Fuck2FA Privacy Policy
Last updated 7 September 2026.
Fuck2FA is operated by Philip S. Wright. This policy describes exactly what the app sends to its server, what the server keeps, and how to have it deleted. It covers no other product.
What the app collects
- Your email address, as released by Sign in with Apple, plus the opaque Apple user identifier. If you choose Apple's private relay address, that relay address is what the server sees.
- Site credentials you add: the domain, and the email and password for that site.
- Device details sent with each sign-in: a per-install identifier, the device name you have given the device, the app version and iOS version, and the IP address the request arrives from.
- Sign-in activity: which domain was filled, when, and whether it succeeded.
What it does not collect
No advertising identifier, no analytics or tracking SDK, no location, no contacts, no browsing history. Nothing is shared with data brokers or advertisers, and nothing is sold.
How credentials are stored
Site emails and passwords are encrypted with AES-GCM before they are written to the database, each with its own initialisation vector and authentication tag. The session token the app holds is kept in the iOS keychain, and the server stores only a hash of it. Your Fuck2FA account itself has no password — authentication is delegated to Apple.
Where it is stored
On a server operated by Philip S. Wright and reached over HTTPS. Data is not processed by any third party other than Apple, whose role is limited to verifying your identity when you use Sign in with Apple.
How long it is kept
Credentials are kept until you delete them. Device records and sign-in activity are kept while the account is open so that unfamiliar sign-ins can be spotted. Deleting the account removes all of it.
Your choices
- Delete any single credential from its detail screen in the app.
- Sign out from the Settings tab, which clears the token from the device.
- Request a copy of everything held for your account, or its deletion, by email. Requests are answered within thirty days.
Children
Fuck2FA is not directed to children under 13 and is not knowingly used to collect their information.
Changes
If this policy changes materially, the updated date above changes with it and the revision is published on this page before it takes effect.
Contact
Philip S. Wright — me@alwaysunder.me