Privacy Policy
Last updated: August 2026
This Privacy Policy explains how TOTP Authenticator ("we", "us", or "our") collects, uses, stores and protects your information when you use our website and services. We take your privacy seriously and have designed this service so that your most sensitive data is protected at every step.
1. Information we collect
Account data
When you create an account, we collect your email address and your username. We never ask for your real name, phone number or any other personal identifier.
Authentication data
Your password is hashed with bcrypt before being stored. The plain-text password is only present in memory during the signup and login requests and is never written to logs, analytics or any third-party service.
TOTP account data
The authenticator accounts you create (service name, account name, logo and settings such as algorithm, digits and period) are stored in your account. The sensitive TOTP secret keys are encrypted with AES-256-GCM before storage and can only be decrypted server-side with an encryption key that never leaves the server environment.
2. Cookies and sessions
We use a single session cookie to keep you logged in. This cookie is HTTP-only (inaccessible to client-side JavaScript), Secure in production (transmitted only over HTTPS) and uses SameSite protection against cross-site request forgery. It expires automatically after 7 days.
We also use a local browser storage entry to remember your theme preference (light, dark or system). This never leaves your device.
3. How we use your data
- To create and manage your account and session.
- To store and display your authenticator accounts.
- To generate time-based one-time passwords (TOTP codes) on your request.
- To respond to support and contact messages.
- To keep the service secure against abuse (rate limiting, abuse detection).
4. Analytics and third parties
We do not use analytics trackers, advertising networks or third-party scripts that scan your page content. Your passwords and TOTP secrets are never transmitted to any analytics, error-tracking or marketing service. Font Awesome icons are loaded from a public CDN; that request does not include any of your account data.
5. Data retention
Your account data is retained for as long as your account exists. Session cookies expire automatically. If you delete an authenticator account, its entry — including the encrypted secret — is permanently removed from your profile.
6. Data deletion
You can delete individual authenticator accounts from the dashboard at any time. To delete your entire account, contact us at pabelprfb@gmail.com using the email address registered on your account, and we will permanently delete your account and all associated data within 30 days.
7. Data security
We apply industry-standard protections: bcrypt password hashing, AES-256-GCM encryption of secrets, HTTP-only secure cookies, server-side authorization on every request, rate limiting on authentication endpoints and security headers (CSP, HSTS, X-Content-Type-Options and more). No system is completely immune to failure, but we are committed to continuous hardening of these controls.
8. Children's privacy
This service is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. Material changes will be announced on this page with an updated revision date. Continued use of the service after changes constitutes acceptance of the updated policy.
10. Contact
For privacy questions or requests, contact Pabel Islam at pabelprfb@gmail.com.