← Close

Privacy Policy

Effective and last updated: July 14, 2026

This Policy describes how 2FA Pro ("we", "us") processes personal data when you use the website, browser extension, and related services at sync2fa.com.

Important: OTP/TOTP vault data is encrypted on the client before synchronization. Account, device, log, subscription, and transaction data must still be processed to operate the service.

1. Data we process

2. Purposes and legal bases

We process data to create and authenticate accounts; encrypt, store, and synchronize vaults; manage sessions; detect fraud; activate Pro plans; support users; maintain security and performance; and comply with applicable law. Processing is based on providing the service you request, consent where required, legitimate security interests, and applicable legal obligations.

3. Encryption and technical limitations

Vault secrets are protected using client-side cryptography. The Master Password is not transmitted in plaintext. Decrypted data temporarily exists in device memory while the vault is unlocked; malware, malicious extensions, XSS, a compromised device, or disclosure of the Master Password may expose it. We may be unable to recover a vault if both the Master Password and recovery code are lost.

4. Providers and disclosures

We may provide necessary data to processors supporting the service, including Google/Firebase, Cloudflare, SePay, banks/VietQR, CDNs, and integrated technical providers. Data may also be disclosed when required by law, to protect legal rights, or as part of a business reorganization.

We do not sell OTP/TOTP secrets or personal data for behavioral advertising.

5. Local storage, cookies, and transfers

The service uses cookies, IndexedDB, Local Storage, and Session Storage for authentication, session locking, preferences, and synchronization. Providers may process data on servers outside Vietnam; where applicable, we use reasonable safeguards and follow legal requirements for cross-border transfers.

6. Retention

Account and vault data is retained while the account remains active. After account deletion, active-system data is deleted or disabled where technically possible. Backups, anti-fraud logs, transactions, or records required by law may be retained for the necessary period and then deleted or anonymized.

7. Your rights and choices

Subject to applicable law, you may have rights to be informed, consent or withdraw consent, access, correct, restrict or object to processing, request deletion or data delivery, and complain. Withdrawal does not affect prior lawful processing and may prevent certain features from operating. We may verify identity before completing a request.

8. User responsibilities and children

You must protect your device, Master Password, and recovery codes; avoid sharing accounts; keep software updated; and only submit data you are entitled to process. The service is not intentionally directed to children who cannot independently consent under applicable law.

9. Incidents, changes, and contact

We use reasonable safeguards, but no system is completely secure. We will provide legally required incident notices when applicable. We may update this Policy and will give appropriate notice of material changes.

Privacy requests: support@sync2fa.com
Website: https://sync2fa.com/

See also the Security Policy and Terms of Use, Payment and Refund Policy.