Privacy Policy
How Team2FA handles account, authenticator and website data.
Effective 2026-09-26Who operates the service
Team2FA is a shared authenticator application operated by its service provider. For privacy requests, contact omri@educenter.co.il. An organization administrator controls member access and the shared entries in that organization.
Information we handle
We process account names, email addresses, password hashes, passkey credentials, optional phone numbers, membership, signup and invitation records, session identifiers, share link records, audit activity, authenticator labels and encrypted TOTP seeds. Administrators may provide account labels that contain personal data. We also process service logs needed for security and operation.
Why we use it
Account, session, invitation and authenticator data is used to provide the service and perform the agreement with users and organizations. Security logs and rate limits support protection of the service and legitimate operational interests. Optional analytics would require a separate choice and is not currently installed.
Providers and transfers
The application is hosted on Render, including its PostgreSQL database. If enabled by the administrator, SendGrid delivers account email and invitations and Twilio Verify handles SMS verification. Their processing locations and transfer mechanisms should be reviewed for the applicable deployment before EU customer data is onboarded. We do not sell personal data or use advertising trackers on this site.
Retention and security
Sessions expire after 12 hours. Unopened share links expire at the selected deadline; opened links allow code access for five minutes, and expired share records are purged after 30 days. Removed group assignments and globally archived entries are purged after 30 days. Organization audit views include recent activity, while underlying audit records and operational logs can have different retention. Exact account deletion and log retention procedures require operator review. Entries are encrypted in the application, but the server can decrypt them to issue codes. This is not end to end encryption.
Your choices and rights
You can request access, correction, deletion, restriction or a copy of your personal data where applicable, and object to processing in appropriate cases. Contact the service operator at the address above; for membership or shared account content, also contact your organization administrator. You may complain to your local supervisory authority. We may need to retain limited records where legally required or necessary for security.
Cookies and updates
We use essential sign in and short lived share viewer cookies, and remember a local cookie preference. See the Cookie Policy. Material changes to this notice will be published here with a revised date.