Zwei-Faktor-Authentifizierung. Sicher. Einfach. Privat.
Two-Factor Authentication. Secure. Simple. Private.
MFA-Safe ist der TOTP-Authenticator, der deine Konten zuverlässig und privat schützt. Deine Schlüssel bleiben verschlüsselt auf deinem Gerät – ohne Cloud-Zwang, ohne Tracking, ohne Werbung.
MFA-Safe is the TOTP authenticator that protects your accounts reliably and privately. Your keys stay encrypted on your device – no forced cloud, no tracking, no ads.
Was MFA-Safe bietet What MFA-Safe offers
Mobil & am Handgelenk Mobile & on your wrist
Codes überall verfügbar – direkt am Handgelenk oder per Home-Screen-Widget.
Codes available everywhere – on your wrist or via home screen widget.
Lokal & verschlüsselt Local & encrypted
Geheimnisse liegen sicher im System-Schlüsselbund deines Geräts. Kein Pflicht-Cloud-Konto.
Secrets stored safely in your device's system keychain. No mandatory cloud account.
QR-Code-Import QR code import
Konten in Sekunden hinzufügen – per QR-Scan oder manueller Eingabe.
Add accounts in seconds – via QR scan or manual entry.
Tags & Favoriten Tags & favorites
Konten flexibel organisieren – mit mehreren Tags pro Eintrag.
Organize accounts flexibly – with multiple tags per entry.
Face ID & Auto-Lock Face ID & auto-lock
Biometrische Entsperrung und automatisches Sperren nach Inaktivität.
Biometric unlock and automatic locking after inactivity.
Keine Werbung. Kein Tracking. No ads. No tracking.
Datensparsam by design – wir sehen deine Konten nie.
Privacy-first by design – we never see your accounts.
Impressum Imprint
Anbieter
HFB GmbH
Thüler Str. 3
49681 Garrel
Deutschland
Kontakt
E-Mail: info@hfb.one
Registereintrag
Registergericht: Amtsgericht Oldenburg
Registernummer: HRB 215254
Umsatzsteuer-ID
Umsatzsteuer-Identifikationsnummer gemäß § 27a UStG: DE329109581
Verantwortlich für den Inhalt nach § 18 Abs. 2 MStV
Geschäftsführung der HFB GmbH (Anschrift wie oben)
EU-Streitschlichtung
Die Europäische Kommission stellt eine Plattform zur Online-Streitbeilegung (OS) bereit: https://ec.europa.eu/consumers/odr/. Wir sind nicht verpflichtet und nicht bereit, an Streitbeilegungsverfahren vor einer Verbraucherschlichtungsstelle teilzunehmen.
Haftungsausschluss
Die Inhalte dieser Seite wurden mit größter Sorgfalt erstellt. Für die Richtigkeit, Vollständigkeit und Aktualität der Inhalte kann jedoch keine Gewähr übernommen werden. Für Inhalte externer Links sind ausschließlich deren Betreiber verantwortlich.
Urheberrecht
Die durch den Seitenbetreiber erstellten Inhalte und Werke auf dieser Website unterliegen dem deutschen Urheberrecht. Vervielfältigung, Bearbeitung, Verbreitung und jede Art der Verwertung außerhalb der Grenzen des Urheberrechtes bedürfen der schriftlichen Zustimmung des Autors.
Provider
HFB GmbH
Thüler Str. 3
49681 Garrel
Germany
Contact
Email: info@hfb.one
Commercial Register
District Court: Amtsgericht Oldenburg
Register Number: HRB 215254
VAT ID
VAT identification number according to § 27a German VAT Act: DE329109581
Responsible for content according to § 18 (2) MStV
Management of HFB GmbH (address as above)
EU Dispute Resolution
The European Commission provides a platform for online dispute resolution (ODR): https://ec.europa.eu/consumers/odr/. We are neither obliged nor willing to participate in dispute resolution proceedings before a consumer arbitration board.
Disclaimer
The contents of this page have been created with the utmost care. However, no guarantee can be given for the accuracy, completeness and topicality of the contents. The operators of linked external pages are solely responsible for their content.
Copyright
The content and works on this website created by the site operator are subject to German copyright law. Duplication, processing, distribution and any kind of use outside the limits of copyright require the written consent of the author.
Datenschutzerklärung Privacy Policy
1. Verantwortlicher
Verantwortlich für die Datenverarbeitung auf dieser Website und in der App ist die HFB GmbH, Thüler Str. 3, 49681 Garrel, Deutschland, E-Mail: info@hfb.one.
