Effective date: September 2, 2026
This Privacy Policy explains how the Authenticator — TOTP/HOTP Vault Chrome extension ("the extension," "we," "our") handles information when you use it.
The extension is designed to work entirely on your device. It generates TOTP and HOTP two-factor authentication codes and stores your account secrets in an encrypted local vault protected by a master password that you set. We do not operate a server that receives, stores, or processes your vault data, and we do not require you to create an account to use the extension.
The extension handles the following categories of information, all of which stay on your device:
Authentication information. When you add a two-factor account — by scanning a QR code, pasting an otpauth:// URI, entering details manually, or importing a file — the extension stores the issuer name, account label, and secret key needed to generate TOTP/HOTP codes.
Master password. Used locally to encrypt and decrypt your vault. We do not transmit your master password anywhere, and we do not have a way to recover it if you forget it.
Vault settings. Preferences such as auto-lock timing are stored locally alongside your vault.
We do not collect personally identifiable information (name, address, email address), health information, financial or payment information, personal communications, location data, browsing history, or general web activity.
Information stored in your vault is used only to:
Generate and display TOTP/HOTP codes for the accounts you've added
Keep your vault locked behind your master password until you unlock it
Automatically re-lock the vault after a period of inactivity
We do not use your vault data for advertising, analytics profiling, or any purpose unrelated to generating your two-factor codes.
The extension requests the following browser permissions, each limited to a specific function:
Permission Purpose
Storage Saves your encrypted vault locally so your accounts persist between sessions
activeTab Reads the currently open tab only when you click "Scan QR from Current Tab"
Scripting Runs the QR-detection logic on the current tab, only when you initiate a scan
Idle Detects inactivity so the vault can automatically lock itself
Alarms Schedules the vault's auto-lock timer
Clipboard write Lets you copy a generated code with one click, so you can paste it where it's needed
None of these permissions are used to monitor your browsing activity in the background, and none are active unless you're directly interacting with the extension.
Your vault is encrypted and stored locally in your browser profile. Your secret keys are parsed and validated on your device at the moment you add an account — they are never sent to us or to any third-party server. Because we do not operate a backend for this extension, we do not have access to your vault contents, your master password, or your stored secrets.
If you export your vault to a file (encrypted or plain), that file is created and saved by your browser directly to your device. We do not receive a copy of it.
We do not sell, rent, or transfer your data to third parties. We do not use or transfer your data for purposes unrelated to the extension's single purpose of generating two-factor authentication codes, and we do not use your data to determine creditworthiness or for lending purposes.
This extension does not load or execute remote code. All logic runs from code packaged directly with the extension.
The extension is not directed at children, and we do not knowingly collect information from children.
We may update this Privacy Policy from time to time. Changes will be reflected by an updated "Effective date" at the top of this page.
If you have questions about this Privacy Policy, contact us at: codelifeai@gmail.com
Note: this draft assumes no remote code is loaded and no host permission beyond activeTab/scripting is required, per your confirmation. If the manifest turns out to use a broader host permission or any remote code, sections 4 and 7 need to be revised to match before publishing.