🔐 TOTP Vault

Privacy Policy

Effective date: September 8, 2026

This Privacy Policy explains how the TOTP Vault browser extension ("TOTP Vault", "we", "our", or "the extension") handles information when you use the extension.

Your TOTP secrets and generated verification codes stay local. TOTP Vault does not upload your authenticator secrets or generated one-time passwords to our Firebase backend.

1. What TOTP Vault does

TOTP Vault is a browser extension for storing TOTP account configuration, importing supported otpauth:// data and QR codes, generating time-based one-time passwords, and copying those codes to the clipboard.

2. Information stored locally in your browser

The extension uses browser extension storage to keep data needed for its core functionality. This may include:

TOTP secrets and generated OTP codes are intended to remain on your device and are not transmitted to our backend for storage or processing.

3. Google Sign-In and Firebase authentication

TOTP Vault requires Google Sign-In to establish and periodically verify an extension session. Authentication is handled using Google Sign-In and Firebase services.

When you sign in, we may process information associated with your Google account that is provided through Firebase Authentication, such as your Firebase user identifier and, where provided, your email address.

TOTP Vault uses an application session token for extension access. The backend stores a cryptographic hash of that session token rather than the plaintext token. Sessions are designed to expire after approximately five days, after which sign-in is required again.

4. QR-code processing and active-tab access

If you explicitly choose to scan a QR code from the currently active tab, TOTP Vault temporarily accesses the visible tab for that user-initiated action.

QR image data used for TOTP detection is processed locally by the extension and is not uploaded to our backend. TOTP Vault does not continuously monitor browsing activity and does not maintain a browsing-history database.

5. Clipboard access

TOTP Vault may write a generated TOTP code to your clipboard when you explicitly press a copy control. The extension does not require clipboard read access for this feature.

6. Network requests

The extension may connect to our Firebase-hosted backend for functions necessary to operate the service, including:

These requests do not include your TOTP shared secrets or generated verification codes.

7. Advertising, sponsors, and affiliate links

The free version of TOTP Vault may display direct sponsorships, affiliate promotions, or third-party advertising inside the extension interface.

Sponsor and affiliate campaign information may be retrieved from our backend. If you follow an affiliate link, we may receive a commission from the relevant provider.

On supported Chromium-based versions, TOTP Vault may use PlayaYield as a third-party advertising provider. Advertising providers may process limited technical information needed to serve, secure, and measure advertisements, such as IP address, browser or device information, ad impressions, and ad interactions, subject to the provider's own privacy terms and applicable law.

Advertising providers do not need access to your TOTP secrets or generated verification codes in order to serve ads through TOTP Vault.

8. Information we do not intentionally collect

TOTP Vault does not intentionally collect or store the following as part of its core functionality:

9. Data sharing and sale

We do not sell your personal information.

Information may be processed by service providers only where necessary to provide the extension's disclosed functionality, such as authentication, hosting, security, and advertising. We do not use or transfer user data for determining creditworthiness or for lending purposes.

10. Data retention

Local extension data remains in your browser until you remove it, reset the extension, or uninstall the extension, subject to the behavior of your browser.

Backend authentication and session records are retained only for as long as reasonably necessary to operate, secure, and maintain the authentication service. Expired or invalid session records may be deleted or rendered unusable after expiration.

11. Security

We use reasonable technical measures designed to protect backend authentication and configuration services. However, no networked system, browser extension, or storage mechanism can guarantee absolute security.

You are responsible for maintaining the security of the device and browser profile where your TOTP secrets are stored.

12. Children's privacy

TOTP Vault is not designed to knowingly collect personal information from children in circumstances where parental consent is required by applicable law.

13. Changes to this Privacy Policy

We may update this Privacy Policy when the extension, its service providers, or applicable requirements change. The effective date at the top of this page will be updated when material changes are published.

14. Contact

For privacy questions or requests related to TOTP Vault, contact: 9u364lnj8@mozmail.com