>>timbit+(OP)
If my phone is compromised, probably neither of them are compromised, or both are. I do not see how a separate app helps. I see where you are coming from, but I think using KeepassDX for password and TOTP should work. Keep in mind you can have multiple databases, you can store the TOTP only in one of the databases.