How 2FA secrets are processed
When you generate a code, the browser sends the secret in a POST request to this website’s server. The server calculates and returns the code. While the page remains open, later periods trigger additional requests to refresh it.
The application does not write secrets to localStorage, sessionStorage, or server files. Secrets and codes remain in the current page’s memory and are cleared when it is reloaded or closed.
Facebook IDs and inbox data
Account checks send entered user IDs to this server, which queries Facebook’s public picture endpoint. The request does not require a Facebook password or cookies.
Inbox form data is submitted to this server, which uses the configured Mail.td interface to access messages. Addresses, message lists, and content are displayed in the current page. The application does not intentionally persist these forms or messages in browser storage or server files.
Analytics, external resources, and logs
This website includes Google Analytics for visit statistics and Google Fonts for fonts. These third parties may process IP addresses, browser details, page addresses, and cookies according to their policies and your browser settings.
The application does not intentionally log secrets or message content. Hosting, reverse proxies, and upstream providers may produce access or operational logs according to their configurations. Do not put secrets or passwords in URLs, query parameters, or shared links.
Signing out and clearing page state
Close or reload the page to clear the current tool inputs and results. Signing out of the inbox clears its displayed state without deleting messages stored by the provider. Browser privacy settings can manage third-party cookies and website data.