Purr ← Back to purr2fa.app
PURR2FA.APP/PRIVACY

Privacy Policy

Last updated: 12 August 2026

Purr is built to know as little about you as technically possible. No account, no email, no phone number, no sign-up. Your two-factor secrets are encrypted on your phone with a key only you hold. We never receive them and could not read them if we tried.

Who we are

Purr is a two-factor (TOTP) authenticator app, browser extension, and relay service. The data controller is:

Not Final
PO Box 110, 8430 AC Oosterwolde, Netherlands
Email: luna@not-final.com
Phone: +31 85 369 6103
KVK (Netherlands Chamber of Commerce): 86022164

Website: purr2fa.app. Source code: github.com/LunaNiermann/Purr (open source, GPL-3.0).

What stays on your device

The following never leaves your phone in a form we can read:

These are encrypted on the device with a random data key, itself protected by your master password (Argon2id) and your recovery phrase. We hold no copy of any of these keys.

What the Purr relay processes

To let your browser receive a code from your phone, and to store an encrypted backup, our relay service (2fa.apps.not-final.com) processes:

The relay is a dumb pipe. It enforces timing and delivery (approval requests expire after 60 seconds; an answer is deleted the moment it is delivered) but has no ability to read the protected content.

What we do not collect

Third parties and sub-processors

We do not sell or rent personal data, and we do not share it except as needed to run these services or where required by law.

International transfers

Push notifications are delivered through Google's global infrastructure, which may process the FCM token outside the European Economic Area. Such transfers rely on the safeguards Google provides, for example Standard Contractual Clauses. All other processing takes place on our own relay.

Legal bases (GDPR)

Retention

DATA KEPT FOR
Approval requests Deleted 60 seconds after creation, or immediately once answered
Pairings and push tokens Until you unpair the browser or uninstall
Encrypted backup Until you turn backup off or delete it, which you can do in the app at any time
Server logs Briefly, for security and operations, then discarded after a maximum of 30 days. Does not include tokens or codes.

How to delete your data

Because the service is zero-knowledge, we identify your data only by opaque, device-generated identifiers. We have no name or email to look you up by.

Your rights

If you are in the EU/EEA, you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. Since we hold no account and no directly identifying data, some of these may be satisfied simply by the self-service deletion steps above. To exercise a right, contact luna@not-final.com.

You also have the right to lodge a complaint with your supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

Security

Secrets are encrypted on the device (XChaCha20-Poly1305 with an Argon2id-derived key wrap); data between your paired devices is end-to-end encrypted; the relay stores ciphertext only. Screens that reveal sensitive content are protected against screenshots on Android. No system is perfectly secure, but Purr is designed so that a breach of our relay exposes no readable secrets. To report a vulnerability, see our security policy or email luna@not-final.com.

Children

Purr is not directed at children and does not knowingly collect data from children under 16.

Changes to this policy

We may update this policy. Material changes will be posted at purr2fa.app with a new effective date.

Contact

Not Final
luna@not-final.com
PO Box 110, 8430 AC Oosterwolde, Netherlands