FAQ
Question not here? Drop us a line via the contact page.
No. DualKey has no accounts — open it and start. We do not ask for an email address, a name, a phone number or a date of birth. The Pro purchase is verified by your Apple ID or Google account, so we cannot even see whether you bought it.
Not by default. The free tier is entirely offline, with secrets and vault entries in the system's encrypted store and notes encrypted on the device. Pro adds a backup, but the contents are encrypted and written only to your own iCloud or Google storage, in a folder only you can see, and only when you press it. Our servers are never involved.
Yes. DualKey has a built-in migration tool that reads an Authy export file and brings everything across at once. If another app can produce a transfer QR code, you can simply scan it. Failing that, type it in by hand: service name, account and secret are all it takes.
Free: the vault and private notes with no limit, code accounts with no limit (from the fifth onwards, one short ad before adding another), the standard algorithms, QR scanning, the migration tool and encrypted file export. Pro is NT$30 once: ads gone for good, cloud backup, biometric unlock for the app and account QR export.
The backup is encrypted with your master password before it leaves the device, and it is written into an isolated folder under your own account that only you and this app can see. The platform adds its own account isolation and encryption at rest on top. We have no backend, so we see nothing at all — and without your master password, that file does not open for anyone.
On Pro: run a backup on the old phone, sign in to the same Apple ID or Google account on the new one, and restore. On the free tier, export to an encrypted file and enter the same master password when importing. The Pro unlock itself travels through Restore Purchases on the App Store or Play Store.
No. Purchases on iPhone are held against your Apple ID and purchases on Android against your Google account, and the two stores do not share them. The encrypted file export and import does work across platforms, though.
Code secrets and vault entries are held in the iOS Keychain or Android Keystore — the hardware-backed encrypted store the operating system provides, separate from the app's own file sandbox. Uninstalling clears them. The flip side is that once they are gone, nothing brings them back without a backup, so make one before you change phones.
The first four accounts are free with no ads, which covers most people using a handful of main services. From the fifth onwards, each addition asks you to watch one short ad first; watch it and you carry on, and the number of accounts itself is never capped. If you would rather not, NT$30 once removes ads for good. The vault and private notes are not subject to this at all.
They work perfectly. Both are purely local: the time-based kind combines the secret with the current time to produce six digits, rolling over every 30 seconds; the counter-based kind combines the secret with a counter that only moves when you press the button. Nothing goes over the network. The one caveat is that time-based codes depend on the device clock, so leave system time on automatic and it is fine.
They really are free with no limit right now — there is not a single paid gate in the code for either of them. We describe how things stand today. If the pricing ever changes we will say so on this page first, and nothing you have already stored would be touched.
On export you set a master password, the app derives a key from it and encrypts everything into a single file you can send to yourself, put on a USB stick or keep on your own storage. Importing on the new phone needs the same password. A forgotten master password cannot be recovered — we hold no copy and there is no back door. That is precisely why it is safe, so keep the password somewhere safe of its own.
It turns a single code account back into a QR code so the new phone can scan it across without restoring everything. Because that QR contains the account's secret, anyone who scans it can generate your codes — so the app asks for biometric verification before it is shown, and the screen says plainly not to screenshot or share it.
With it on, every launch asks for face or fingerprint first, and without it you cannot even see the code list. If the phone is stolen, this is the layer that stops someone with an already-unlocked handset from simply browsing your codes. The secrets themselves sit in the system's encrypted store, so plugging the phone into a computer does not yield them in the clear either.
That short ad exists so that a fifth or later account can be added after watching it. If a failed load simply let the addition through, the whole thing would be meaningless, so it blocks and asks you to try again. In practice failures are rare and usually mean a shaky connection at that moment. Unlocking Pro removes this step entirely.