Privacy Policy
This policy explains what information CodeGate processes when you use the tool, buy advertising, or sign in to an advertiser account, and the choices you have.
Last updated: 21 September 2026
Who we are
CodeGate is an independent web-based TOTP authentication-code utility. It is run by the site operator whose details appear on the Contact Us page. In this policy, "we" and "us" mean the operator of this website.
Using the TOTP tool
The box on the home page accepts two kinds of input. What happens to your information depends on which one you use.
Your own TOTP secret key or otpauth link
If you paste a secret key or an otpauth:// link, the code is calculated inside your browser. The key is not sent to our server, is not saved by our software, and is not written to any log by our software. It stays in the page only until you clear the box, leave the page, or reload it. The only thing our server receives is an anonymous counter update saying that a code was generated: it contains no key, no code and no identifier, and we keep it only as a daily total.
An email address for an account set up for you
If you enter an email address, it is sent to our server so that it can find the account the site operator has set up for that address. The server applies request limits and, if the address matches an active account, calculates the current code from a secret stored for that account in encrypted form, and returns the code to you. When a code is returned, we record that a code was requested for that account together with the IP address of the request. These records are deleted automatically after about 30 days. If the address does not match an account, the only thing kept is a request-limit counter, deleted automatically after about 24 hours.
Accounts stored on our server
For accounts set up by the operator, the server stores a name or label, an email address, the issuer, the code settings (algorithm, digits, period), the status, and the TOTP secret. The secret is encrypted with AES-256-GCM. Administrators can reveal a secret only after entering their own password again, and each reveal is recorded in the audit log.
Messages sent through the Contact Us form
If you send a message through the Contact Us form, we save the name, email address, optional phone number and message you type, the time it was sent, and the first part of your network address (the last part is hidden) to help us deal with abuse. Only administrators of this website can read it. We use it to answer you and to keep a record of the conversation. The form uses no cookies: it is protected by a signed time value in the page, a hidden field that people never see, and limits on how many messages one address can send. You can ask us to delete your message at any time (see "Your choices").
Technical and security records
- Web server logs. Like any website, our web server and hosting provider receive your IP address, the time, the page requested and your browser type. Their retention is governed by the hosting provider's settings.
- Request limits. To prevent abuse, we count requests per IP address or email address. The counters use a one-way hash (SHA-256) instead of the plain value and are deleted after about 24 hours.
- Audit log. Sign-ins and important actions in the administration panel and in advertiser accounts (for example password changes, payments confirmed, or an administrator opening an advertiser dashboard) are recorded with the time, the IP address and the browser type. These records are kept for as long as they are needed for security and accountability.
- Service counters. We keep anonymous daily totals, such as how many codes were generated from a personal key. They contain no personal information.
Advertising and analytics
This website shows banner advertisements that we sell directly to advertisers. They are labelled "Advertisement" and are separate from the tool. When an advertisement is shown or clicked, we count it.
- What is counted. Daily totals of views and clicks, and daily breakdowns by device type (desktop, mobile, tablet), operating system, browser, country (only if the hosting or network provider passes a country code to the site), traffic source, and any UTM tags in the address you arrived from.
- Unique visitors. To count a visitor once per day, we calculate a short one-way code from your IP address, browser type and the date, using a secret key that only the server knows. It cannot be reversed and it changes every day, so a person cannot be recognised from one day to the next. These codes are deleted after three days. We do not store your IP address for this purpose.
- Who sees it. Advertisers see only the totals and breakdowns for their own advertisements, never information about individual visitors.
- Clicks. Clicking an advertisement takes you to the advertiser's website, which has its own privacy policy.
Google AdSense and other third-party advertising
At the time of writing, advertisements on this site are placed through our own system. If we enable a third-party advertising service such as Google AdSense, that service may use cookies or similar technologies to show and measure advertisements, including advertisements based on your visits to this or other websites. Google's use of advertising cookies is described at policies.google.com/technologies/ads, and you can manage personalised advertising at adssettings.google.com. We will update this policy before enabling such a service.
Advertisers, orders and payments
- Orders. When you order advertising we collect the brand or business name, a contact email address, the website address, the banner image and the package you choose.
- Advertiser accounts. After a payment is confirmed, an account is created for the email address on the order. It may also hold your name, company, phone number, address, website, timezone, profile picture and notification choices if you add them. The password is stored only as a hash, and the first temporary password is sent to you by email.
