Last updated: August 5, 2026
NIM Authenticator is the companion app for Nesnet Identity Manager (NIM), the sign-in service your organization runs. You use it to approve sign-ins on your phone and to generate the six-digit codes that some services still ask for. This page explains what information the app handles, where that information goes, and how you get rid of it. We have tried to keep it short enough that you will actually read it.
The short version
The app collects the minimum it needs to deliver sign-in approvals to your phone: a push token, a device identifier, and the name of the account you paired. It shows no ads, contains no analytics or tracking SDKs, and never sells or shares data with anyone. The secrets that generate your codes stay on your phone. If backup is turned on, your account list is encrypted and stored with your organization's NIM service so a new phone can restore it automatically.
What we store, and why
When you pair the app with your account, three things are registered with your organization's NIM service: a push token issued by Apple or Google (so an approval request can find this phone), a device identifier created during pairing (so the server knows which enrolled device is answering), and the username and organization you paired with (so the approval screen can tell you which account is signing in). That is the whole list. All of it is created when you add an account and deleted when you remove it.
What never leaves your phone
The secret keys behind your one-time codes are kept in the iOS Keychain and are never sent anywhere. Face ID and passcode checks are performed by the operating system on the device; no biometric data is available to the app, let alone transmitted. The only exception to "codes stay on the phone" is the encrypted backup described below — and whether that exists is up to you and your organization.
Backups
Whether a cloud backup is available is set by your organization; when it is, you choose whether to use it. If backup is on, the app encrypts your account list on your phone (AES-256-GCM) before anything is uploaded, and stores the encrypted copy on your organization's NIM service. The key that decrypts it is safeguarded for you by that same NIM service — this is what lets a new or reset phone restore your accounts automatically, without you having to remember anything. Because the service holds the key, your organization's NIM operator is technically able to decrypt the backup; this is the same model used by other cloud-backed authenticator apps, and it is the trade-off that makes seamless recovery possible. If you would rather not keep a cloud copy, leave backup off (your organization can also disable it entirely), and nothing is uploaded. Turning backup off deletes the encrypted copy from the server.
Push notifications
Approval requests are delivered through Apple's and Google's push services, because that
is the only way to reach a phone that isn't running the app. The notification itself is just
a knock on the door: it carries no secrets and no details about the sign-in. When you open
it, the app fetches the actual request directly from your organization's NIM service over
TLS. The app talks to that service and nothing else — for example
push.id.nesnet.com, or the NIM appliance your organization hosts itself.
Deleting your data
Remove an account in the app and the phone is deregistered from the server at the same moment — no request form, no waiting period. Turning off backup deletes the backup. Your organization's NIM administrator can also detach a device from the server side, which is what to ask for if the phone itself is lost.
Changes to this policy
If we change what the app collects — which we don't expect to do often — we will update this page and the date at the top before the change ships.
Contact
Questions about this policy or your data: Nesnet, info@nesnet.com.
Son güncelleme: 5 Ağustos 2026
NIM Authenticator, kurumunuzun kullandığı oturum açma servisi Nesnet Identity Manager'ın (NIM) telefon uygulamasıdır. Oturum açma isteklerini telefonunuzdan onaylamak ve bazı servislerin hâlâ istediği altı haneli kodları üretmek için kullanılır. Bu sayfa uygulamanın hangi bilgiyi tuttuğunu, o bilginin nereye gittiğini ve nasıl sildireceğinizi anlatır. Gerçekten okuyabileceğiniz kadar kısa tutmaya çalıştık.
Kısa özet
Uygulama, onay isteklerini telefonunuza ulaştırmak için gereken asgariyi toplar: bir push token, bir cihaz kimliği ve eşleştirdiğiniz hesabın adı. Reklam göstermez; içinde analitik ya da izleme SDK'sı yoktur; veriniz kimseyle paylaşılmaz, kimseye satılmaz. Kodlarınızı üreten gizli anahtarlar telefonunuzda kalır. Yedeklemeyi açarsanız yedek, yalnızca sizin bildiğiniz bir parolayla şifrelenir — istesek de okuyamayız.
Neyi neden tutuyoruz
Uygulamayı hesabınızla eşleştirdiğinizde kurumunuzun NIM servisine üç şey kaydedilir: Apple ya da Google'ın verdiği push token (onay isteği bu telefonu bulabilsin diye), eşleştirme sırasında üretilen bir cihaz kimliği (sunucu hangi kayıtlı cihazın yanıt verdiğini bilsin diye) ve eşleştiğiniz kullanıcı adı ile kurum (onay ekranı hangi hesabın oturum açtığını gösterebilsin diye). Listenin tamamı bu. Hepsi hesap eklerken oluşur, hesabı kaldırınca silinir.
Telefonunuzdan hiç çıkmayanlar
Tek kullanımlık kodlarınızın arkasındaki gizli anahtarlar iOS Keychain'de durur ve hiçbir yere gönderilmez. Face ID ve parola kontrolünü işletim sistemi cihazın üzerinde yapar; uygulama biyometrik veriye erişemez, dolayısıyla iletemez de. "Kodlar telefonda kalır" kuralının tek istisnası aşağıda anlatılan şifreli yedektir — onun var olup olmayacağına da siz karar verirsiniz.
Yedekleme
Yedekleme varsayılan olarak kapalıdır. Açarsanız uygulama, hesap listenizi sizin seçtiğiniz bir kurtarma parolasıyla telefonunuzda şifreler ve sonucu kurumunuzun NIM servisinde saklar. Şifreleme (Argon2id ile türetilen anahtar, AES-256-GCM) yükleme yapılmadan önce gerçekleşir; sunucudaki şey okunamaz bir blob'dur. Nesnet çözemez, yöneticiniz çözemez; parolayı unutursanız biz de çözemeyiz — zaten amaç bu. Yedeklemeyi kapatmak blob'u sunucudan siler.
Push bildirimleri
Onay istekleri Apple ve Google'ın push servisleri üzerinden iletilir; uygulaması açık
olmayan bir telefona ulaşmanın başka yolu yok. Bildirimin kendisi kapıya vurmaktan
ibarettir: gizli bilgi de, oturumun ayrıntısı da taşımaz. Bildirime dokunduğunuzda uygulama
asıl isteği TLS üzerinden doğrudan kurumunuzun NIM servisinden alır. Uygulama o servisten
başkasıyla konuşmaz — örneğin push.id.nesnet.com ya da kurumunuzun kendi
barındırdığı NIM appliance'ı.
Verilerinizi silme
Uygulamada hesabı kaldırdığınız anda telefonun sunucudaki kaydı da silinir — form yok, bekleme süresi yok. Yedeklemeyi kapatmak yedeği siler. Telefonun kendisi kaybolduysa istenecek şey şudur: kurumunuzun NIM yöneticisi cihazı sunucu tarafından da ayırabilir.
Bu politikadaki değişiklikler
Uygulamanın topladığı bir şey değişirse — ki sık olmasını beklemiyoruz — değişiklik yayına çıkmadan önce bu sayfayı ve üstteki tarihi güncelleriz.
İletişim
Bu politika ya da verinizle ilgili sorular için: Nesnet, info@nesnet.com.