2. Daten in der App MFA-Safe
MFA-Safe ist eine datensparsame Anwendung. Sämtliche Konten, TOTP-Geheimnisse und Einstellungen werden ausschließlich lokal auf deinem Gerät gespeichert:
- TOTP-Geheimnisse werden in der iOS-Keychain abgelegt.
- Konten-Metadaten (z. B. Aussteller, Bezeichnung, Tags) liegen lokal im verschlüsselten App-Sandbox-Speicher.
- Bei optionaler Aktivierung von iCloud-Sync werden Daten Ende-zu-Ende-verschlüsselt über deinen privaten Apple-Account synchronisiert. Der Anbieter hat keinen Zugriff auf diese Daten.
Es findet keine Übertragung an Server des Anbieters statt. Es werden keine Analyse-, Tracking- oder Werbedienste eingesetzt.
3. Berechtigungen
- Kamera: Wird ausschließlich zum Scannen von QR-Codes zur Konteneinrichtung verwendet. Es werden keine Aufnahmen gespeichert.
- Face ID / Touch ID: Wird ausschließlich zum lokalen Entsperren der App verwendet. Biometrische Merkmale verlassen das Gerät nicht.
4. Daten auf dieser Website
Beim Aufruf dieser Website werden technisch notwendige Daten verarbeitet (IP-Adresse, Datum/Uhrzeit, aufgerufene Ressource, User-Agent) zur Auslieferung der Inhalte und Sicherstellung der Stabilität. Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse). Es werden keine Cookies gesetzt und kein Tracking betrieben.
5. Deine Rechte
Du hast jederzeit das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch gegen die Verarbeitung deiner Daten sowie das Recht auf Beschwerde bei einer Aufsichtsbehörde.
6. Kontakt
Anfragen zum Datenschutz bitte an: info@hfb.one
1. Data controller
Responsible for data processing on this website and in the app is HFB GmbH, Thüler Str. 3, 49681 Garrel, Germany, email: info@hfb.one.
2. Data in the MFA-Safe app
MFA-Safe is a privacy-minimal application. All accounts, TOTP secrets and settings are stored exclusively locally on your device:
- TOTP secrets are stored in the iOS Keychain.
- Account metadata (e.g. issuer, label, tags) is stored locally in the encrypted app sandbox.
- If you optionally enable iCloud sync, data is synchronized end-to-end encrypted via your private Apple account. The provider has no access to this data.
There is no transmission to servers operated by the provider. No analytics, tracking or advertising services are used.
3. Permissions
- Camera: Used exclusively to scan QR codes for account setup. No recordings are stored.
- Face ID / Touch ID: Used exclusively for local app unlock. Biometric features never leave your device.
4. Data on this website
When visiting this website, technically necessary data is processed (IP address, date/time, requested resource, user agent) in order to deliver the content and ensure stability. Legal basis is Art. 6 (1) lit. f GDPR (legitimate interest). No cookies are set and no tracking is performed.
5. Your rights
You have the right at any time to access, rectify, erase, restrict processing, data portability and object to the processing of your data, as well as the right to lodge a complaint with a supervisory authority.
6. Contact
Privacy-related requests please to: info@hfb.one
Allgemeine Geschäftsbedingungen (AGB) Terms and Conditions
§ 1 Geltungsbereich
Diese Allgemeinen Geschäftsbedingungen (AGB) gelten für die Nutzung der von der HFB GmbH, Thüler Str. 3, 49681 Garrel, Deutschland (nachfolgend „Anbieter") angebotenen Software „MFA-Safe" sowie der zugehörigen Website mfa-safe.hfb.one. Mit der Installation oder Nutzung der App erkennt der Nutzer diese AGB an.
§ 2 Leistungsbeschreibung
MFA-Safe ist eine Software zur Erzeugung zeitbasierter Einmalpasswörter (TOTP) gemäß RFC 6238 für die Zwei-Faktor-Authentifizierung. Die Bereitstellung erfolgt über den Apple App Store. Der Funktionsumfang ergibt sich aus der jeweiligen Produktbeschreibung im App Store.
§ 3 Vertragsschluss und Lizenz
Der Bezug der App erfolgt ausschließlich über den Apple App Store. Vertragspartner für den Download ist Apple. Der Anbieter gewährt dem Nutzer mit der Installation ein einfaches, nicht ausschließliches, nicht übertragbares Recht zur Nutzung der App im Rahmen der Apple-Nutzungsbedingungen.
§ 4 Preise und Zahlung
Die App wird zu den im App Store angegebenen Konditionen angeboten. Etwaige In-App-Käufe oder Abonnements werden über das Apple-Konto des Nutzers abgewickelt; es gelten die Bedingungen von Apple.
