← Close

Security & Data Protection Policy

Effective and last updated: July 14, 2026

This Policy explains the security model, responsibilities, and limitations of 2FA Pro. It is not a promise that the service is immune from every attack or incident.

Core principle: OTP/TOTP vault data is encrypted on your device before synchronization. You are solely responsible for controlling your Master Password and recovery codes.

1. Protection scope

2. Data not end-to-end encrypted

Email addresses, user identifiers, subscription status, payment and reconciliation data, device identifiers, activity times, logs, and some metadata must remain processable by the system or infrastructure providers. The entire service should not be considered “zero knowledge.”

3. Master Password and recovery

The Master Password is not stored in plaintext. Recovery codes should be stored securely offline. If the Master Password and recovery codes are lost, or encrypted data is damaged, the vault may be unrecoverable. Support will never ask you to send OTP secrets, OTP codes, your Master Password, or recovery codes.

4. Mandatory user responsibilities

5. Risks that cannot be eliminated

Encryption does not protect data displayed on a compromised device. The service may be affected by malware, phishing, XSS, malicious extensions, browser defects, clock drift, connectivity problems, third-party outages or changes, and force-majeure events.

6. Incident response

We may revoke sessions, restrict access, suspend features, or request verification when risk is detected. Incidents will be assessed, contained, remediated, and notified according to severity and applicable law. Users must maintain alternative access methods for critical accounts.

7. Vulnerability reports

Send a description, reproduction steps, and impact to support@sync2fa.com. Do not access other users' data, cause damage, or disclose a vulnerability before allowing a reasonable remediation period. Reporting does not automatically create a reward obligation.

8. Disclaimer and limitation of liability

The service is provided “as is” and “as available.” To the maximum extent permitted by law, we do not guarantee uninterrupted, error-free operation, universal compatibility, or prevention of every incident; and we are not liable for losses caused by user actions, lost recovery information, compromised devices, third parties, events beyond reasonable control, or indirect/consequential damages. These exclusions do not apply where liability cannot legally be excluded.

See also the Privacy Policy and Terms of Use, Payment and Refund Policy.