Privacy policy
Last updated 2026-07-29. Plain-English summary first, full text below.
Plain-English summary
- We collect: the email address you sign up with, your Argon2id password hash, your TOTP secret (encrypted), your 2FA recovery codes (Argon2id hashed), the organizations you create or join, and the TOTP sites you store.
- We do not collect: your name, phone number, address, payment information, or any third-party account credentials beyond the encrypted TOTP secret you choose to store.
- Outbound email we send (all transactional, never marketing):
- Signup verification — one magic link at signup, valid 24 hours.
- Password-reset link — when you request one. Single-use, expires in 1 hour.
- Password-changed heads-up — to you, immediately after a successful reset, as a defense-in-depth signal that someone rotated your password.
- Invite-redeemed notice — to organization admins when their invitee signs up, unless Opt-out is chosen in their profile.
- Invite-expired notice — to organization admins when their invitee fails to sign up, unless Opt-out is chosen in their profile.
- Security breach notification — to affected users in the event of a security incident affecting unencrypted personal information. Rare, conditional; see the Security & breach notification section below for the legal basis and timing.
- Advertising: third-party ad networks (currently Google AdSense) may set cookies when you visit a public page. Authenticated pages serve no ads.
- We do not sell your data.
- Deletion: contact admin@crew2fa.com from the address on your account; we delete your account within 7 days.
What we store
| Category | Specific data | Storage |
|---|---|---|
| Account | email address, password hash | Argon2id hash; email in plaintext for login lookups. |
| Two-factor | TOTP secret, recovery codes | Secret encrypted with Fernet (AES-128 + HMAC). Recovery codes stored as Argon2id hashes. |
| Organizations | name, slug, your role per org | Plaintext. |
| TOTP sites you store | label, issuer, base32 secret | Secret encrypted with Fernet per organization. |
| Audit log | action, timestamp, actor, target org | Plaintext. Retained for the life of the account. |
| Session cookies | Flask session | HttpOnly, SameSite=Lax, Secure (HTTPS only). |
Advertising
Public pages (/, /about/*, /login, /signup) display ads from
Google AdSense. AdSense uses cookies and may use your IP address, user-agent, and
referrer to serve relevant ads and to measure ad performance. AdSense's own privacy policy applies
to that data: https://policies.google.com/privacy.
You can opt out of personalised advertising at
https://www.google.com/settings/ads.
Authenticated pages serve no advertising. When you are signed in, no ad scripts run, no third-party cookies are set by the ad network, and no advertising pixels load.
Cookies
- Session cookie — required for sign-in. HttpOnly, SameSite=Lax, Secure (HTTPS).
- CSRF cookie — required to submit forms.
- AdSense cookies — set by Google on public pages only. See Google's cookie policy.
- Cloudflare cookies —
__cf_bmis set by Cloudflare's bot-management on public pages and expires after 30 minutes of inactivity.
Data retention
Account data is retained for the life of the account plus 30 days of grace, after which all associations (memberships, invites, sites, audit log entries, recovery codes) are hard-deleted. Backups are retained for 7 days rolling and then rotated out.
Your rights
- Export: there is no self-serve export yet. Email admin@crew2fa.com and we will provide a JSON dump of your account within 30 days.
- Deletion: email admin@crew2fa.com from the address on your account. We will reply within 7 days and complete deletion within 30 days.
- Correction: you can change your password and regenerate your recovery codes from the Profile page at any time.
Sub-processors
- Google AdSense — advertising on public pages only.
- Cloudflare — reverse proxy, TLS termination, bot management.
- Google Workspace — inbound mail delivery for
@crew2fa.com. No application data is ever sent to Google; only inbound messages you send to one of the operator mailboxes (admin@,abuse@,postmaster@,bug_report@,security@) are delivered there. - Hetzner Online GmbH — hosting (Falkenstein, Germany).
California residents
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to consumers who reside in California. We do not meet the statutory thresholds (annual revenue, volume of California consumer data, or revenue from sale/sharing) that would require mandatory compliance, but we voluntarily extend the following rights to all California residents and honor them regardless of jurisdiction:
- Right to know what personal information we have collected about you, the categories of sources, and the business or commercial purposes — admin@crew2fa.com.
- Right to delete personal information we have collected from you, subject to the exceptions in Cal. Civ. Code § 1798.105(d) — admin@crew2fa.com.
- Right to opt out of sale or sharing. We do not sell or share your personal information. To exercise this right anyway, see the Do Not Sell or Share My Personal Information page.
- Right to limit use of sensitive personal information. We do not collect sensitive personal information as defined in Cal. Civ. Code § 1798.140(ae) (no SSN, financial account credentials, precise geolocation, racial or ethnic data, etc.).
- Right to non-discrimination. We will not deny service, charge a different price, or provide a different level of quality to anyone who exercises these rights.
To exercise any of these rights, email admin@crew2fa.com from the address on your account. We will acknowledge within 10 business days and respond substantively within 45 calendar days as required by Cal. Civ. Code § 1798.130(a)(2).
EU / EEA residents (GDPR)
The EU General Data Protection Regulation (Regulation (EU) 2016/679) applies to data subjects in the European Economic Area, the United Kingdom, and Switzerland. The Service is operated by the data controller identified in the Contact section below, with the sub-processors listed above (Hetzner Online GmbH for hosting, Google Workspace for inbound mail delivery to operator mailboxes). We process your personal data on the legal basis of contract performance (Art. 6(1)(b)) for the authentication service you signed up for, and legitimate interest (Art. 6(1)(f)) for security monitoring and abuse prevention.
You have the following rights under the GDPR, exercisable by emailing admin@crew2fa.com:
- Right of access (Art. 15) — request a copy of your personal data.
- Right to rectification (Art. 16) — correct inaccurate data.
- Right to erasure / "right to be forgotten" (Art. 17) — request deletion, subject to the exceptions in Art. 17(3).
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — receive your data in a machine-readable format.
- Right to object (Art. 21) — to processing based on legitimate interest.
- Right to lodge a complaint with a supervisory authority (Art. 77) — in particular, the supervisory authority of your habitual residence, place of work, or place of the alleged infringement. A list is available at edpb.europa.eu.
International data transfers: your data is processed on servers in Falkenstein, Germany (Hetzner) but accessed from the operator in California, USA. The European Commission has not adopted an adequacy decision for the United States; transfers are therefore made on the basis of the operator's legitimate interest (Art. 6(1)(f)) and the contractual safeguards in Hetzner's standard data-processing agreement.
Children
The Service is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. If you believe we have collected information from a child under 13, email admin@crew2fa.com and we will delete the account within 7 days.
Security & breach notification
In the event of a security incident affecting your unencrypted personal information, we will notify affected users by email and post a notice on the landing page within the timeframes required by applicable law (Cal. Civ. Code § 1798.82 for California residents; analogous state laws elsewhere).
Contact
Email admin@crew2fa.com for any privacy request. We will reply within 7 days.