Quick summary (not a substitute for reading the full text)

2FA Live does not collect, transmit, or have access to any of your data. There is no account, no server, and no analytics. Every two‑factor code, secret key, and setting you add is stored only in your own browser, encrypted with a passphrase that only you know.

There is no way for us — or anyone else — to recover your data if you forget your passphrase or lose your browser profile without a backup. That trade‑off is intentional: it's what makes the encryption meaningful.

Terms of Service

1. Acceptance

By installing or using the "2FA Live — Authenticator & OTP Code Generator" browser extension ("the Extension", "we", "our"), you agree to these Terms of Service. If you don't agree, please don't install or use the Extension.

2. What the Extension does

2FA Live generates time‑based one‑time password (TOTP) codes for two‑factor authentication, entirely inside your browser. It lets you add accounts by scanning a QR code shown on a webpage, uploading or pasting a QR code image, pasting an otpauth:// link, or entering a secret key manually. All codes and account data are encrypted at rest with a passphrase you choose.

3. No account, no warranty

The Extension is provided "as is" and "as available", without warranties of any kind, express or implied, including but not limited to fitness for a particular purpose or non‑infringement. You use it at your own risk.

4. Your responsibility

5. Limitation of liability

To the maximum extent permitted by law, we are not liable for any indirect, incidental, special, or consequential damages arising from your use of, or inability to use, the Extension — including loss of access to your accounts due to a forgotten passphrase, browser data loss, or similar events.

6. Changes

We may update these Terms from time to time. Continued use of the Extension after changes are published constitutes acceptance of the updated Terms. The "Last updated" date at the top of this page reflects the most recent revision.

7. Termination

You may stop using the Extension at any time by removing it from your browser via your browser's extension settings. Uninstalling deletes all locally stored data associated with the Extension, unless you have exported a backup beforehand.

Privacy Policy

1. Data we collect

None. The Extension does not have a server, does not use analytics or crash‑reporting services, does not embed third‑party trackers or ads, and does not transmit any data over the network. We — the developer — have no ability to see your accounts, secrets, codes, or any other information you enter.

2. Where your data lives

Everything you add (issuer, account label, secret key, algorithm, digits, and refresh period) is encrypted with AES‑256‑GCM using a key derived from your passphrase (PBKDF2, 210,000 iterations), and stored using your browser's built‑in extension storage APIs — physically, on your own device. It never leaves your browser unless you explicitly export a backup file yourself.

3. QR code scanning

When you scan a QR code from the current tab or from an uploaded/pasted image, that image is decoded entirely inside your browser (using your browser's built‑in barcode reader, or a bundled offline decoding library as a fallback). The image itself is never uploaded or sent anywhere.

4. Optional "keep unlocked" setting

If you turn on the optional setting to stay unlocked after closing your browser, the Extension stores your derived unlock key (not your passphrase) locally on your device so you aren't asked for it again. This key never leaves your device either. You can turn this off, or lock the vault manually, at any time from the Extension's Settings.

5. Browser permissions and why we need them

PermissionWhy it's needed
storageTo save your encrypted vault and preferences locally in your browser.
activeTabTo let you capture a screenshot of the page you're viewing when you choose to scan a QR code from it. Only triggered by your explicit action; no background access to your tabs.
alarmsTo automatically lock your vault after the period of inactivity you configure in Settings.

6. Third parties

We do not share data with third parties, because we do not collect or receive any data to share in the first place.

7. Children's privacy

The Extension is not directed at children and does not knowingly collect information from anyone, regardless of age — because it does not collect information at all.

8. Changes to this policy

If this policy changes, we'll update the "Last updated" date above. Since the Extension has no way to contact you directly, please check back here periodically if you have concerns.

Contact

Questions about these Terms or this Privacy Policy? Reach out at taibanhatk1@gmail.com.