Zero Data Collection & Zero Tracking
KeySync is fundamentally architected as an offline-first, client-side browser extension. We do not collect, transmit, store, sell, monetize, or share any personal data, usage telemetry, analytics, IP addresses, browsing histories, or 2FA credentials.
There are no user profiles, account registration systems, passwords, or cloud backends associated with KeySync. You use the software anonymously, and all actions remain restricted strictly to your local computer.
Client-Side Local Encryption Architecture
Your sensitive authenticator seeds and account configurations are protected using industry-standard cryptography via the browser's native WebCrypto API:
-
Local Sandboxed Storage: All Time-Based One-Time Password (TOTP) secret keys, account
identifiers, and service names are stored strictly on your local computer inside your browser's isolated
sandboxed storage (
chrome.storage.local). - AES-256-GCM Cipher: Your vault payload is encrypted using the authenticated AES-256-GCM cipher with a distinct 12-byte cryptographically secure pseudorandom number generator (CSPRNG) initialization vector (IV) generated for each write operation.
- PBKDF2 Key Derivation: Encryption keys are derived locally from your 4-digit Master PIN using PBKDF2 with SHA-256 and 100,000 iterations, combined with a 16-byte random salt generated on your device.
- Zero-Knowledge Principle: Neither the developers of KeySync nor any third party have access to your Master PIN or unencrypted secret keys. We possess no backdoor, bypass mechanism, or recovery key.
In-Memory Session Persistence
KeySync features an optional in-memory session persistence system utilizing
chrome.storage.session:
The derived encryption key is kept strictly in volatile RAM for a configurable duration (default 15 minutes) so that you do not need to re-enter your PIN every time the popup closes during an active work session.
This session key is never written to disk or non-volatile storage and is immediately discarded when the timer expires, when you manually click the Lock button, or when the browser closes.
Network Communications & Favicon Fetching
KeySync operates 100% offline with one single, optional network interaction:
-
When you add an account with a custom domain or unrecognized brand name, KeySync optionally retrieves a
public favicon icon from Google's public favicon service
(
https://t1.gstatic.com/faviconV2). -
No credentials, secret seeds, account usernames, or user tokens are ever sent with
these icon requests. Only the domain host string (e.g.,
github.com) is queried. - Retrieved favicon image data URLs are cached locally within your browser's private local storage to eliminate redundant future network requests.
Third-Party Services & No Analytics
KeySync does not integrate any commercial third-party analytics libraries (such as Google Analytics, Mixpanel, Amplitude, or Sentry), crash reporters, advertisement trackers, or remote synchronizers.
The extension communicates with zero advertising or marketing servers under any circumstances.
Data Retention, Portability & Deletion
You maintain complete sovereignty and ownership over your data at all times:
- Full Backup Export: You can export an unencrypted or encrypted JSON backup of your vault directly from the Settings menu whenever you want. You are never vendor locked-in.
- Account Deletion: You can delete individual accounts at any time. Deleted accounts are immediately purged from the active encrypted payload.
- Factory Reset: You can execute a complete factory reset from the Settings menu. This immediately purges all stored credentials, salt, verification hash, and session keys from your device.
- Extension Uninstall: If you uninstall KeySync from Chrome, Chrome immediately and permanently removes all sandboxed extension storage associated with KeySync.
Chrome Extension Permissions Transparency
In accordance with Google Chrome Web Store Single-Purpose guidelines, KeySync requests only the absolute minimum set of browser permissions:
| Permission | Exact Purpose |
|---|---|
storage |
Saves your encrypted TOTP accounts locally via chrome.storage.local and keeps
session unlock state in RAM via chrome.storage.session. |
alarms |
Powers the configurable auto-lock timer to lock your vault after inactivity. |
clipboardWrite |
Allows 1-click copying of 6-digit TOTP codes directly to your clipboard when you click a code card. |
Contact & Developer Attribution
KeySync was developed by Ali Sufian (@aliscodes).
If you have any questions, feedback, or security inquiries regarding this Privacy Policy or KeySync's cryptographic architecture, please contact the developer via X or open an issue in the public GitHub repository: