← Secure 2FA Authenticator · FAQ
Secure 2FA Authenticator · Last updated: 4 June 2026
Secure 2FA Authenticator ("the Extension") is a Chrome browser extension that generates time-based one-time password (TOTP) codes for two-factor authentication. Your privacy is important to us. This policy explains what data the Extension uses and how it is handled.
getsecuretotp.us) may show Google AdSense display ads and uses Google Ads conversion tags — see Website advertising.
When you add an account, the Extension saves the account name (username or email) and
the Base32 TOTP secret in chrome.storage.local on your computer. This data
never leaves your device except when you explicitly export an encrypted backup (Pro feature).
Pro license status and your license key (if activated) are also stored locally in
chrome.storage.local so the Extension can verify your purchase offline between
periodic checks.
The Extension requests access to web pages you visit for these user-facing features only:
Page content is processed locally in your browser. It is not uploaded, logged, or transmitted to us or any third party.
If you purchase a Pro license, the Extension contacts our license server
(secure-totp-license-api.piyushchhabbi.workers.dev) to validate your license key. The following data is sent:
TOTP-XXXX-XXXX-XXXX)Your TOTP secrets, account names, and page content are never sent during license validation. We do not store personal information beyond what is needed to issue and validate license keys (license key, install ID, purchase timestamp).
Payments are processed by Gumroad. We do not receive or store your payment card details.
The Extension requires you to sign in with your Google account before use. We receive your Google account ID and email address (via Google's OAuth API) and store them on our license server for identity, Pro license restore, and optional encrypted cloud sync. We never receive your Google password or TOTP secrets.
If you use cloud sync (Pro), your vault is encrypted on your device using your Google account identity before upload. Only ciphertext is stored on our server — we cannot decrypt it without your signed-in Google session on a device.
To improve the product, the Extension may send anonymous events to Google Analytics 4 using
Google's Measurement Protocol (no advertising IDs, no TOTP data). Examples: popup opened,
Pro tab viewed, upgrade nudge shown, license activated. Events use a random client ID stored
in chrome.storage.local on your device.
Not collected in analytics events: TOTP secrets, account names, page URLs, hostnames, or raw email addresses (signed-in users send a hashed Google ID only).
See Google's Privacy Policy. Chrome Web Store may also provide the developer with separate aggregate statistics.
Our marketing website at getsecuretotp.us (not the Chrome Extension) may display
third-party advertisements through Google AdSense when enabled. Google and its
partners may use cookies or similar technologies to serve and measure ads, including personalized
ads where permitted by law and your consent settings. We do not receive your TOTP secrets or
Extension data through AdSense.
The site also uses Google Ads conversion tags to measure whether visitors from our paid campaigns reach the site. Google may collect page views, referrer, and device/browser data. See Google's Privacy Policy and Google Ad Settings to manage ad personalization. Website tags and ads are separate from Extension analytics events.
This privacy policy page does not show AdSense ad units.
You can remove individual accounts from the Extension popup at any time. You can remove your Pro license from the Pro tab. Uninstalling the Extension removes all locally stored data from Chrome.
The Extension is not directed at children under 13 and does not knowingly collect information from anyone.
We may update this policy occasionally. Changes will be posted on this page with an updated date.
Questions about this policy? Contact: support@getsecuretotp.us