collect
- Device ID: a random UUID created on the device and stored in the iOS Keychain. It is sent to your organization’s gateway so the device can be recognized.
- Account fields: server address, port, username, and password that you enter. Password is stored in the iOS Keychain on the device.
- MFA code: fetched from your organization’s
/otpendpoint and shown on screen. The last code may be stored locally on the device. - Camera: used only when you choose Scan QR, to read a provision invite. Images are not uploaded to us.
How data is used
All network requests go to the gateway your organization configures (HTTPS /provision and /otp). We do not operate a TOORCE cloud account for this App. We do not sell personal data. We do not use advertising SDKs or analytics SDKs in this version.
Who receives data
Your organization (the gateway operator) receives Device ID, username, a hashed password, and a hashed Device ID according to the TOORCE API. Apple may process data as part of iOS, App Store, and iCloud backups if you enable device backup.
Retention
Data remains on the device until you tap Reprovision, delete the App, or erase the device. Gateway logs are controlled by your organization.
Children
The App is intended for workforce use, not for children under 13.
Contact
For privacy questions, contact your TOORCE administrator or support@toorce.com.