com.bluefoxconsultant.otp
Last updated: 14 September 2026
Controller: Blue Fox Inc., bonjour@symbifox.com
Symbifox Tokens produces the one-time codes of your own Odoo instance's vault. The app has no account, no server and no service of its own.
English version of PRIVACY.md, published on 18 September 2026 and carrying the date of the French policy it translates (14 September 2026). Both say the same thing; where they differ, the French one governs, because it is the one Blue Fox Inc. writes first.
The app collects nothing, transmits nothing to Blue Fox or to any third party, and talks only to the Odoo instance you point it at yourself.
No contacts, no SMS, no call log, no location, no shared storage, no microphone. The declared permissions can be checked: internet, biometrics, camera.
Everything stays on your device, in its private storage:
| What is kept | How |
|---|---|
| Your tokens | encrypted, exactly as the instance returned them. Seeds are never written in the clear |
| A sealed copy of the vault key | sealed by the Android Keystore, in hardware, and reopened only after authentication |
| The instance address and the device's access | in the app's private storage, with no further encryption: that access opens nothing but ciphertext |
| Your organisation's logo | as the instance serves it, so it can be shown before any network exchange |
🔴 A sealed key is bound to this device. Lose the phone, or add a fingerprint to it, and the key is lost with it: nobody, at Blue Fox or anywhere else, can give it back. Your passphrase remains the only fallback: it is what derives the vault key, and the server does not know it either.
The vault closes as soon as the app goes to the background. Android's automatic backup is turned off: nothing goes to Google, and there is no device-to-device transfer. Exchanges with the instance happen over https only.
Only to the Odoo instance you designated, and only to read the vault, the tokens and your organisation's branding, and to record there what you do from the device. The app contacts no other server: no analytics, no telemetry, no crash reporting, no advertising, no remotely loaded code. Blue Fox Inc. receives no data about your use of it.
No password passes through the app: sign-in happens on your instance's own web page, which returns a one-time bearer token.
⚠️ Unlocking with a passkey relies on Android's credential manager, which goes through Google Play services on Android 13 and below. On a device without those services, the feature is hidden and everything else, offline codes included, works normally.
/my/appareils) lists the paired devices and lets you remove one, or all of them.⚠️ Removing a device does not wipe it: it keeps what it has, that access simply opens nothing new.
Since no personal data is collected by Blue Fox Inc., there is nothing on our side to consult, correct or delete. Your data stays under your control, on your device and on your Odoo instance. For any question: bonjour@symbifox.com.
Any change to this policy will be published at this address, with its date.