Last Updated: October 8, 2026
TOTP Token Generator is a two-factor authenticator that runs entirely in your browser. There is no account, no login, and no server-side database of secrets. Your tokens are encrypted on your device with a master password that only you know, and the encrypted vault is stored in your own browser storage. This page explains that in detail, along with the limited data collection that does happen through analytics and advertising.
TOTP Token Generator has no accounts and no API. We do not receive, store, or transmit:
The service you use is a static page plus the operating system's own cryptography. Nothing in the workflow requires sending your secrets anywhere.
Tokens are encrypted with AES-GCM-256 using a key derived from your master password via PBKDF2-HMAC-SHA-256 (600,000 iterations with a random salt). The ciphertext, the salt and the iteration count are stored in your browser's IndexedDB. The salt and iteration count are not secret; they are needed to unlock the vault.
The derived key is marked non-extractable and is never written to storage or sent over the network. It is discarded when you lock the vault, close the tab, or reload the page.
Because no copy of your key exists outside your device, a forgotten master password means the vault cannot be decrypted by anyone — including us. There is no reset, no support override, and no server-side backup.
Interface preferences (sort order, active filter, auto-lock timeout, dismissed banners) are stored unencrypted in the same browser storage. None of them are secret.
The QR scanner asks for camera permission only when you press Start scanning. Video frames are decoded in a local canvas to read a TOTP QR code; no frame is recorded, stored, or transmitted. Closing the dialog stops the camera track immediately.
We use Google Analytics 4 to understand aggregate usage — for example how many visitors load the page and which features are used. Analytics never receives your secrets, your password, or the contents of your vault; events we track are limited to coarse product actions such as creating a vault or adding a token.
This site is supported in part by advertising. Third-party vendors, including Google, use cookies and similar technologies to serve ads based on your prior visits to this or other websites.
Google's use of advertising cookies enables it and its partners to serve ads based on your visit to our site and/or other sites on the Internet. You may opt out of personalised advertising by visiting Google Ads Settings, or opt out of a third-party vendor's use of cookies for personalised advertising by visiting aboutads.info.
For more information about how Google uses data from sites that use its services, see How Google uses information from sites or apps that use our services.
Advertising scripts are loaded on content pages. They are deliberately kept out of the vault interface itself: code cards, the unlock screen and the token editor never render ad units.
Besides the encrypted vault, we use browser storage for interface preferences only. You can delete it at any time through your browser's site-data settings; deleting it also deletes the vault, so export a backup first if you need one.
The site is served through Cloudflare, which processes requests to deliver the pages. Typefaces are loaded from Google Fonts. Analytics is provided by Google Analytics and advertising by Google AdSense. Beyond these, the page does not contact third-party servers — in particular, it does not fetch service logos or icons from external networks, because that would leak which services you use.
The vault is protected by authenticated encryption and a deliberately slow key derivation. Those protections cover data at rest on your device. They cannot protect you from a compromised browser: a malicious extension or injected script running in the same page could read secrets while the vault is unlocked. Keep your browser and extensions trustworthy, and lock the vault when you are done.
TOTP Token Generator is not directed at children under 13, and we do not knowingly collect personal information from them. Since we operate no accounts, we hold no profile data about any user.
We may update this Privacy Policy as the product changes. Material changes will be reflected in the date at the top of this page.
Questions about this Privacy Policy can be sent to support@totptokengenerator.com.