Privacy Policy
Our commitment to protecting your privacy and personal data
Effective Date: January 1, 2025
Privacy-First Approach
TOTP Generator operates with a privacy-by-design philosophy. We collect zero personal data and perform all operations locally in your browser. This policy explains our practices and your rights.
Information We Collect
Personal Information
We do NOT collect any personal information, including but not limited to:
- Names, email addresses, or contact information
- TOTP secret keys or generated codes
- Account credentials or passwords
- Device identifiers or fingerprints
- Location data or IP addresses
- Usage patterns or behavioral data
Technical Information
The only information that may be logged are standard web server logs for basic operational purposes:
| Data Type | Collected | Purpose | Retention |
|---|---|---|---|
| TOTP Secret Keys | No | N/A | Never stored |
| Generated TOTP Codes | No | N/A | Never stored |
| IP Addresses | No | N/A | Not logged |
| Browser Information | No | N/A | Not stored |
| Usage Analytics | No | N/A | Not tracked |
| Cookies | No | N/A | None set |
How We Process Data
Client-Side Processing
All TOTP generation occurs entirely within your web browser using JavaScript. Your secret keys and generated codes never leave your device. The processing includes:
- Local computation: TOTP algorithms run on your device's CPU
- Memory-only storage: Data exists only in browser memory during use
- No transmission: No data is sent to our servers or third parties
- Automatic cleanup: Data is cleared when you close the browser tab
Server Responsibilities
Our servers only deliver static HTML, CSS, and JavaScript files. We do not:
- Process or handle your TOTP data
- Store any user-generated content
- Maintain databases of user information
- Track user interactions or behavior
- Share data with advertisers or partners
Use of Information
Since we don't collect personal information, we cannot use it for any purpose. The TOTP Generator service:
- Provides TOTP generation functionality only
- Does not create user profiles or accounts
- Does not send marketing communications
- Does not perform data analysis on user behavior
- Does not monetize user data in any way
Data Sharing and Disclosure
We do not share, sell, rent, or disclose any personal information because we don't collect any. However, we may disclose information if required by law:
- Legal compliance: If required by valid legal process
- Security threats: To address security violations or protect rights
- Service protection: To maintain the integrity of our service
Important Note
Since we don't collect or store personal data, there would be no user information to disclose even under legal compulsion.
Your Privacy Rights
Depending on your jurisdiction, you may have various privacy rights. Since we don't collect personal data, most of these rights are inherently protected:
Right to Access
You can request information about data we hold. Since we collect no personal data, there's nothing to access.
Right to Deletion
You can request deletion of your data. Since we store no personal data, there's nothing to delete.
Right to Portability
You can request data in a portable format. Since we store no data, there's nothing to export.
Right to Correction
You can request correction of inaccurate data. Since we store no data, there's nothing to correct.
Right to Restriction
You can request restricted processing. Since we process no personal data, this is inherently satisfied.
Right to Object
You can object to data processing. Since we process no personal data, there's nothing to object to.
International Data Transfers
Since all processing occurs in your browser and we don't collect personal data:
- No international data transfers occur
- Your data remains in your jurisdiction
- No cross-border privacy concerns exist
- Local data protection laws are respected
Data Security
While we don't store personal data, we implement security measures to protect our service:
- HTTPS encryption: All connections use TLS 1.3
- Content Security Policy: Prevents code injection attacks
- Subresource Integrity: Validates external resources
- HSTS headers: Forces secure connections
- Regular updates: Keeping software current
- No third-party scripts: Eliminates external tracking
Children's Privacy
Our service doesn't knowingly collect information from children under 13 (or applicable age in your jurisdiction). Since we collect no personal information from anyone:
- Children can safely use our service
- No age verification is required
- No special parental controls are needed
- COPPA compliance is inherently maintained
Cookies and Tracking
We do not use:
- Cookies of any kind (session, persistent, or third-party)
- Local storage for tracking purposes
- Web beacons or tracking pixels
- Analytics or measurement tools
- Social media tracking
- Advertising networks
Changes to This Privacy Policy
We may update this privacy policy to reflect:
- Changes in applicable laws
- Updates to our service
- Improvements to our privacy practices
Material changes will be posted on this page with an updated "Last Modified" date. Continued use after changes constitutes acceptance of the new policy.
Compliance Information
This privacy policy is designed to comply with major privacy regulations:
- GDPR: European Union General Data Protection Regulation
- CCPA: California Consumer Privacy Act
- PIPEDA: Personal Information Protection and Electronic Documents Act (Canada)
- LGPD: Lei Geral de Proteção de Dados (Brazil)
- COPPA: Children's Online Privacy Protection Act
Contact Information
For privacy-related questions or concerns, please contact us:
Email: privacy@totpgenerator.com
Data Protection Officer: dpo@totpgenerator.com
Address: TOTP Security Solutions
123 Privacy Lane
Data Protection City, DP 12345
United States
Response Time: We aim to respond to privacy inquiries within 30 days.
Summary
TOTP Generator is designed for maximum privacy. We collect no personal data, perform no tracking, and ensure all processing happens locally on your device. Your privacy is protected by design, not just by policy.