Privacy policy for TOTP Vault by HWO
TOTP Vault by HWO by Hardwarriore
Effective date: September 8, 2026
TOTP Vault is a browser extension for generating and managing time-based one-time passwords (TOTP).
TOTP account configuration, shared secrets, and generated verification codes are stored and processed locally in Firefox.
TOTP shared secrets and generated verification codes are not uploaded to the TOTP Vault backend.
TOTP Vault uses Google Sign-In and Firebase for user authentication and session validation.
During authentication, information provided through Firebase Authentication, such as a Firebase user identifier and, where provided, an email address, may be processed.
The extension uses an application session for access control. Sessions expire periodically and require the user to authenticate again.
When a user explicitly requests QR-code scanning from the active tab, TOTP Vault temporarily accesses the visible tab for that purpose.
QR image data is processed locally and is not uploaded to the TOTP Vault backend.
TOTP Vault does not continuously monitor browsing activity or maintain a browsing-history database.
TOTP Vault writes a generated verification code to the clipboard only when the user explicitly requests it. The extension does not require clipboard read access for this feature.
The free version may display direct sponsor or affiliate promotions inside the extension interface.
Sponsor and affiliate campaign information may be retrieved from the TOTP Vault backend. If a user follows an affiliate link, TOTP Vault may receive a commission from the relevant provider.
Sponsor and affiliate functionality does not require access to TOTP shared secrets or generated verification codes.
TOTP Vault does not intentionally collect health information, financial information, personal communications, general browsing history, TOTP shared secrets, or generated verification codes on its backend.