Privacy Policy

Last updated: August 2026

This Privacy Policy explains how TOTP Authenticator ("we", "us", or "our") collects, uses, stores and protects your information when you use our website and services. We take your privacy seriously and have designed this service so that your most sensitive data is protected at every step.

1. Information we collect

Account data

When you create an account, we collect your email address and your username. We never ask for your real name, phone number or any other personal identifier.

Authentication data

Your password is hashed with bcrypt before being stored. The plain-text password is only present in memory during the signup and login requests and is never written to logs, analytics or any third-party service.

TOTP account data

The authenticator accounts you create (service name, account name, logo and settings such as algorithm, digits and period) are stored in your account. The sensitive TOTP secret keys are encrypted with AES-256-GCM before storage and can only be decrypted server-side with an encryption key that never leaves the server environment.

2. Cookies and sessions

We use a single session cookie to keep you logged in. This cookie is HTTP-only (inaccessible to client-side JavaScript), Secure in production (transmitted only over HTTPS) and uses SameSite protection against cross-site request forgery. It expires automatically after 7 days.

We also use a local browser storage entry to remember your theme preference (light, dark or system). This never leaves your device.

3. How we use your data

  • To create and manage your account and session.
  • To store and display your authenticator accounts.
  • To generate time-based one-time passwords (TOTP codes) on your request.
  • To respond to support and contact messages.
  • To keep the service secure against abuse (rate limiting, abuse detection).

4. Analytics and third parties

We do not use analytics trackers, advertising networks or third-party scripts that scan your page content. Your passwords and TOTP secrets are never transmitted to any analytics, error-tracking or marketing service. Font Awesome icons are loaded from a public CDN; that request does not include any of your account data.

5. Data retention

Your account data is retained for as long as your account exists. Session cookies expire automatically. If you delete an authenticator account, its entry — including the encrypted secret — is permanently removed from your profile.

6. Data deletion

You can delete individual authenticator accounts from the dashboard at any time. To delete your entire account, contact us at pabelprfb@gmail.com using the email address registered on your account, and we will permanently delete your account and all associated data within 30 days.

7. Data security

We apply industry-standard protections: bcrypt password hashing, AES-256-GCM encryption of secrets, HTTP-only secure cookies, server-side authorization on every request, rate limiting on authentication endpoints and security headers (CSP, HSTS, X-Content-Type-Options and more). No system is completely immune to failure, but we are committed to continuous hardening of these controls.

8. Children's privacy

This service is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

9. Changes to this policy

We may update this policy from time to time. Material changes will be announced on this page with an updated revision date. Continued use of the service after changes constitutes acceptance of the updated policy.

10. Contact

For privacy questions or requests, contact Pabel Islam at pabelprfb@gmail.com.