- Sign-in records. We record sign-ins with the time, browser type, the first part of the network address (the last part is hidden), and the country when the host provides it, so that you can review activity and we can warn you about new devices.
- Payments. Payments are made in cryptocurrency through Binance or by a manual method. We record the order, the amount, the currency, the time, the payment method and the transaction reference. To confirm a Binance payment, the server reads the transaction history of our own Binance account through Binance's API. We do not receive your Binance login or API keys, and we do not collect card details.
- Invoices, support and notifications. We keep invoices for your paid orders, the messages and attachments in support tickets, change requests for your banners, and notifications shown in your dashboard.
We send email, such as login details, payment receipts, expiry reminders and replies to support tickets, through an email (SMTP) service chosen by the site operator. We keep a log of each message with the recipient, the subject, the type and whether sending succeeded. You can switch off non-essential advertising notification emails in your advertiser profile. Security, password and payment emails are always sent.
Cookies and browser storage
- Home page. Our software sets no cookies on the home page. Your light, dark or system theme choice is saved in your browser's local storage on your device; it is not sent to us.
- Order pages, advertiser dashboard and administration. A session cookie is used to keep you signed in and to protect forms against forgery. If you choose "Remember me" on the advertiser sign-in page, an additional cookie keeps you signed in for up to 30 days. These cookies are needed for those pages to work.
- Analytics. If the site operator switches on Google Analytics, it is loaded only on the home page and the advertising pages, never in the dashboards or administration panel, and not when your browser sends a Do Not Track signal. Google Analytics sets cookies of its own.
- Advertising cookies. See "Google AdSense and other third-party advertising" above.
You can delete or block cookies and local storage in your browser settings. The tool on the home page works without cookies.
Third-party services
- Hosting provider for the website and its database.
- Binance, for payment confirmation, as described above.
- Email (SMTP) provider, to deliver messages.
- Google Analytics and Google AdSense, only if the site operator enables them.
The home page does not load fonts, scripts or widgets from other websites by default.
How we use information
We use information to provide the tool, to protect it against abuse, to fulfil advertising orders, to send the messages described above, to answer questions and support requests, to keep records that the law may require, and to keep the service running. We do not sell personal information.
Retention
| Information | How long |
|---|---|
| Your own secret key (pasted in the box) | Not stored. It exists only in your browser page. |
| Records that a code was requested for a stored account (account and IP address) | About 30 days |
| Request-limit counters | About 24 hours |
| Daily visitor codes for advertisement counting | 3 days (live-visitor entries: 2 hours) |
| Advertisement totals and daily breakdowns | Totals are kept with the advertisement; daily breakdowns for about 13 months |
| Stored accounts (email, encrypted secret, settings) | Until the operator removes or changes the account |
| Audit log, sign-in history, orders, payments and invoices | Kept for as long as needed for security, accounting and legal reasons |
| Messages sent through the Contact Us form | Kept while needed to answer you and for our records; deleted on request |
| Advertiser account and support tickets | While the account exists, or until deleted on request |
Security
Stored TOTP secrets are encrypted with AES-256-GCM. Passwords are stored as hashes. Pages are served over HTTPS when the site is configured for it. Requests are limited to slow down abuse, and access to the administration panel is restricted to signed-in administrators with the right permissions. No method of storage or transmission is completely secure, so we cannot guarantee absolute security. Please keep your own secret keys private.
Sharing
We share information with the service providers listed above only as needed to run the website, with advertisers only as the totals for their own advertisements, and with authorities where the law requires it or where it is necessary to prevent fraud, abuse or harm.
Your choices
- Use the tool with your own secret key if you do not want anything sent to our server: the code is calculated in your browser.
- Block or delete cookies and local storage in your browser.
- Update your details or notification choices in your advertiser profile.
- Ask us to tell you what information we hold about you, to correct it, or to delete it (including a message you sent through the contact form, a stored account that uses your email address, or an advertiser account). We will respond as required by the law that applies to you. Use the Contact Us page.
Children
CodeGate is not directed to children, and we do not knowingly collect personal information from them. If you believe a child has provided personal information, please contact us so that we can remove it.
Changes
We may update this policy when the service changes. The date at the top shows when it was last changed.
Contact
For questions or requests about privacy, see the Contact Us page.