TOTP Vault

Privacy Policy

Effective date: September 8, 2026 · Extension version 0.2.0

TOTP Vault is an offline Chrome extension for managing time-based one-time passwords (TOTP). This policy explains what information the extension processes, how it stores that information, and the choices available to you.

Your authenticator accounts stay in your browser. TOTP Vault does not upload your vault, secrets, master password, QR images, or verification codes to the publisher or to external servers.

1. Information you provide

The extension processes the information needed for its authentication features:

  • Service names, account labels (which may contain an email address or username), TOTP secret keys, and account metadata such as the algorithm, code length, refresh period, and creation date.
  • Your master password, used locally to derive the encryption key for your vault.
  • QR code images or camera frames that you choose to scan, and backup files that you choose to import.
  • Your language preference and the selected unlock duration.

No separate online account is required to use the extension.

2. Local processing and protection

Account data is encrypted with AES-GCM before it is saved in Chrome's local extension storage. The encryption key is derived from your master password using PBKDF2 with SHA-256. The extension does not persist your master password or a plaintext copy of your account secrets.

While the vault is unlocked, decrypted account data is available in extension memory. A derived encryption key and an expiration timestamp are also kept in Chrome's session memory so that you can reopen the popup during an unlocked session. The extension checks that expiration when opening and while the popup is active. Manual locking removes the stored session key; restarting the browser clears Chrome's session storage.

Language and unlock-duration preferences are saved locally outside the encrypted vault. The publisher does not have your master password and cannot recover it or decrypt your vault for you.

3. QR codes, camera, and clipboard

Camera access is requested only when you choose camera scanning. QR recognition runs locally. The extension does not record or upload camera video or QR images; camera access stops when scanning is stopped or its view is closed.

When you click a verification code, the extension writes that code to your system clipboard. It does not read your clipboard. Your operating system, clipboard history, or other applications may retain copied content independently of the extension.

4. Backups, retention, and deletion

Exporting creates an encrypted backup file on your device, protected by the master password in use when that backup was made. Importing decrypts a file locally and saves the imported accounts in your current encrypted vault. Files are not sent to the publisher.

Accounts remain in local extension storage until you delete them, replace them through an import, clear the extension's data, or uninstall the extension. Deleting accounts or uninstalling does not remove backup files, source QR images, or clipboard history stored elsewhere on your device. You control those copies separately.

5. Sharing and limited use

The extension does not include analytics, advertising, behavioral tracking, cloud synchronization, or remotely hosted executable code. It does not collect browsing history or access the contents of the websites you visit.

TOTP Vault's use of user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used only to provide the extension's TOTP management features. The publisher does not sell or transfer your extension data to third parties, use it for personalized advertising, or use it to determine creditworthiness or for lending.

6. This policy website and support

This public policy page is separate from the extension. Its hosting provider may process standard web-request information, such as an IP address and browser details, to deliver and protect the page. Visiting this page does not give it access to your TOTP vault.

If you email the publisher for support, the publisher and email provider will receive the address and message you send and use them to respond to your request. Please do not send master passwords, TOTP secrets, active verification codes, or backup files.

7. Policy updates

This policy may be updated when the extension's data practices change. The effective date above will be updated accordingly. Material changes will also be reflected in the extension's store disclosures and, where applicable, its interface.

8. Contact

For privacy questions or requests, contact the TOTP Vault publisher: java22031@gmail.com.