Privacy policy
This website collects nothing about you by default: no cookies, no analytics, no third-party requests. The apps store your two-factor codes encrypted on your device and send nothing anywhere unless you turn on Cloud Sync or connect the browser extension. The sections below cover exactly what that means.
In short
- No account is needed to use the app, and none is created unless you opt in to a connected feature.
- Your two-factor secrets stay on your device, encrypted. We never receive them.
- This website sets no cookies and runs no analytics.
- Cloud Sync backups go to your own iCloud or Google Drive, not to servers we run.
- We don't sell data, show ads, or share anything with data brokers.
Who we are
TOTP Authenticator is operated by Nexora Digitech Private Limited, a company registered in India. Questions about this policy go to support@nexoradigitech.com.
This website
nexoradigitech.com is a static site with zero third-party requests: fonts are self-hosted, there is no content-delivery network, and no script or style loads from anywhere but this domain. We do not currently run analytics of any kind: no page-view tracking, no cookies, no session recording, nothing from Google Analytics, Meta, or similar. If we later add cookieless, self-hosted analytics (aggregate page metrics only, no personal data, no cross-site tracking), we'll describe exactly what it collects in this section first.
Support requests you send us (email, in-app feedback) contain whatever you choose to write. We use that only to help you and don't sell or share it.
The apps
TOTP Authenticator doesn't require an account to work. Your two-factor secrets are generated and stored, encrypted, on your device. See how the encryption works for the full detail. Two things change that:
- Cloud Sync (optional, paid) writes an encrypted backup of your accounts to your own iCloud (iOS) or Google Drive (Android) account. That backup lives in storage you control, not on a server we run.
- Browser extension (optional, paid) relays an already-computed, expiring six-digit code through our infrastructure to your browser add-on when you request one. The secret that generates your codes never makes that trip, only the code itself, encrypted.
See who we rely on to run either of these at subprocessors.
Purchases
Cloud Sync and browser-extension push are unlocked by a one-time, per-platform purchase (see pricing) handled entirely by the Apple App Store or Google Play. We never see or store your payment details; the stores do.
How long we keep things
Data on your device stays until you delete it or uninstall the app. Cloud Sync backups stay in your own iCloud or Google Drive until you delete them there. Support email is kept only as long as we need it to resolve your request and a reasonable period afterwards, in case you write back about the same issue. Browser-extension relay entries expire on their own: the relayed code is only valid for its 30-second window.
Your rights
Wherever you live, you can ask us what we hold about you, ask for a copy, or ask us to delete it by emailing support@nexoradigitech.com. For most people the honest answer is that we hold nothing, because the app runs without an account. Where local law (such as the GDPR or CCPA) gives you additional rights, those apply on top of this section.
Deleting your data
Because most of what the app stores lives only on your device, uninstalling removes it. For Cloud Sync backups, browser-extension links, and anything else, see deleting your account and data.
Children's privacy
TOTP Authenticator is not directed at children and we don't knowingly collect data from them.
Changes to this policy
We'll update this page when what we collect changes, and keep the effective content current rather than backdating changes.