Privacy Policy

Effective October 10, 2026

The short version:

This policy explains what information the 2FA Live app for iPhone, iPad and Apple Watch (the "App") handles, where it goes and what choices you have. "We", "us" and "our" refer to the developer of 2FA Live. If you have questions, email fengzy1024@outlook.com.

1. Information you store in the App

You can store two-factor account secrets, passwords, passkeys, payment card details, secure notes, Wi-Fi network details and folders in the App. We call these "your vault items".

2. iCloud Sync (optional)

iCloud Sync is off until you turn it on. When it is on:

To delete synced data, turn off iCloud Sync in the App, then go to iOS Settings, tap your name, iCloud, Manage Account Storage, and delete the data for 2FA Live.

3. Encrypted backups

You can export a backup file. It is encrypted on your device with a key derived from a password you choose (PBKDF2 with SHA-256 and AES-256-GCM). You decide where the file goes, for example Files or AirDrop. We never receive your backup or its password, and we cannot open or recover it.

4. Password breach check

When you start a breach check, the App uses the Pwned Passwords service run by Have I Been Pwned. For each password, the App computes a SHA-1 hash on your device and sends only the first 5 characters of that hash. The service returns a list of matching hash endings, and the App compares them on your device. Your password and its full hash never leave your device. The request also asks the service to pad its responses so their size reveals nothing. Like any web request, it exposes your IP address to the service. See the Have I Been Pwned privacy policy.

Password health checks for weak, reused and old passwords run entirely on your device.

5. Subscriptions and purchases

Purchases are processed by Apple through your Apple ID. We do not receive your name, email address or payment details.

We use RevenueCat, Inc. to check whether you have an active subscription. To do this, the App sends RevenueCat:

We use this information only to unlock Premium features, restore purchases and understand subscription totals. See the RevenueCat privacy policy.

RevenueCat processes this information on our behalf under a data processing agreement and must protect it to the same standard as this policy. Apart from the breach check described in section 4, we do not share information with any other third party, except where the law requires it.

6. Device permissions

PermissionWhy the App asksWhat happens to the data
CameraTo scan QR codes when you add an accountFrames are read on your device and are not saved or sent anywhere
Photos (picker)To read a QR code from a screenshot you selectOnly the image you pick is read, on your device, and it is not saved
Face ID or Touch IDTo unlock the App and confirm AutoFillHandled by iOS. The App only learns whether the check succeeded

7. What we do not do

If you choose to share crash reports and analytics with app developers in iOS Settings, Apple may provide us with crash reports that do not identify you. We use them only to fix problems.

8. Support emails

If you email us, we receive your email address and whatever you include in your message. We use it only to reply and help you, and delete it when it is no longer needed. Please never send us your codes, passwords or backup passwords.

9. Retention and deletion

Your vault items stay on your device until you delete them or delete the App. Deleted items go to the trash for 30 days for Premium users, then are removed. Data in iCloud stays until you delete it as described in section 2. RevenueCat keeps purchase records for as long as needed to provide the service and meet legal obligations. To ask us to delete the RevenueCat records linked to your anonymous identifier, contact us.

10. Your rights

Depending on where you live, including the European Economic Area, the United Kingdom and California, you may have the right to access, correct, delete or move personal information, and to object to or limit its use. Because your vault items never reach us, you control them directly in the App. You can withdraw consent at any time: turn off iCloud Sync, stop using the breach check, or delete the App. For anything else, email fengzy1024@outlook.com and we will respond within 30 days. You may also complain to your local data protection authority.

11. Children

The App is not directed to children under 13, and we do not knowingly collect personal information from them.

12. Security

We protect your data with the iOS Keychain, on-device encryption, the Secure Enclave and optional app lock with Face ID, Touch ID or a PIN. No system is perfectly secure, so please keep your device passcode, Apple ID and backup password safe.

13. Changes to this policy

If we change this policy, we will update the effective date above. If a change affects how your information is handled in a significant way, we will tell you in the App before it takes effect.

14. Contact

Email fengzy1024@outlook.com.