Mobile apps

Symbifox Tokens

com.bluefoxconsultant.otp

Last updated: 14 September 2026

Controller: Blue Fox Inc., bonjour@symbifox.com

Symbifox Tokens produces the one-time codes of your own Odoo instance's vault. The app has no account, no server and no service of its own.

English version of PRIVACY.md, published on 18 September 2026 and carrying the date of the French policy it translates (14 September 2026). Both say the same thing; where they differ, the French one governs, because it is the one Blue Fox Inc. writes first.

In one sentence

The app collects nothing, transmits nothing to Blue Fox or to any third party, and talks only to the Odoo instance you point it at yourself.

What the app reaches

  • Your Odoo instance, the one whose address you enter on first launch. It reads the vault and the tokens there, both encrypted, along with your organisation's name, colours and logo. It writes back what you do from the device: a token added (encrypted on the device before it is sent), the date a copied code was used, the counter of a counter-based token, a passkey enrolled.
  • The camera, only while you are scanning a QR code to add a token, and only after you have allowed it. The image is neither kept nor transmitted: it is decoded on the fly and discarded.
  • The fingerprint reader or the device lock, to open the vault.

🔴 What it does not reach

No contacts, no SMS, no call log, no location, no shared storage, no microphone. The declared permissions can be checked: internet, biometrics, camera.

What the app keeps, and where

Everything stays on your device, in its private storage:

What is keptHow
Your tokensencrypted, exactly as the instance returned them. Seeds are never written in the clear
A sealed copy of the vault keysealed by the Android Keystore, in hardware, and reopened only after authentication
The instance address and the device's accessin the app's private storage, with no further encryption: that access opens nothing but ciphertext
Your organisation's logoas the instance serves it, so it can be shown before any network exchange

🔴 A sealed key is bound to this device. Lose the phone, or add a fingerprint to it, and the key is lost with it: nobody, at Blue Fox or anywhere else, can give it back. Your passphrase remains the only fallback: it is what derives the vault key, and the server does not know it either.

The vault closes as soon as the app goes to the background. Android's automatic backup is turned off: nothing goes to Google, and there is no device-to-device transfer. Exchanges with the instance happen over https only.

What the app transmits, and to whom

Only to the Odoo instance you designated, and only to read the vault, the tokens and your organisation's branding, and to record there what you do from the device. The app contacts no other server: no analytics, no telemetry, no crash reporting, no advertising, no remotely loaded code. Blue Fox Inc. receives no data about your use of it.

No password passes through the app: sign-in happens on your instance's own web page, which returns a one-time bearer token.

⚠️ Unlocking with a passkey relies on Android's credential manager, which goes through Google Play services on Android 13 and below. On a device without those services, the feature is hidden and everything else, offline codes included, works normally.

Retention and deletion

  • Uninstalling the app erases everything it was keeping, tokens included.
  • Signing out removes the bearer token, the sealed key and the tokens from the device.
  • From your instance, the "My devices" page (/my/appareils) lists the paired devices and lets you remove one, or all of them.

⚠️ Removing a device does not wipe it: it keeps what it has, that access simply opens nothing new.

Your rights

Since no personal data is collected by Blue Fox Inc., there is nothing on our side to consult, correct or delete. Your data stays under your control, on your device and on your Odoo instance. For any question: bonjour@symbifox.com.

Changes

Any change to this policy will be published at this address, with its date.

All three policies