Privacy Policy
Last updated: 12 August 2026
Purr is built to know as little about you as technically possible. No account, no email, no phone number, no sign-up. Your two-factor secrets are encrypted on your phone with a key only you hold. We never receive them and could not read them if we tried.
Who we are
Purr is a two-factor (TOTP) authenticator app, browser extension, and relay service. The data controller is:
PO Box 110, 8430 AC Oosterwolde, Netherlands
Email: luna@not-final.com
Phone: +31 85 369 6103
KVK (Netherlands Chamber of Commerce): 86022164
Website: purr2fa.app. Source code: github.com/LunaNiermann/Purr (open source, GPL-3.0).
What stays on your device
The following never leaves your phone in a form we can read:
- Your two-factor secrets and the codes generated from them.
- Your master password and the keys derived from it.
- Your 12-word recovery phrase.
These are encrypted on the device with a random data key, itself protected by your master password (Argon2id) and your recovery phrase. We hold no copy of any of these keys.
What the Purr relay processes
To let your browser receive a code from your phone, and to store an encrypted backup, our relay service (2fa.apps.not-final.com) processes:
- Encrypted pairing, approval, and backup data. When you pair a browser, ask for a code, or enable backup, the relay stores and forwards ciphertext only, end-to-end encrypted between your devices. This includes your encrypted vault backup and the encrypted name of a paired device (for example, "Your Android phone"). The relay cannot decrypt any of it.
- A push notification token. If you enable notifications, your device's Firebase Cloud Messaging (FCM) token is stored so the relay can wake your phone when your browser asks for a code. The wake message carries only routing identifiers (a request id and a pairing id), never a domain, account, or code.
- IP address and basic request metadata. Like any internet service, our servers briefly log the IP address, timestamp, and endpoint of incoming requests for security, abuse prevention, and debugging.
The relay is a dumb pipe. It enforces timing and delivery (approval requests expire after 60 seconds; an answer is deleted the moment it is delivered) but has no ability to read the protected content.
What we do not collect
- No name, email address, phone number, or postal address.
- No advertising identifiers, no analytics, no trackers, no ad networks.
- No location data.
- No contact lists, no browsing history, no page content.
Third parties and sub-processors
- Google Firebase Cloud Messaging (Google Ireland Ltd. / Google LLC) delivers push notifications. Google receives your FCM push token and the routing-only wake payload. See Google's privacy policy for how they process this. Push is optional; if you decline notifications, no FCM token is created or shared.
- Hetzner Online GmbH (Germany) provides the server infrastructure the relay runs on. The relay itself is operated by Not Final; Hetzner hosts the machine, so the encrypted data and server logs described above reside on their infrastructure in the EU.
We do not sell or rent personal data, and we do not share it except as needed to run these services or where required by law.
International transfers
Push notifications are delivered through Google's global infrastructure, which may process the FCM token outside the European Economic Area. Such transfers rely on the safeguards Google provides, for example Standard Contractual Clauses. All other processing takes place on our own relay.
Legal bases (GDPR)
- Providing the service you request (pairing a browser, relaying a code, storing your encrypted backup): performance of a service at your request and our legitimate interest in operating it (Art. 6(1)(b)/(f)).
- Push notifications: your consent, given when you turn them on and withdrawable at any time (Art. 6(1)(a)).
- Security logging: our legitimate interest in keeping the service safe and available (Art. 6(1)(f)).
Retention
| DATA | KEPT FOR |
|---|---|
| Approval requests | Deleted 60 seconds after creation, or immediately once answered |
| Pairings and push tokens | Until you unpair the browser or uninstall |
| Encrypted backup | Until you turn backup off or delete it, which you can do in the app at any time |
| Server logs | Briefly, for security and operations, then discarded after a maximum of 30 days. Does not include tokens or codes. |
How to delete your data
- Unpair a browser in the app to remove that pairing and its push token.
- Turn off Encrypted/Cloud backup in the app to delete your stored backup.
- Uninstall the app to remove everything held on your device.
- Or email luna@not-final.com and we will delete relay-side data associated with your pairing or backup identifiers.
Because the service is zero-knowledge, we identify your data only by opaque, device-generated identifiers. We have no name or email to look you up by.
Your rights
If you are in the EU/EEA, you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. Since we hold no account and no directly identifying data, some of these may be satisfied simply by the self-service deletion steps above. To exercise a right, contact luna@not-final.com.
You also have the right to lodge a complaint with your supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
Security
Secrets are encrypted on the device (XChaCha20-Poly1305 with an Argon2id-derived key wrap); data between your paired devices is end-to-end encrypted; the relay stores ciphertext only. Screens that reveal sensitive content are protected against screenshots on Android. No system is perfectly secure, but Purr is designed so that a breach of our relay exposes no readable secrets. To report a vulnerability, see our security policy or email luna@not-final.com.
Children
Purr is not directed at children and does not knowingly collect data from children under 16.
Changes to this policy
We may update this policy. Material changes will be posted at purr2fa.app with a new effective date.