TOTP Token Generator logoTOTP Token Generator

Privacy Policy

Last Updated: October 8, 2026

1. The short version

TOTP Token Generator is a two-factor authenticator that runs entirely in your browser. There is no account, no login, and no server-side database of secrets. Your tokens are encrypted on your device with a master password that only you know, and the encrypted vault is stored in your own browser storage. This page explains that in detail, along with the limited data collection that does happen through analytics and advertising.

2. What we do not collect

TOTP Token Generator has no accounts and no API. We do not receive, store, or transmit:

  • Your TOTP secrets or the codes generated from them
  • Your master password, or any key derived from it
  • The service names, account names, or tags you store in the vault
  • Encrypted backups you export (they are written directly to your device)

The service you use is a static page plus the operating system's own cryptography. Nothing in the workflow requires sending your secrets anywhere.

3. Where your data lives

3.1 Local encrypted vault

Tokens are encrypted with AES-GCM-256 using a key derived from your master password via PBKDF2-HMAC-SHA-256 (600,000 iterations with a random salt). The ciphertext, the salt and the iteration count are stored in your browser's IndexedDB. The salt and iteration count are not secret; they are needed to unlock the vault.

3.2 Memory-only key

The derived key is marked non-extractable and is never written to storage or sent over the network. It is discarded when you lock the vault, close the tab, or reload the page.

3.3 No recovery

Because no copy of your key exists outside your device, a forgotten master password means the vault cannot be decrypted by anyone — including us. There is no reset, no support override, and no server-side backup.

3.4 Local preferences

Interface preferences (sort order, active filter, auto-lock timeout, dismissed banners) are stored unencrypted in the same browser storage. None of them are secret.

3.5 Camera

The QR scanner asks for camera permission only when you press Start scanning. Video frames are decoded in a local canvas to read a TOTP QR code; no frame is recorded, stored, or transmitted. Closing the dialog stops the camera track immediately.

4. Cookies, analytics and advertising

4.1 Analytics

We use Google Analytics 4 to understand aggregate usage — for example how many visitors load the page and which features are used. Analytics never receives your secrets, your password, or the contents of your vault; events we track are limited to coarse product actions such as creating a vault or adding a token.

4.2 Advertising

This site is supported in part by advertising. Third-party vendors, including Google, use cookies and similar technologies to serve ads based on your prior visits to this or other websites.

Google's use of advertising cookies enables it and its partners to serve ads based on your visit to our site and/or other sites on the Internet. You may opt out of personalised advertising by visiting Google Ads Settings, or opt out of a third-party vendor's use of cookies for personalised advertising by visiting aboutads.info.

For more information about how Google uses data from sites that use its services, see How Google uses information from sites or apps that use our services.

Advertising scripts are loaded on content pages. They are deliberately kept out of the vault interface itself: code cards, the unlock screen and the token editor never render ad units.

4.3 Local storage

Besides the encrypted vault, we use browser storage for interface preferences only. You can delete it at any time through your browser's site-data settings; deleting it also deletes the vault, so export a backup first if you need one.

5. Third-party services

The site is served through Cloudflare, which processes requests to deliver the pages. Typefaces are loaded from Google Fonts. Analytics is provided by Google Analytics and advertising by Google AdSense. Beyond these, the page does not contact third-party servers — in particular, it does not fetch service logos or icons from external networks, because that would leak which services you use.

6. Security and its limits

The vault is protected by authenticated encryption and a deliberately slow key derivation. Those protections cover data at rest on your device. They cannot protect you from a compromised browser: a malicious extension or injected script running in the same page could read secrets while the vault is unlocked. Keep your browser and extensions trustworthy, and lock the vault when you are done.

7. Children's privacy

TOTP Token Generator is not directed at children under 13, and we do not knowingly collect personal information from them. Since we operate no accounts, we hold no profile data about any user.

8. Changes to this policy

We may update this Privacy Policy as the product changes. Material changes will be reflected in the date at the top of this page.

9. Contact

Questions about this Privacy Policy can be sent to support@totptokengenerator.com.