2FA4G Privacy Policy

Effective Date: July 12, 2026

2FA4G ("we", "our", or "us") is a utility for importing OTP tokens on a phone and syncing supported tokens to a Garmin watch. This Privacy Policy explains what data is stored, how it is used, and which third-party services are involved.

1. Data Stored by the App

OTP data

  • token labels
  • issuer names
  • token secrets
  • token type and algorithm metadata
  • local sync state and HOTP counter state

This information is stored locally on your device. When you choose to sync to Garmin, supported tokens are also stored locally on the watch.

Purchase state

For overseas builds, Pro purchase validation is handled through RevenueCat together with the App Store or Google Play billing systems. The mainland China Android build uses Alipay authorization and payment, while the 2FA4G backend processes the account identifier, order number, product, amount, payment status, and entitlement status. We do not receive your full bank-card details or Alipay payment password.

Device and operational data

We may process limited operational data needed to make Garmin sync and entitlement checks work, such as device identifiers returned by Garmin Connect Mobile, entitlement status, and basic error information.

Camera access

If you choose to scan an OTP QR code, 2FA4G requests camera access on your device. Camera access is used only to scan QR codes for token import. We do not use the camera for advertising, profiling, or unrelated background collection as part of the normal product flow.

2. How We Use Data

We use data only to:

  • provide OTP import, storage, and Garmin sync
  • preserve local token state and HOTP counters
  • verify Pro entitlement status
  • diagnose reliability issues such as sync failures

3. Data Sharing

We do not sell OTP vault data.

We may rely on these third parties for limited product functions:

  • Garmin Connect Mobile for phone-to-watch communication
  • RevenueCat for overseas entitlement management
  • Apple App Store and Google Play for overseas billing and app distribution
  • Alipay for account authorization and payment processing in the mainland China Android build
  • The 2FA4G payment and entitlement backend for mainland China login state, orders, and entitlement validation

These providers may process identifiers or billing-related metadata required for their services.

4. No Required Cloud Account

OTP import, storage, and Garmin sync are local-first and do not require you to create a separate username and password. In the mainland China Android build, when you choose to sign in, buy, or restore access, an Alipay authorization identifier is used to associate the backend account with its entitlement.

5. Your Choices

You can:

  • delete tokens from inside the app
  • stop syncing tokens to the watch
  • uninstall the app to remove locally stored data from the phone
  • manage subscriptions through your App Store or Google Play account settings
  • email [email protected] to request deletion of the mainland China backend account data

If you remove the app from the watch, locally stored watch data may also be removed depending on Garmin platform behavior and your own actions.

6. Retention and deletion

OTP data remains stored locally until you delete the token, remove the app, or clear local app data. Watch-side token data remains until you remove it through sync changes, uninstall the watch app, or Garmin removes local storage as part of device behavior. Operational and entitlement data is retained only as long as needed for the related feature or troubleshooting purpose.

7. Security Notes

2FA4G is designed to keep token data local, but you remain responsible for:

  • securing your phone and watch
  • protecting access to your store account
  • verifying imported token details before use

8. Children's Privacy

2FA4G is not designed specifically for children and does not knowingly collect personal data from children as a first-party service.

9. Changes

We may update this Privacy Policy from time to time. The latest version published at this URL is the current policy.

10. Contact

For privacy questions, contact [email protected].