Legal
Privacy Policy
Short version: generated passwords are created in your browser and are not sent to us; we do not receive them. We collect minimal data, only with your consent where the law requires it, and you can withdraw consent at any time.
This policy explains in detail what that means: which categories of data exist on this site, the legal basis for each, how long anything is kept, which rights you have depending on where you live, and how to exercise them. It follows the structure of the GDPR and UK GDPR, with additional notes for California (CCPA/CPRA) and other US state privacy laws. If any term is unfamiliar, the short version above still applies: secrets stay on your device, optional tracking is off until you turn it on, and nothing here requires you to create an account, because there are none.
1. What we do NOT collect
- Generated passwords or PINs: these exist only in your tab's memory and vanish on close.
- Account data: there are no accounts or sign-ups.
- Secret values in analytics: tracking events record only anonymous actions (e.g. “generated a password”), never values.
- Contact details from the contact page: there is no web form; you send email from your own mail client, and we only receive what you choose to write.
- Payment information: the tool is free and no billing data is collected anywhere on the site.
- Location, device fingerprints, or advertising identifiers without consent: optional tags stay unloaded until you opt in.
2. What we collect, and why
- Strictly necessary: your consent choice (localStorage, 12 months). Legal basis: legitimate interests / legal obligation (GDPR Art. 6(1)(f)/(c)).
- Functional (opt-in): generator settings (length, toggles) stored locally on your device only.
- Analytics (opt-in): if analytics are enabled, aggregated usage data (e.g. via Google Analytics 4 with Consent Mode, or Plausible). Legal basis: consent (Art. 6(1)(a)). No advertising identifiers without separate marketing consent.
- Marketing/ads (opt-in): if advertising is enabled, ad-network cookies/tags (e.g. Google AdSense) to show and measure clearly-labelled banners, only after consent and only when slots scroll into view.
- Standard web logs: like virtually every site, our host may temporarily log IP address, user agent, and requested path for security and abuse prevention. These server-side logs are not combined with secrets (which never reach the server) and are kept only as long as the host's normal operational retention.
None of these categories is required to use the generator. You can decline everything in the consent banner (including optional categories) and still create, copy, and store passwords exactly as before.
3. Consent & your controls
- Choose granularly in the cookie banner; change your mind anytime via the button or the consent panel linked in the footer.
- Do Not Track / Global Privacy Control signals are honored automatically: analytics and ads stay off.
- US users: use “Update consent” as your Do Not Sell or Share My Personal Information control; we do not sell data and share only service-provider data under contract.
- Withdrawing consent is as easy as granting it: reopen the panel, untick a category, and the corresponding scripts unload on your next page load. Withdrawal does not affect the lawfulness of processing that happened before it.
- Browser controls also work: clear site data in Chrome, Firefox, Safari, or Edge, or use private windows to prevent persistence. Clearing site data removes the stored consent choice entirely; the banner will reappear on your next visit so you can choose again.
- Per-browser cookie managers (Chrome's cookie icon, Firefox's lock icon, Safari's “Manage Website Data”, Edge's cookie panel) let you inspect and delete individual items. “Block third-party cookies” is compatible with this site: the generator does not depend on cross-site cookies, and optional third parties will simply receive less.
4. Cookies & similar technologies
We use a small amount of browser storage. No storage is set for analytics or ads until you consent (EU/UK ePrivacy + GDPR). Cookies, localStorage, and similar browser storage are used sparingly: the consent choice itself is stored locally so the banner does not reappear on every visit, and optional generator preferences may be stored the same way if you enable functional storage. A “cookie” is a small piece of data a website asks your browser to remember; “local storage” is a similar cupboard in the same browser. On this site the cupboard holds almost nothing, and generated passwords are never written to any storage mechanism, including cookies, sessionStorage, IndexedDB, or cache entries.
| Category | Examples | Basis | Duration |
|---|---|---|---|
| Strictly necessary | Consent choice (localStorage) | Exempt / legitimate interests | 12 months |
| Functional | Generator settings (local device) | Consent | Until cleared |
| Analytics | GA4 / Plausible (only if enabled) | Consent | Up to 14 months aggregate |
| Marketing / ads | Ad-network tags (only if enabled) | Consent | Per network (see their policies) |
What each category is for
- Strictly necessary: remembers your cookie-banner decision so you are not asked on every page view. Without it the banner could not honor your choice at all, which is why it is treated as necessary rather than optional. It contains no identifier beyond the settings themselves.
- Functional: optionally remembers generator preferences such as default length or which character sets you prefer, so the tool opens the way you left it. Stored on your device only; never uploaded. Skip it and the generator simply starts from its defaults each visit.
- Analytics: aggregated statistics about page views and interactions (for example how often the generate button is pressed; never the password itself). Helps us see which guides people read and where the interface confuses them. Off by default; both GA4 (with Consent Mode) and Plausible are handled so events are not recorded before consent.
