Open Desktop Authenticator

What this site stores

Short version: the application holds your secrets on your own machine and sends them nowhere. This website holds nothing about you unless you file a report, and what a report holds is listed below with how long it lives.

The application is the part that matters, and it is the part that stores nothing

Open Desktop Authenticator keeps your Steam Guard secrets in an encrypted vault on your computer. There is no account, no sync, no server of ours for them to reach, and no telemetry — the security page explains the design. Nothing on this page describes your secrets, because we never have them.

If you file a report

The support form is the only place this site collects anything. It stores:

What you wrote
The kind of report, the one-line summary and the detail. Submissions that look like they contain a Steam secret are refused and never written — that check reads text, so it cannot see inside an image.
A reply address, only if you give one
Optional, and never shown on the report page that anyone holding the link can read. Leave it blank and the report still works; you just cannot be asked a follow-up question.
Screenshots or clips, only if you attach them
Stored under a name we generate, readable only through the report they belong to, and served as the file type their own bytes say they are. Check a screenshot before you choose it — a code or an account name in the corner is ours to hold once you send it.
Ordinary server logs
The web server records requests — address, time, page, user agent — as any web server does. Kept 14 days, then rotated away.

How long each thing lives

WhatKept for
An upload you never attached to a report2 hours
An open report, and anything attached to itUntil it is closed
A resolved or declined report90 days after it was closed, then deleted with its attachments
Web server request logs14 days
Backups of the report databaseSame 90-day cycle; a deleted report leaves the backups as they age out

Deletion runs on a clock inside the service, hourly, whether or not anybody visits. It used to run only when somebody uploaded a file, which meant a quiet week was a week when nothing expired.

Having something removed sooner

Reply on your own report and ask — the reference is the only thing needed, and the support page explains how to get back to it. We will delete the report, its replies and its attachments, and say when it is done. There is no account to close because there was never one to create.

If you attached something by mistake and have not submitted yet, Remove on the file deletes our copy immediately rather than just hiding the thumbnail.

Who else is involved

Cloudflare
Sits in front of this site and terminates TLS, so it sees requests to it. We run no analytics product — not Cloudflare's, not anybody's — and there is no tracking script on any page here.
GitHub
Hosts the source and the eventual releases. If the application's update check is on, it asks GitHub's public releases page whether a newer version exists; GitHub sees an address and that the application is running, the same as any visitor to that page. Nothing about you or your accounts is sent.
Nobody else
No advertising network, no analytics vendor, no third-party fonts or scripts, and nothing sold or shared. Donations are cryptocurrency only partly for this reason — taking cards would mean a payment processor holding donor names against a project whose whole argument is that it holds nothing.

Reaching us about this

Use the report form. For a security issue, the routes are on the security page and in security.txt.

Published by MASTERPANEL LLC. Last reviewed 2026-08-12.

Last reviewed .