Privacy Policy — Cytracon Authenticator
What the extension does
Cytracon Authenticator generates TOTP two-factor codes locally. Account secrets stay in Chrome storage on your device. Backup sync writes an encrypted vault file into your Google Drive plugin folder through a local native host.
Data collected
- TOTP account metadata and secrets that you import or enter
- Exact hosts you assign to accounts
- Current tab host, used only to suggest the matching account
Storage and sharing
- Accounts are stored in Chrome extension storage.
- Sync writes encrypted
cytracon-authenticator.jsonvia native hostcom.cytracon.plugin_sync. - The vault passphrase never leaves the browser session.
- No Cytracon server receives secrets. Data is not sold.
Permissions
storage— local accounts and settingsactiveTab/tabs— exact host matchingscripting— autofill a codeclipboardWrite— copy a codenativeMessaging— encrypted Drive-folder backupalarms— periodic backup while the vault is unlocked
Remote code
The extension does not load remote code. All scripts ship inside the extension package.
Your choices
You can use the extension locally, export a backup, or uninstall it to remove local extension data from Chrome. Synced JSON files live in your own Google Drive folder and can be deleted there.
Changes
If this policy changes, this page will be updated and the effective date will change.