Privacy Policy
What FactorTwo is
FactorTwo is a Chrome extension with a single purpose: it stores your two-factor authentication (2FA) accounts and fills the matching one-time code into the page that asks for it.
Information stored on your device
To do its job, FactorTwo stores the following in your browser profile, on your device:
- Your authenticator accounts: issuer, account name, secret key and code settings.
- Which sites each account is linked to, and your FactorTwo settings.
- If you set a password, the encrypted vault, plus the optional recovery code and passkey wrappers that unlock it.
- Up to 7 rolling local backup snapshots, kept in your browser's local storage (IndexedDB).
This information never leaves your device unless you turn on one of the optional backups below. We (the developers) never receive it.
Optional backups
- OneDrive. If you click “Connect OneDrive”, you sign in with Microsoft and FactorTwo requests only the
Files.ReadWrite.AppFolderandoffline_accesspermissions. That limits it to its own hidden app folder, not the rest of your OneDrive. An encrypted backup file is stored there. It goes directly from your browser to Microsoft; it does not pass through any server of ours. Microsoft's privacy statement applies to what they store. - Browser sync. If you turn on backup to your browser's sync storage (
chrome.storage.sync), an encrypted copy is synced by Chrome according to your own browser sync settings. - File export. You can export an encrypted file, or a CXF file, whenever you like. Where it goes is up to you.
Backups are encrypted in your browser before they are stored: AES-256-GCM, with a key derived from your key phrase using PBKDF2-SHA256 at 600,000 iterations. Whoever stores the file receives only ciphertext.
Web pages and emailed codes
- Detecting code fields. To autofill, a FactorTwo script runs on web pages to detect one-time-code fields. It does not read, store or transmit the content of pages. A page receives only the one code that is being filled for it, for an account that matches that page.
- Gmail tab (beta). When a site is waiting for an emailed code or sign-in link, FactorTwo can read the text of a Gmail tab you already have open, to find the code or link. This happens locally in your browser; nothing from your email is stored or transmitted, and no Google API or Google sign-in is used.
- Camera. If you choose to scan a QR code with your camera, the camera image is processed locally to read the code. It is not saved or sent anywhere. Your browser asks for permission first.
Permissions, and why each is needed
| Permission | Why FactorTwo needs it |
|---|---|
storage | Keeps your accounts, settings, and backups in your browser. |
identity | Runs the optional Microsoft sign-in for OneDrive backup. |
alarms | Schedules automatic backups and auto-lock timers. |
idle | Locks the vault when your computer locks or goes idle. |
activeTab, scripting | Lets you capture or select a QR code on the page you're viewing, when you ask it to. |
clipboardWrite | Copies a code to your clipboard when you click copy. |
favicon | Shows each site's icon next to its account. |
contextMenus | Adds the right-click “Fill 2FA code” option. |
Access to web pages (http/https) and mail.google.com | Detects one-time-code fields to autofill, and reads an open Gmail tab for emailed codes (see above). |
What we don't do
- We do not collect, sell, rent or share your personal data.
- We do not use or transfer user data for purposes unrelated to FactorTwo's single purpose, or to determine creditworthiness or for lending.
- We do not use analytics, telemetry, advertising or tracking of any kind.
- We do not run accounts or servers for the extension, so there is nothing of yours for us to store, sell or lose.
Your control and deleting your data
Removing the extension deletes the data stored on your device. Backups you chose to create live in your own OneDrive, browser sync storage or exported files, so delete them there if you no longer want them. Because we hold no data about you, there is nothing for us to delete on our side.
Security
Set a password in FactorTwo's Settings to encrypt your accounts on disk and enable auto-lock. Without a password, accounts are stored unencrypted in your browser profile, as in most authenticator extensions. Keep your recovery code somewhere safe: we cannot reset your password or recover your vault, because we never have your keys.
Children
FactorTwo is not directed at children under 13, and we do not knowingly collect information from anyone.
Changes to this policy
If we change this policy, we will update the effective date above. If a change affects how your information is handled, we'll make that clear in the extension's update notes.
Contact
Questions about this policy: [add contact email here]