§ 5 Pflichten des Nutzers
Der Nutzer ist selbst für die Sicherung seiner Geräte, seiner Apple-ID, seiner Biometrie-Einstellungen und seiner TOTP-Geheimnisse verantwortlich. Der Nutzer hat sicherzustellen, dass er Sicherungskopien seiner TOTP-Konten anlegt, soweit dies für seine Nutzung erforderlich ist.
§ 6 Haftung
Der Anbieter haftet unbeschränkt für Vorsatz und grobe Fahrlässigkeit sowie nach dem Produkthaftungsgesetz. Bei leichter Fahrlässigkeit haftet der Anbieter nur bei Verletzung wesentlicher Vertragspflichten (Kardinalpflichten) und begrenzt auf den vertragstypischen, vorhersehbaren Schaden. Eine Haftung für entgangenen Gewinn, mittelbare Schäden oder Datenverluste ist – soweit gesetzlich zulässig – ausgeschlossen. Insbesondere haftet der Anbieter nicht für den Verlust von TOTP-Geheimnissen, die ausschließlich lokal auf den Geräten des Nutzers gespeichert sind.
§ 7 Verfügbarkeit
Der Anbieter ist bemüht, die App stabil und fehlerfrei bereitzustellen, übernimmt jedoch keine Garantie für ununterbrochene Verfügbarkeit oder vollständige Fehlerfreiheit. Updates können bestehende Funktionen ändern oder einschränken, soweit dies aus technischen, rechtlichen oder sicherheitsrelevanten Gründen erforderlich ist.
§ 8 Datenschutz
Es gilt die Datenschutzerklärung dieser Website.
§ 9 Änderungen der AGB
Der Anbieter behält sich vor, diese AGB mit Wirkung für die Zukunft zu ändern. Die jeweils aktuelle Fassung ist auf mfa-safe.hfb.one abrufbar.
§ 10 Schlussbestimmungen
Es gilt das Recht der Bundesrepublik Deutschland unter Ausschluss des UN-Kaufrechts. Gegenüber Verbrauchern gilt diese Rechtswahl nur insoweit, als dem Verbraucher dadurch nicht der Schutz zwingender Vorschriften seines Wohnsitzstaates entzogen wird. Sollten einzelne Bestimmungen unwirksam sein, bleibt die Wirksamkeit der übrigen Bestimmungen unberührt.
Stand: Mai 2026
§ 1 Scope
These Terms and Conditions (T&C) apply to the use of the software "MFA-Safe" and the associated website mfa-safe.hfb.one, both offered by HFB GmbH, Thüler Str. 3, 49681 Garrel, Germany (hereinafter "Provider"). By installing or using the app, the user accepts these T&C.
§ 2 Description of services
MFA-Safe is a software for generating time-based one-time passwords (TOTP) in accordance with RFC 6238 for two-factor authentication. Distribution takes place via the Apple App Store. The scope of functions is defined by the respective product description in the App Store.
§ 3 Contract conclusion and license
The app is obtained exclusively through the Apple App Store. The contractual partner for the download is Apple. Upon installation, the Provider grants the user a simple, non-exclusive, non-transferable right to use the app within the scope of Apple's terms of use.
§ 4 Prices and payment
The app is offered under the conditions stated in the App Store. Any in-app purchases or subscriptions are processed via the user's Apple account; Apple's terms apply.
§ 5 User obligations
The user is solely responsible for securing their devices, their Apple ID, their biometric settings and their TOTP secrets. The user must ensure that backup copies of TOTP accounts are made where this is required for their use case.
§ 6 Liability
The Provider is liable without limitation for intent and gross negligence as well as under the German Product Liability Act. In cases of slight negligence, the Provider is only liable for breach of essential contractual obligations (cardinal obligations) and limited to typical, foreseeable damage. Liability for lost profits, indirect damages or data loss is – to the extent permitted by law – excluded. In particular, the Provider is not liable for the loss of TOTP secrets that are stored exclusively locally on the user's devices.
§ 7 Availability
The Provider endeavors to make the app available stably and free of errors but does not guarantee uninterrupted availability or complete absence of errors. Updates may modify or restrict existing functions to the extent required for technical, legal or security reasons.
§ 8 Data protection
The privacy policy of this website applies.
§ 9 Changes to the T&C
The Provider reserves the right to amend these T&C with effect for the future. The current version is available at mfa-safe.hfb.one.
§ 10 Final provisions
The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods. With respect to consumers, this choice of law shall only apply insofar as it does not deprive the consumer of the protection of mandatory provisions of their country of residence. Should individual provisions be invalid, the validity of the remaining provisions shall remain unaffected.
Last updated: May 2026