Authenticator - Auth Code · Browser Extension

Privacy Policy

Effective date: August 7, 2026

In short: the Authenticator - Auth Code browser extension has no accounts, no servers, no analytics, no ads and no tracking. Your two-factor authentication secrets are stored inside your own browser and are never sent to us or to any third party.

1. Scope

This policy covers the Authenticator - Auth Code extension for Google Chrome, Microsoft Edge and Mozilla Firefox. Our iOS application is covered by its own policy at techsmart.bio/authenticatorapp/privacy-policy.html.

2. What we do not collect

We — the developer — receive no data at all from the extension. It contains no analytics, crash reporting, advertising or tracking code, requires no account or sign-in, and never transmits your 2FA secrets, generated codes, browsing activity or any personal information to us or to anyone else.

3. What the extension stores in your browser

This data is kept in the browser's extension storage (chrome.storage). You can choose between Local storage (this device only) and Sync storage in the extension's backup settings. If you set an optional password, your secrets are additionally encrypted with it before being stored.

4. Browser sync

If you choose Sync storage and have signed in to your browser with syncing enabled, your browser vendor (Google, Microsoft or Mozilla) replicates the extension's storage across your own devices under that vendor's privacy policy. This is a built-in browser feature; the data flows through your browser account, never through us. Choosing Local storage keeps everything on the current device.

5. Network access

The extension works fully offline and makes no network requests, with one optional exception: if you press Sync Clock with Google in the settings, it sends a single request to https://www.google.com/ and reads only the response's time header to correct your device clock so codes are generated with accurate time. No user data is sent with this request, and the permission for it is only requested when you use the feature.

6. QR scanning and imported images

When you click Scan QR Code, the extension takes a screenshot of the visible part of the current tab, decodes the QR code region you select entirely on your device, and discards the image. QR images you import from files are likewise processed locally. Nothing is uploaded anywhere.

7. Autofill and clipboard

Copying a code to the clipboard, or filling it into a login form, happens only when you click a code, use the keyboard shortcut, or the context-menu shortcut — and is processed entirely inside your browser.

8. Permissions summary

PermissionWhy the extension needs it
storageSave your 2FA entries and preferences in the browser.
activeTabCapture the current tab for QR scanning — only when you start a scan.
scriptingShow the QR selection overlay and fill codes into the page — only on your action.
alarmsAuto-lock: clear the cached password after the idle time you configure.
clipboardWrite (optional)Copy a code when you click it.
contextMenus (optional)Right-click shortcut that opens the extension in a small window, if you enable it.
www.google.com (optional)The one-time clock synchronisation described above.

9. Data retention and deletion

Your data stays in your browser until you delete entries in the extension or uninstall it. If you use Sync storage, delete your entries (or switch to Local) before uninstalling to remove them from your browser account's sync data as well; you can also clear synced extension data from your browser's sync settings. Backup files you export are ordinary files under your control.

10. Children

The extension does not collect data from anyone, including children, and is suitable for a general audience.

11. Your rights

Because we hold no data about you, requests under GDPR, CCPA and similar laws to access, correct, export or delete personal data have nothing to operate on — every piece of data the extension handles is already under your direct control in your browser.

12. Changes to this policy

If we ever change how the extension handles data, we will update this page and its effective date before the change ships.

13. Contact

Questions or concerns: [email protected]