Fuck2FA Privacy Policy

Last updated 7 September 2026.

Fuck2FA is operated by Philip S. Wright. This policy describes exactly what the app sends to its server, what the server keeps, and how to have it deleted. It covers no other product.

What the app collects

What it does not collect

No advertising identifier, no analytics or tracking SDK, no location, no contacts, no browsing history. Nothing is shared with data brokers or advertisers, and nothing is sold.

How credentials are stored

Site emails and passwords are encrypted with AES-GCM before they are written to the database, each with its own initialisation vector and authentication tag. The session token the app holds is kept in the iOS keychain, and the server stores only a hash of it. Your Fuck2FA account itself has no password — authentication is delegated to Apple.

Where it is stored

On a server operated by Philip S. Wright and reached over HTTPS. Data is not processed by any third party other than Apple, whose role is limited to verifying your identity when you use Sign in with Apple.

How long it is kept

Credentials are kept until you delete them. Device records and sign-in activity are kept while the account is open so that unfamiliar sign-ins can be spotted. Deleting the account removes all of it.

Your choices

Children

Fuck2FA is not directed to children under 13 and is not knowingly used to collect their information.

Changes

If this policy changes materially, the updated date above changes with it and the revision is published on this page before it takes effect.

Contact

Philip S. Wright — me@alwaysunder.me