Privacy Policy
Last updated: August 20, 2026
This Privacy Policy describes how Better Authenticator (“we”, “us”, or “our”) collects, uses, stores, and shares information when you use our website at betterauthenticator.com, the Better Authenticator Chrome extension, our iOS app, and our related API (together, the “Services”).
If you do not agree with this policy, please do not use the Services. For questions, email [email protected].
1. Who we are
Better Authenticator is an authenticator product that stores your TOTP (time-based one-time password) accounts and can autofill 2FA codes in your browser. We operate the Services at betterauthenticator.com.
2. Information we collect
We collect only the information needed to provide and secure the Services:
- Account information. When you sign in, we receive your email address and a unique user ID from our authentication provider, Clerk. We store these so we can identify your account.
- Authenticator accounts. Labels, issuer names, and TOTP configuration (algorithm, digits, period) that you add. We also store the TOTP secret keys you provide so we can generate codes.
- Domain mappings. If you choose “Fill & Save Domain” in the Chrome extension, we store the website hostname you associated with an authenticator account so we can autofill that site later.
- Session information. Authentication cookies and session tokens are used to keep you signed in on the website and to sync that session to the Chrome extension.
- Technical logs. Our servers record request method, path, status code, timing, and whether a request was authenticated. We filter secrets, tokens, and email addresses out of application logs.
We do not collect your browsing history, page contents, passwords, or payment card details. We do not use advertising identifiers, analytics SDKs, or tracking pixels.
3. Chrome extension data use
The Chrome extension handles user data only to provide authenticator features. Specifically:
- It reads the hostname of the current tab so it can match a saved domain mapping and request the correct one-time code.
- It looks for one-time-code / OTP input fields on the page in order to autofill a 2FA code. It does not scrape, store, or transmit other page content.
- It uses the cookies permission only to sync your Better Authenticator sign-in session from betterauthenticator.com (via Clerk). It does not read cookies from unrelated websites for any other purpose.
- It uses storage to keep local session data needed to stay signed in.
- Host access to websites you visit is used solely to detect OTP fields and autofill codes on those sites. We do not sell this access or use it to build advertising profiles.
Chrome permission declarativeNetRequestWithHostAccess is used only to adjust
request headers on calls to Clerk’s authentication API so sign-in and sign-out work from
the extension. It is not used to intercept or modify other websites.
4. How we use information
We use the information above to:
- Create and maintain your account
- Store your authenticator accounts and generate TOTP codes
- Autofill codes on websites you have mapped, when you ask us to
- Authenticate you and protect the account (including Clerk’s failed-attempt protections)
- Respond to support requests you send us
- Operate, secure, and debug the Services
We do not sell your personal information. We do not use your data for advertising. We do not use it to train third-party AI models. We do not use the Chrome extension to collect data for an unrelated purpose.
5. How we share information
We share information only as needed to run the Services:
- Clerk, Inc. provides sign-in (email magic links / one-time codes and related session management). Clerk processes your email address and authentication events under Clerk’s Privacy Policy.
- Hosting and infrastructure providers store and serve the website, API, and encrypted database on our behalf.
- We may disclose information if required by law, legal process, or to protect the security of the Services or our users.
TOTP secret keys are not returned to the Chrome extension or website after you save them. The server generates the current code and sends only that short-lived code to your signed-in client.
6. Storage, security, and retention
- TOTP secrets are encrypted at rest using AES-256-GCM (Rails Active Record Encryption).
- Data is transmitted over HTTPS.
- On iOS, locally stored secrets and session material are kept in the system Keychain.
- We retain account and authenticator data until you delete the relevant items in the app or ask us to delete your account.
No method of transmission or storage is 100% secure. Please keep your sign-in credentials protected and only add authenticator accounts you intend to store with us.
7. Your choices
- You can add, rename, or delete authenticator accounts and saved domains in the website.
- You can sign out of the website and the Chrome extension at any time.
- To delete your entire Better Authenticator account and associated data, email [email protected] from the address on the account. We will delete the data we store for that account, except information we must keep for legal or security reasons.
- You may also request access to the personal information we hold about you at the same address.
Deleting the Chrome extension from your browser removes local extension data. It does not by itself delete the accounts stored on our servers.
8. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.
9. International users
We may process and store information in the United States or other countries where we or our processors operate. If those locations have different data-protection laws than your country, we still handle the information as described in this policy.
10. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. The current version will always be available at https://betterauthenticator.com/privacy.
11. Contact
For privacy questions, data-access requests, or deletion requests, contact:
Better Authenticator
Email: [email protected]
Support instructions are also available at betterauthenticator.com/support.