Privacy Policy
Last updated: April 19, 2026
2FAnyone ("we", "us", "our") provides a shared two-factor authentication service for teams. This policy explains what data we collect, how we use it, and the choices you have.
Information We Collect
- Account data: name, email address, and hashed password.
- Team data: team names, membership, and the 2FA services you add. Secrets (TOTP seeds) are encrypted at rest.
- Billing data: handled by our payment processor (Stripe). We do not store card details.
- Usage data: basic, privacy-respecting analytics via Fathom. No cookies, no cross-site tracking.
How We Use Information
- To provide, maintain, and secure the service.
- To communicate with you about your account, billing, and service changes.
- To detect and prevent abuse.
Sharing
We do not sell your data. We share data only with service providers needed to run 2FAnyone (hosting, email delivery, payment processing), and when required by law.
Data Retention
We keep your data while your account is active. You can delete your account at any time; backups are purged on a rolling schedule.
Your Rights
You can access, export, or delete your data by contacting [email protected].
Contact
Questions? Email [email protected].