This Privacy Policy explains how Get2FA.dev processes information when you use the public website or contact us. It should be read together with our Cookie Policy.
1. TOTP secrets and authentication codes
The public generator calculates TOTP codes in your browser using client-side JavaScript. The application is designed so that secrets entered into the generator and the resulting codes are not sent to our application server or stored in our database.
Do not treat a browser tool as a permanent credential vault. Your device, browser extensions, network environment, screenshots, clipboard, and third-party services are outside our control.
2. Information you provide
If you use the contact form, we receive the name, email address, subject, and message you submit. We use this information to respond, investigate issues, handle privacy requests, and protect the website from abuse.
Do not submit passwords, TOTP secrets, authentication codes, recovery codes, or other credentials.
3. Technical information
Our hosting and web server may process standard technical information needed to deliver and secure the website, such as request time, requested URL, browser information, error details, and network address. For contact-form abuse prevention, the application stores a one-way keyed hash derived from the submitting IP address rather than the plain address in the contact-message record.
4. Local storage and essential sessions
The public interface uses browser local storage to remember your light or dark theme preference. Contact and administrator areas may use essential session cookies for form security and authentication. See the Cookie Policy for details.
5. DeepL and translations
Administrators may use DeepL to translate public website copy, pages, and articles. The translation workflow is not intended to include TOTP secrets, generated codes, contact messages, or other user credentials.
6. How long information is kept
Contact messages and associated abuse-prevention data are retained only for as long as reasonably necessary to respond, maintain records, resolve disputes, and protect the service. Operational logs may be retained for a limited period according to hosting and security needs.
7. Sharing and disclosure
We do not sell personal information. Information may be processed by infrastructure providers that help operate the website, disclosed when required by law, or used when reasonably necessary to protect users, the service, or the rights of others.
8. Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, or objection regarding personal information we hold about you. You may submit a request through the contact page. Some information may need to be retained where required by law or for legitimate security and recordkeeping purposes.
9. Children
Get2FA.dev is a general-purpose security utility and is not directed to children. Please do not submit personal information if you are not legally permitted to do so in your jurisdiction.
10. Security
We use reasonable technical and organizational measures appropriate to the service, but no website or transmission method can be guaranteed completely secure.
11. Changes to this policy
We may update this policy when the website, our practices, or applicable requirements change. The date shown at the top of this page indicates the latest update.
12. Contact
For questions or privacy requests, use our contact form.