Stored locally
Encrypted vault records remain in your browser profile.
Privacy policy
TOTP Vault is a local-first authenticator. It has no account system, cloud sync, telemetry, advertising, analytics, or business network requests.
Encrypted vault records remain in your browser profile.
Developer personnel and third parties cannot access your vault.
Data is handled only to deliver the authenticator features you request.
01
The extension locally handles your Master Password, TOTP secrets and codes, account metadata, and—only after an explicit QR scan action—a screenshot of the visible tab.
Master Passwords, codes, screenshots, and QR decoding results are not persisted or uploaded. Vault records are encrypted before they are stored.
For marketplace disclosure, local processing includes personally identifiable information when an account label contains an email address or username, authentication information, user-entered metadata, and visible website content during a user-triggered QR scan. These categories do not mean that the data is sent to us.
02
TOTP Vault does not request clipboard read access, host permissions, <all_urls>, cookies, or browsing-history permission. It does not read, monitor, or automatically clear your clipboard.
04
You can edit or delete individual accounts inside the extension. TOTP Vault V1.0 Personal has no cloud backup, recovery key, cross-device sync, or server-side password reset.
Uninstalling the extension or clearing its storage may permanently remove the vault. Keep each service’s recovery codes somewhere safe before making changes.
05
All JavaScript, WebAssembly, and runtime resources ship inside the extension package. TOTP Vault does not use remote code. If features or data practices change, this policy will be updated before the new behavior is released.
For product questions or a safe issue-reporting checklist, visit TOTP Vault Support.