1. We follow a "trusted devices" model, where you 2FA using your phone number for the first login on a device. Future logins on that device aren't 2FA'd. I agree that using a code gen is a good improvement we can make over time.
2. Marketing opt-out is prominent in account settings. Any email that is very strictly not transactional is considered marketing by our team, and can be opted out of. Developing simple, focused products is core to our identity and we won't add irrelevant features that might upsell to 10% of customers. I assure you there won't be a "refer your friends" badge blinking on the home page of the app.
3. Unfortunately we're not on web yet - but we'd love to get there after iOS and Android. We hear from most people that iOS or Android are their preferred platforms, so we have to start there.
4. We share data as required to support financial transactions and other core parts of the business, but we do adhere to the GDPR.
5. I think VPNs are allowed - at least I don't think we block them in particular.
We're excited to bring a fresh perspective and better pricing to a landscape with a lot of providers doing approximately the same thing. We'd love for you to try out the app once it's available - if you decide to register on our site we'll be sure to keep you updated.