2FA Live Code ← Back to the code generator

Privacy Policy

Last updated: 7 August 2026

Short version: we do not collect anything. There is no account system, no analytics, no advertising and no database. Your two-factor keys are processed inside your own browser and are never transmitted to us, because there is nothing on our side to transmit them to.

1. What we collect about you

Nothing that identifies you. The generator has no sign-up, no login, no cookies, no analytics or tracking scripts, and no advertising. We do not build profiles, we do not set identifiers, and we have no way to link one visit to another.

2. Your 2FA keys never reach us

When you paste a setup key, scan a QR code, or import from Google Authenticator, everything happens inside your browser using its built-in cryptography. No key, and no code generated from a key, is ever sent over the network.

You can verify this yourself: load the page, disconnect from the internet, and it keeps generating codes. You can also download the whole tool as one file and run it from your own computer with no connection at all.

3. What is stored on your own device

By default, nothing is saved. Closing the tab discards your keys.

If you choose Save these on this device, your keys are encrypted with a passphrase you pick before they are written, and are stored in your browser's own local storage on your machine. That data never leaves your device and we cannot read it — without your passphrase it is unreadable to anyone, including us. You can delete it at any time with Delete vault, or by clearing your browser's site data.

Downloaded backup files and printed recovery sheets are yours alone. We never see them.

4. The one optional outbound request

The Check clock button compares your device clock against internet time, because a drifting clock is the usual reason a website rejects a valid code. It only runs when you press it.

Where possible the check reads the time from our own server, so nothing is shared with any third party. If that is unavailable, it falls back to a public time service (timeapi.io or worldtimeapi.org). As with any web request, those services will see your IP address and browser user-agent. They receive nothing else, and never any part of your keys. If you would rather not contact them, simply do not press the button.

5. Server logs

Our hosting provider records standard access logs when a page is served — typically IP address, date and time, the file requested, and browser user-agent. This is ordinary web server behaviour, used for security and to keep the site running. These logs contain no key material, since keys are never sent. We do not use them to identify or profile visitors.

6. Third parties

The page loads no third-party scripts, fonts, trackers or advertising. Everything it needs is contained in the page itself. The only third parties that can ever be contacted are the fallback time services described in section 4, and only if you press that button.

7. Children

This is a general-purpose security utility, not directed at children. We do not knowingly collect information from anyone, of any age, because we do not collect information at all.

8. Your rights

Data protection laws such as the GDPR and CCPA give you rights to access, correct, export or delete personal data held about you. We hold none, so there is nothing for us to produce or erase. Data stored on your own device is under your control and can be deleted by you at any time, as described in section 3.

9. Changes to this policy

If this policy changes, the date at the top of this page will change with it. If we ever introduce anything that collects data — analytics or advertising, for instance — we will say so plainly here and on the main page, rather than quietly amending this document.

10. Contact

Questions about privacy: contact us.

Never send us a setup key. No legitimate support request requires one, and we will never ask. Anyone who does is trying to take over your account.