Privacy Policy

At 2FA Auth we take your privacy seriously. Our tool is designed to process authentication data directly in your browser.

1. Your secret stays in your browser

When you enter a TOTP secret key or scan a QR code, the data is processed locally in your browser. The page’s code does not send your secret keys or generated 2FA codes to our servers, and we do not store them.

2. No account or secret-key database

2FA Auth does not require an account, and we do not maintain a database of your TOTP secret keys or generated codes. When you leave or refresh the page, your active tool data is cleared.

3. What is stored in your browser

The site saves your language choice in your browser’s local storage so the page opens in the same language next time. Nothing else is stored.

4. Server logs

Like most websites, our hosting infrastructure may record standard technical information about requests, such as IP address, browser type, requested page and time. This information does not include your secret key or codes, because they are never part of a page request.

5. Third-party services

Pages load fonts from Google Fonts. When you press “Scan QR” in a browser without built-in QR detection, the open-source jsQR library is loaded from the jsDelivr CDN. These providers receive standard request data such as your IP address.

6. Advertising & cookies

We may use Google AdSense to display advertisements. Google and its advertising partners may use cookies or similar technologies to provide, measure and improve advertising. Depending on your location and applicable requirements, you may be asked for consent before certain advertising technologies are used.

7. Your responsibility

Only use your own authentication keys and avoid entering sensitive information on shared or untrusted devices.

8. Contact

If you have questions about this Privacy Policy, write to support@2fauth.online or use our contact page.

Last updated: October 8, 2026