Privacy Policy
Effective date: July 26, 2026 · Last updated: July 26, 2026
Who we are
FactorCat is a multi-factor authentication (MFA) platform that connects your browser, phone, and TOTP tokens into an approve-and-autofill flow. FactorCat is operated by FactorCat ("we," "us," "our").
Contact: Contact form
What we collect
Account data
- Email address — from your OAuth provider (Google, Apple, or Microsoft). Used as your account identifier.
- Name — as provided by your OAuth provider.
- OAuth provider link — which provider(s) you've used. We never receive your provider password.
Token metadata
- Site names, display names, domains, and URL patterns you provide when adding factors.
- Vault membership — which vault each factor belongs to and its encryption mode.
Encrypted secrets (Cloud Vault)
TOTP secrets encrypted with a server-managed key. FactorCat can decrypt these to generate codes on your behalf (web dashboard, phone-offline fallback).
Encrypted secrets (Locked Vault)
TOTP secrets encrypted with a key derived from your master key. FactorCat stores the encrypted blob but cannot decrypt it. Only your devices can.
Device data
- Push notification tokens (APNs, FCM) for delivering approval notifications.
- Device name as reported by your OS.
Usage data
- Approval log — timestamp, token ID, approve/deny. No TOTP codes logged.
- Analytics — screen views, sessions, and product interaction events collected by the analytics vendors we use (Firebase in the mobile app; Google Analytics on the marketing site with consent; PostHog for the web dashboard and extension). Product-analytics events use an opaque per-user identifier we generate — never your email or name. Where technically feasible, we proxy these events through our own backend before dispatching them to the vendor, keeping client IP addresses out of the vendor's view.
- Error reports — crash data via Sentry. PII disabled.
Cookies and tracking
- Marketing site: Google Analytics via GTM. Cookies load only after you consent via our cookie banner.
- Web dashboard: Essential cookies plus product-analytics events (see Analytics above). Events use an opaque per-user identifier — no email, no name. DNT is honored: when DNT is enabled, no product-analytics events are sent. You can also opt out at app.factorcat.com/privacy/opt-out or Settings → Privacy → Analytics; opt-out is stored per-user and applies across every device you sign in from.
- Mobile app: Firebase Analytics (no advertising identifiers).
- Browser extension: No cookies and no third-party tracking. Product-analytics events fire on specific actions (like your first successful autofill) and are sent through our own backend to the analytics vendor — the extension never connects to third-party analytics services directly.
What we do NOT collect
- Passwords. FactorCat is MFA-only.
- Browsing history. The extension detects MFA fields on the current page only.
- Plaintext TOTP secrets in Locked Vault mode.
- Data from children. FactorCat is not intended for users under 16.
How we use your data
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the service | Account data, token metadata, encrypted secrets, device tokens | Contract (Art. 6(1)(b)) |
| Push notifications | Device push tokens | Contract (Art. 6(1)(b)) |
| Web dashboard | Token metadata, encrypted secrets (Cloud Vault) | Contract (Art. 6(1)(b)) |
| Security audit trail | Approval log | Legitimate interest (Art. 6(1)(f)) |
| Improve the product | Marketing site analytics; app and extension product analytics; error reports | Marketing site analytics: consent (Art. 6(1)(a)). App/extension product analytics and error reports: legitimate interest (Art. 6(1)(f)), with a right to object via DNT and opt-out. |
| Prevent abuse | IP, rate limiting, Turnstile | Legitimate interest (Art. 6(1)(f)) |
We do not sell your data. We do not use it for advertising. We do not engage in automated decision-making or profiling.
International data transfers
FactorCat's infrastructure is hosted on Cloudflare's global network. Your data may be processed in countries outside your jurisdiction, including the United States. Where data is transferred outside the EEA, UK, or Canada, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and sub-processor agreements with appropriate safeguards.
Data retention
- Account data — until you delete your account
- Token metadata + encrypted secrets — until you delete them
- Approval log — 90 days
- Analytics — per provider defaults (14 months)
- Error reports — 90 days
- Payment records — as required by tax law (typically 7 years)
Account and data deletion
Delete your account at any time: Settings → Account → Delete Account in the mobile app, or use the web fallback. You may also contact us.
Deletion is permanent. All data is purged within 30 days. Emergency Kits stored offline by you are not affected.
Your rights
All users
- Access your personal data
- Correct inaccurate data
- Delete your account and data
- Export your data (via the API)
European Economic Area and United Kingdom (GDPR / UK GDPR)
- Restrict processing of your data
- Object to processing based on legitimate interest
- Data portability — receive your data in a machine-readable format
- Withdraw consent at any time (e.g., for marketing analytics), without affecting prior processing
- Lodge a complaint with your local data protection authority (EEA DPAs or the UK ICO)
California (CalOPPA)
- This privacy policy is conspicuously linked from our homepage and app
- We disclose what personal information we collect and with whom we share it
- We honor Do Not Track (DNT) signals on both the marketing site and the web dashboard — when DNT is enabled, third-party analytics do not load on the marketing site and we do not send product-analytics events from the web dashboard or extension
- We do not sell personal information
Canada (PIPEDA)
- Access your personal information held by FactorCat
- Challenge the accuracy and have it amended
- Withdraw consent for non-essential processing
- File a complaint with the Office of the Privacy Commissioner of Canada
Security
See our security model for technical details. In the event of a data breach affecting your personal data, we will notify affected users and relevant authorities within 72 hours as required by GDPR, or as otherwise required by applicable law.
Age restriction
FactorCat is not intended for users under 16. We do not knowingly collect data from children. If we learn we have, we will delete it promptly. Contact Contact us if you believe a child has provided data.
Changes to this policy
We update this policy as the platform evolves. How we notify you depends on the change:
- Material changes — including additions of sub-processors that receive personally identifiable data, new categories of data collected, or changes to how long we retain your data — are communicated via in-app notification and/or email at least 30 days before they take effect.
- Non-material updates — clarifications, additions of sub-processors that receive only anonymized or aggregated data the sub-processor can't use to identify you, sub-processor removals, minor wording changes — are reflected here without advance notice; the "Last updated" date at the top always reflects the most recent revision.
Contact
Privacy inquiries, data access requests, or complaints:
Contact form