Privacy

Privacy & security

TOTP Studio generates codes in your browser. Guest vaults stay on this device. If you enable cloud sync, your vault is encrypted before it leaves your device.

What the server sees

If you sign in and enable cloud sync, the server sees:

  • a stable opaque account id,
  • opaque per-record ids (random UUIDv4, non-correlatable),
  • per-record version numbers,
  • coarse hour-bucket timestamps (not seconds),
  • your subscription state,
  • your device list (id, label, public-key fingerprint, hour-bucket last-seen).

The server does not see your issuer, account label, algorithm, digits, period, current codes, or the secret itself.

What admin cannot see

Admin staff cannot decrypt your vault, view your current codes, export your secret, reset your passphrase, or satisfy end-user re-authentication on your behalf.

No third-party scripts

The vault, add, scan, sync, settings, and admin routes load no third-party scripts and no analytics. The QR scanner runs entirely in this browser; camera frames are never uploaded.

Recovery

There is no admin-driven secret recovery. If you lose your device and your passphrase, your vault is unrecoverable.