Legal
Privacy Policy
Effective Date: August 26, 2026 · Last Updated: August 26, 2026
OTPSync ("we," "us," or "our") operates a browser-based two-factor authentication extension and related cloud synchronization services. This Privacy Policy describes what information we process, what we deliberately do not possess, and how our zero-knowledge architecture governs every byte that leaves your device.
Read this document carefully. By installing the OTPSync extension, creating an account, or using our services, you agree to the practices described below.
1. The Zero-Knowledge Principle
OTPSync is engineered around a zero-knowledge security model. In practical terms: we never receive, store, or possess your plaintext 2FA secrets, seed keys, TOTP tokens, or custom passcodes.
All sensitive vault data is encrypted locally on your device before it is transmitted to any cloud destination — whether that destination is OTPSync Cloud (our internal synchronization infrastructure) or your personal Google Drive account via the optional Google Drive backup feature.
Encryption is performed in the browser extension using AES-256-GCM. Key material is derived from your custom passcode through PBKDF2 with 600,000 iterations. Because decryption keys exist only in your device's session memory while the vault is unlocked, OTPSync cannot mathematically access, read, inspect, export, or recover your underlying authentication secrets — even if compelled by law, even if our servers are compromised, and even if you contact support requesting access.
We store only the resulting encrypted ciphertext blobs. Those blobs are useless without your passcode and your local device.
2. What We Do Not Collect or Store
To eliminate ambiguity, OTPSync does not collect, transmit to our servers, or retain in readable form:
- Plaintext TOTP seed keys or shared secrets
- Live one-time password codes generated by your vault
- Your custom passcode or any derivative decryption keys
- Recovery phrases or backup codes you generate locally
- Account labels, issuer names, or metadata in unencrypted form within our infrastructure
If you lose your custom passcode, we cannot reset it, bypass it, or reconstruct your vault. That limitation is architectural — not a policy choice.
3. Information We Do Collect
We collect only the minimum data required to operate accounts, enforce subscription tiers, maintain service integrity, and communicate with you about billing or security incidents.
3.1 Account Information
- Email address — used for account creation, authentication, purchase verification, and transactional communications.
- Display name — if you provide one during registration.
- Hashed account credentials — if you register with email and password, your password is stored using industry-standard one-way hashing. We never store plaintext passwords.
3.2 Device and Plan Enforcement Data
- Device identifiers — anonymous UUIDs assigned to each extension installation for the purpose of enforcing plan limits (Free: 1 active device; Premium: unlimited devices) and enabling remote revocation from your dashboard.
- Device metadata — browser type, operating system label, last active timestamp, and online/offline status. This data supports device management; it does not include vault contents.
- Secret count — we track the number of encrypted entries in your vault to enforce Free-tier limits (up to 15 secrets). We do not inspect the contents of those entries.
3.3 Payment Information
Premium Lifetime purchases are securely processed by our authorized payment processors and merchants of record, primarily Paddle and PayPal, with potential integration of Stripe in the future. OTPSync does not collect, process, or store full credit card numbers or financial statements. We only retain transaction identifiers, purchase date, plan status, and refund eligibility records as required for billing support and accounting.
3.4 Technical and Security Logs
Our servers may temporarily log IP addresses, request timestamps, API endpoint paths, and error codes for fraud prevention, rate limiting, and incident response. These logs do not contain vault payloads or authentication secrets.
3.5 Analytics and Third-Party Cookies
We use Google Analytics on our website (otpsync.com) to understand how visitors engage with our landing page, optimize site performance, and improve our marketing campaigns. Google Analytics collects anonymous data such as page views, time spent on the site, and referral sources. This data is aggregated and does not contain any personal information or vault data. You can opt-out of Google Analytics tracking through your browser settings or by using Google's official opt-out add-on.
4. How Encrypted Data Is Synchronized
When you enable cloud backup, your browser extension uploads encrypted vault snapshots. Depending on your settings, copies may be stored in:
- OTPSync Cloud — ciphertext hosted on our infrastructure, tied to your account ID.
- Google Drive — ciphertext written to your Google account's restricted application data folder. OTPSync accesses this folder only after you explicitly authorize Google OAuth. Google Drive data is subject to Google's Privacy Policy in addition to this one.
In every case, synchronization transfers encrypted blobs — never plaintext secrets. Decryption occurs exclusively on your device after you enter your custom passcode.
5. How We Use Your Information
We use collected data to:
- Authenticate your account and maintain active sessions
- Enforce Free and Premium plan restrictions
- Process payments and honor refund requests within our published policy
- Send service-related emails (receipts, security alerts, account deletion confirmations)
- Detect abuse of synchronization infrastructure or API rate limits
- Comply with applicable legal obligations
We do not sell your personal information. We do not use your email for third-party advertising lists.
6. Data Retention and Deletion
Account data is retained while your account remains active. Encrypted vault ciphertext on OTPSync Cloud is deleted when you delete your account or when you issue a remote wipe command from your dashboard. Google Drive backups remain under your control until you revoke OAuth access or delete files through Google.
Upon account deletion, we schedule permanent erasure of associated server-side records in accordance with our data lifecycle procedures. Some billing records may be retained as required by tax and financial regulations.
7. Your Rights and Choices
Depending on your jurisdiction, you may have rights to access, correct, or delete personal data we hold about your account. Because vault secrets are zero-knowledge encrypted, we cannot export or disclose decrypted 2FA data — only account-level metadata.
You may revoke Google Drive access at any time through your Google Account permissions panel. You may uninstall the extension and request account deletion through the OTPSync dashboard.
8. Children's Privacy
OTPSync is not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has created an account, contact us and we will delete it.
9. International Users
Our servers and cloud synchronization infrastructure are hosted securely on Hetzner Cloud located in Germany. By accessing and using our services, you acknowledge that your account metadata and encrypted vault ciphertext are processed and stored in Germany, adhering to strict European data protection and privacy standards.
10. Changes to This Policy
We may revise this Privacy Policy to reflect product changes or legal requirements. Material updates will be posted on this page with a revised "Last Updated" date. Continued use of OTPSync after changes take effect constitutes acceptance of the updated policy.
11. Contact
Privacy-related inquiries may be directed to:
Email: [email protected]