- Marketing / ads: used by ad networks to place and measure the clearly-labelled banners that help fund the site. Off by default. When declined, the ad slots stay empty and no ad-network tags load at all; the generator is unaffected either way.
First-party vs. third-party
First-party storage is set by this site itself and stays in your browser's partition for this domain, that covers the consent choice and any functional preferences. Third-party storage is set by embedded services (an analytics script, an ad frame) under their own domains and is governed partly by their policies. On PassZen, third-party storage exists only after you consent to the relevant category, and some categories may involve no cookies at all depending on how the provider is configured (for example cookieless or privacy-oriented analytics modes where available). Providers we may use are listed above so you can read the fine print before deciding.
Third parties & private windows
With consent (and only if analytics or advertising are enabled) third parties such as Google Analytics or an ad network may set their own cookies or tags under their own policies (for example Google's Privacy & Terms). Those scripts are loaded lazily, only after consent, and are never given generated passwords. Declining marketing keeps ad-network tags unloaded rather than merely hidden; if you ever see an ad after rejecting marketing consent, that would be a bug, please report it via the contact page.
Browsing in private/incognito mode means storage disappears when you close the window: the consent banner will reappear next time, functional preferences will not persist, and no analytics or ad identifiers outlive the session. This is a convenient way to use the site with zero persistence, the generator itself never needed storage in the first place.
5. International transfers
If analytics or advertising providers are enabled, they may process data outside your country (for example in the US), subject to the transfer mechanism they rely on (such as the EU-US Data Privacy Framework or Standard Contractual Clauses). Data is minimized (anonymized IPs where supported, and never generated passwords) before any such transfer. Because optional services stay off by default, users who decline consent keep their data within the normal operation of static hosting and never trigger these transfers at all.
6. Retention
Consent records: 12 months. Aggregated analytics (if enabled): up to 14 months aggregate. Generator inputs: no server-side retention at all; they exist only in your tab's memory. Server security logs, where produced by the host, are rotated on the host's normal short-lived schedule. When a retention period ends, data is deleted or irreversibly aggregated so it can no longer be linked to a browser or person.
7. Your rights (GDPR / UK GDPR / CCPA-CPRA & US state laws)
Depending on residence (EU/EEA, UK, California, Virginia, Colorado, Connecticut, Utah, etc.) you may have rights to access, correct, delete, port, restrict, object, and opt out of sale/sharing or targeted advertising, plus non-discrimination for exercising them. Email us. We respond within statutory deadlines (GDPR: 1 month; CCPA: 45 days). EU/UK users may also complain to their supervisory authority (e.g. the ICO in the UK).
In practice, most requests are simpler than they sound: with no accounts and no server-side profiles, “access” usually means confirming what optional categories are enabled in your browser, and “deletion” usually means clearing your own site data, which you can do yourself in seconds. If you still want a formal written response, say so in your email and include your jurisdiction so we can apply the right timeline. We will never ask you for a password, a government ID scan, or payment in order to honor a privacy request.
8. Children
This tool is for general audiences and not directed at children under 13 (16 in parts of the EU/UK). We do not knowingly collect children's data. Because the site has no registration and no knowledge of who visits, we cannot positively verify age; if you believe a child has sent us personal information via email, contact us and we will delete it promptly.
9. Security
The site is delivered over HTTPS when hosted, it collects minimal data, and passwords are generated client-side rather than on a server. No system is perfect: report issues via contact. Our overall posture is data minimization, the strongest protection for information we never hold. Optional third-party scripts, where enabled, are loaded lazily after consent and are contractually limited to the purposes described here; they never receive generated secrets because those values exist only in your page's memory.
10. Third-party links
The site links to external resources, documentation, breach-check services, and our own legal pages. Those destinations operate under their own privacy policies, which we do not control. Follow a link and you leave this policy behind; check the destination's policy before submitting any personal information there. Advertisements, when shown, are clearly labelled and similarly subject to the ad network's own practices, gated behind marketing consent.
11. Changes
Material changes will be noted here with a new date. Continued use after changes means you accept the update; consent-gated processing always re-asks where required. For substantive changes (a new category of tracking, a new analytics provider, a shift in retention) we will re-display the consent banner so you can make a fresh choice instead of being carried over by default. Routine wording fixes and clarifications only refresh the “Last updated” date at the top of this page, which always reflects the current version; you can compare your current choices against the table in section 4 using the consent panel. Archived versions can be requested by email if you need to compare.
12. How to contact us
Questions about this policy (including anything about cookies, storage, or consent) or any request under the rights described above, can be sent to our contact page or emailed directly to [email protected]. Put “Privacy request” in the subject line and mention your jurisdiction so we can respond within the correct deadline. We are happy to clarify any section in plain language; you should never need a lawyer to understand what this site does with your data.