← LukaOTP

LukaOTP Privacy Policy

Last updated: August 27, 2026

This is the complete privacy policy for the LukaOTP Chrome extension, the LukaOTP website, and the optional LukaOTP support forms. The product homepage provides a plain-language privacy summary, while this page remains the detailed reference for the current release.

LukaOTP processes TOTP data locally in Chrome. For data processed by the Extension, the developer does not receive or transmit user data. LukaOTP does not sell, share, or disclose locally processed information.

What the extension processes

Storage, retention, and deletion

Account names, possible email usernames, TOTP keys, and metadata are encrypted with AES-256-GCM and stored in Chrome’s local extension storage. The optional unlock session defaults to 15 minutes of inactivity and can be set to 1, 5, 15, or 30 minutes, or until the browser closes; real interaction renews it, while automatic TOTP refresh does not. Browser restart, extension reload/update/disable, timeout, and manual lock clear the session. The master password, decrypted values, QR screenshots, imported image bytes, and generated codes are used only in memory for the active operation or unlocked session and are not intentionally retained after processing, cancellation, locking, or closing.

LukaOTP provides a user-controlled encrypted offline backup and restore flow. Export creates an encrypted file protected by a separate backup password; you choose the download location. The developer does not receive or retain that file, and import is processed locally in the Extension. Back up before clearing local data or uninstalling the Extension: those actions delete the local vault. There is no developer-held copy, cloud synchronization, account system, or cloud recovery service, and LukaOTP cannot recover a forgotten master or backup password.

Network requests, sharing, and remote code

The LukaOTP Extension makes no external network requests and transmits no user data. The Extension does not use analytics, advertising, cloud storage, or third-party data-sharing services. All executable Extension logic is packaged with the Extension; remote code is not used.

Optional website analytics

The LukaOTP website uses Google Analytics 4 only after you explicitly select “Allow analytics.” Before consent, the website does not load the Google Analytics script or send analytics requests to Google. Declining analytics leaves the site fully usable. You can change or withdraw your choice at any time through “Analytics settings” in the page footer.

When allowed, Google Analytics processes basic website usage and technical information such as page views, approximate location derived from IP address, browser and device characteristics, and referral information. LukaOTP uses this information only to understand aggregate website use and improve public documentation. The site does not send TOTP secrets, QR images, one-time passwords, vault data, support-form contents, or other Extension data to Analytics. Advertising storage, ad user data, ad personalization, Google Signals, and enhanced measurement are disabled.

The consent choice is stored in your browser's localStorage. Google Analytics may set first-party _ga cookies after consent; withdrawing consent deletes those cookies where the browser permits and prevents Analytics from loading on the next page load. Event and user data in the dedicated LukaOTP Google Analytics property are retained for 2 months, and new activity does not reset that period. Google acts as the analytics service provider and may process data on Google systems. See Google's Privacy Policy for Google's practices.

Optional support and security forms

The support page links to two Google Forms that are separate from the Extension. Opening either form connects your browser to Google. Information you voluntarily submit is sent to and stored by Google for LukaOTP maintainers; this does not change the Extension's local-only network boundary.

Do not submit TOTP provisioning keys or QR codes, one-time passwords, master or backup passwords, recovery codes, session secrets, cookies, credentials, private personal data, or an unredacted backup. Submitted reports are used only to investigate, respond to, and prevent recurrence of support, security, or privacy issues. Access is limited to LukaOTP maintainers and Google's role as the form service provider. Reports are retained only while reasonably needed for those purposes or applicable legal obligations, then deleted. You may request deletion through the general support form using the same contact email so the report can be identified.

Chrome Web Store User Data Policy

LukaOTP follows the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide the stated user-facing features, not for advertising, creditworthiness, or unrelated purposes, and is not sold or transferred to third parties.

Permissions

storage saves the encrypted local vault. activeTab permits the one-time visible-tab capture only after you explicitly request QR scanning. alarms lets the MV3 service worker clear an inactive remembered-unlock session after all extension pages close; it reads only session metadata. The extension does not request persistent website access or browsing history.

Contact support · Return to LukaOTP ·