Chính sách này giải thích mô hình bảo mật, trách nhiệm và giới hạn của 2FA Pro. Đây không phải cam kết rằng dịch vụ miễn nhiễm với mọi cuộc tấn công hoặc sự cố.
Email, mã người dùng, trạng thái gói, dữ liệu thanh toán/đối soát, mã thiết bị, thời điểm hoạt động, nhật ký và một số siêu dữ liệu phải có thể được hệ thống hoặc nhà cung cấp hạ tầng xử lý. Không nên coi toàn bộ dữ liệu của dịch vụ là “zero knowledge”.
Master Password không được lưu dưới dạng rõ. Mã khôi phục chỉ nên lưu ngoại tuyến ở nơi an toàn. Nếu mất cả Master Password và mã khôi phục, hoặc dữ liệu mã hóa bị hỏng, kho có thể không thể phục hồi. Bộ phận hỗ trợ không được yêu cầu bạn gửi khóa bí mật, mã OTP, Master Password hoặc mã khôi phục.
Mã hóa không bảo vệ dữ liệu đang hiển thị trên thiết bị đã bị xâm nhập. Dịch vụ có thể bị ảnh hưởng bởi mã độc, phishing, XSS, tiện ích độc hại, lỗi trình duyệt, sai lệch đồng hồ, mất kết nối, lỗi hoặc gián đoạn của Firebase, Cloudflare, Google, SePay, ngân hàng, nhà mạng, CDN và các sự kiện bất khả kháng.
Chúng tôi có thể khóa phiên, giới hạn truy cập, tạm ngừng chức năng hoặc yêu cầu xác minh khi phát hiện nguy cơ. Sự cố sẽ được đánh giá, hạn chế, khắc phục và thông báo theo mức độ cũng như nghĩa vụ pháp luật áp dụng. Người dùng phải tự duy trì phương án truy cập dự phòng cho các tài khoản quan trọng.
Gửi mô tả, bước tái hiện và mức ảnh hưởng tới support@sync2fa.com. Không truy cập dữ liệu người khác, không phá hoại, không phát tán lỗ hổng trước khi có thời gian hợp lý để xử lý. Việc báo cáo không mặc nhiên tạo nghĩa vụ trả thưởng.
Dịch vụ được cung cấp trên cơ sở “hiện trạng” và “sẵn có”. Trong phạm vi tối đa pháp luật cho phép, chúng tôi không bảo đảm dịch vụ liên tục, không lỗi, tương thích với mọi thiết bị hoặc ngăn chặn được mọi sự cố; không chịu trách nhiệm cho tổn thất do hành vi của người dùng, mất thông tin khôi phục, thiết bị bị xâm nhập, bên thứ ba, sự kiện ngoài khả năng kiểm soát hợp lý hoặc thiệt hại gián tiếp/hệ quả. Các loại trừ này không áp dụng đối với trách nhiệm không thể loại trừ theo pháp luật.
Xem thêm Chính sách quyền riêng tư và Điều khoản sử dụng, thanh toán và hoàn tiền.
This Policy explains the security model, responsibilities, and limitations of 2FA Pro. It is not a promise that the service is immune from every attack or incident.
Email addresses, user identifiers, subscription status, payment and reconciliation data, device identifiers, activity times, logs, and some metadata must remain processable by the system or infrastructure providers. The entire service should not be considered “zero knowledge.”
The Master Password is not stored in plaintext. Recovery codes should be stored securely offline. If the Master Password and recovery codes are lost, or encrypted data is damaged, the vault may be unrecoverable. Support will never ask you to send OTP secrets, OTP codes, your Master Password, or recovery codes.
Encryption does not protect data displayed on a compromised device. The service may be affected by malware, phishing, XSS, malicious extensions, browser defects, clock drift, connectivity problems, third-party outages or changes, and force-majeure events.
We may revoke sessions, restrict access, suspend features, or request verification when risk is detected. Incidents will be assessed, contained, remediated, and notified according to severity and applicable law. Users must maintain alternative access methods for critical accounts.
Send a description, reproduction steps, and impact to support@sync2fa.com. Do not access other users' data, cause damage, or disclose a vulnerability before allowing a reasonable remediation period. Reporting does not automatically create a reward obligation.
The service is provided “as is” and “as available.” To the maximum extent permitted by law, we do not guarantee uninterrupted, error-free operation, universal compatibility, or prevention of every incident; and we are not liable for losses caused by user actions, lost recovery information, compromised devices, third parties, events beyond reasonable control, or indirect/consequential damages. These exclusions do not apply where liability cannot legally be excluded.
See also the Privacy Policy and Terms of Use, Payment and Refund Policy.