Your key.
Your business.
The authenticator processes your secret in your browser. It does not upload or retain it.
Effective September 17, 2026
Secret keys and generated codes
Keys and codes stay in the current page’s memory. We do not send them to an API, write them to cookies or browser storage, or include them in page URLs. Use “Clear everything” to remove them from the interface and application state. Closing the tab ends the session; browsers and extensions control their own memory and session behavior.
Ordinary website requests
Your browser contacts the hosting server to load pages and assets. The hosting provider may process your IP address, browser information, requested path, and request time for delivery and security. The application itself does not create visitor logs or store accounts. Hosting log retention is controlled by the hosting operator.
Cookies and analytics
This release does not set cookies, use browser storage, or load analytics. Copying a code places it on your system clipboard at your request; your device may retain clipboard history.
Advertising
Advertising is disabled in this release. The authenticator page does not load advertising scripts, even if advertising is later enabled elsewhere. If ads are introduced on informational pages, this policy must be updated with the provider’s data practices and any required consent choices before activation.
Your choices
You can use the tool without registration, clear the current session, and choose not to copy codes. Only enter secrets on devices and browsers you trust. Extensions or other software with access to the page may be able to read its contents.
Changes
Updates to these practices will be reflected on this page with a revised effective date.