Last updated: July 11, 2026
2FA Live does not collect, transmit, or have access to any of your data. There is no account, no server, and no analytics. Every two‑factor code, secret key, and setting you add is stored only in your own browser, encrypted with a passphrase that only you know.
There is no way for us — or anyone else — to recover your data if you forget your passphrase or lose your browser profile without a backup. That trade‑off is intentional: it's what makes the encryption meaningful.
By installing or using the "2FA Live — Authenticator & OTP Code Generator" browser extension ("the Extension", "we", "our"), you agree to these Terms of Service. If you don't agree, please don't install or use the Extension.
2FA Live generates time‑based one‑time password (TOTP) codes for two‑factor authentication, entirely inside your browser. It lets you add accounts by scanning a QR code shown on a webpage, uploading or pasting a QR code image, pasting an otpauth:// link, or entering a secret key manually. All codes and account data are encrypted at rest with a passphrase you choose.
The Extension is provided "as is" and "as available", without warranties of any kind, express or implied, including but not limited to fitness for a particular purpose or non‑infringement. You use it at your own risk.
To the maximum extent permitted by law, we are not liable for any indirect, incidental, special, or consequential damages arising from your use of, or inability to use, the Extension — including loss of access to your accounts due to a forgotten passphrase, browser data loss, or similar events.
We may update these Terms from time to time. Continued use of the Extension after changes are published constitutes acceptance of the updated Terms. The "Last updated" date at the top of this page reflects the most recent revision.
You may stop using the Extension at any time by removing it from your browser via your browser's extension settings. Uninstalling deletes all locally stored data associated with the Extension, unless you have exported a backup beforehand.
None. The Extension does not have a server, does not use analytics or crash‑reporting services, does not embed third‑party trackers or ads, and does not transmit any data over the network. We — the developer — have no ability to see your accounts, secrets, codes, or any other information you enter.
Everything you add (issuer, account label, secret key, algorithm, digits, and refresh period) is encrypted with AES‑256‑GCM using a key derived from your passphrase (PBKDF2, 210,000 iterations), and stored using your browser's built‑in extension storage APIs — physically, on your own device. It never leaves your browser unless you explicitly export a backup file yourself.
When you scan a QR code from the current tab or from an uploaded/pasted image, that image is decoded entirely inside your browser (using your browser's built‑in barcode reader, or a bundled offline decoding library as a fallback). The image itself is never uploaded or sent anywhere.
If you turn on the optional setting to stay unlocked after closing your browser, the Extension stores your derived unlock key (not your passphrase) locally on your device so you aren't asked for it again. This key never leaves your device either. You can turn this off, or lock the vault manually, at any time from the Extension's Settings.
| Permission | Why it's needed |
|---|---|
storage | To save your encrypted vault and preferences locally in your browser. |
activeTab | To let you capture a screenshot of the page you're viewing when you choose to scan a QR code from it. Only triggered by your explicit action; no background access to your tabs. |
alarms | To automatically lock your vault after the period of inactivity you configure in Settings. |
We do not share data with third parties, because we do not collect or receive any data to share in the first place.
The Extension is not directed at children and does not knowingly collect information from anyone, regardless of age — because it does not collect information at all.
If this policy changes, we'll update the "Last updated" date above. Since the Extension has no way to contact you directly, please check back here periodically if you have concerns.
Questions about these Terms or this Privacy Policy? Reach out at taibanhatk1@gmail.com.