Privacy policy for OTP Safebox
OTP Safebox by JunjieWan
OTP Safebox (private2fa) is an open-source TOTP authenticator vault. This policy explains how we handle your data when you use this service.
What we collect
Account information: nickname, email and avatar obtained when you sign in with GitHub / Google.
Device tokens: random device identifiers generated for Chrome extension cloud sync.
Vault data: your OTP keys. The server only stores ciphertext encrypted with your account key and cannot read plaintext; the extension additionally encrypts locally with your master password (PBKDF2 + AES-GCM, end-to-end).
Anonymous analytics: page-visit statistics via Google Analytics (no OTP data).
How we use it
To provide core features: sign-in, key management and cross-device sync.
To improve service stability and page experience.
We never sell your personal information to third parties, and we show no personalized ads.
Storage & transfer
The service is hosted on Vercel; data lives in its Neon PostgreSQL database (Southeast Asia region).
OTP keys are stored as ciphertext on the server, which cannot decrypt them; only ciphertext travels between devices.
Sign-in sessions are kept with secure HttpOnly cookies.
Third-party services
GitHub / Google: sign-in authentication.
Vercel / Neon: hosting and database.
Google Analytics: anonymous page statistics.
Your rights
View & export: after signing in you can view all codes; ciphertext can be obtained via “Sync now” in the Chrome extension.
Delete: remove individual keys anytime on the page or in the extension; after clearing the cloud vault, server-side data is immediately unavailable.
Account deletion: contact us and we will remove related cloud data upon request.
Contact us
For questions or requests, file a GitHub Issue: https://github.com/junka/private2fa/issues