Intent-Code Divergence
Medium
- Confidence
- 90% confidence
- Finding
- The terms claim that login tokens and binding information are stored only on the local device and are not uploaded to any third party, yet the same document describes server-side identity verification, link delivery, interface use, and security monitoring. This creates a likely misleading data-handling statement that can cause users to make unsafe trust decisions and may conceal broader processing of authentication or binding data.
