Legal

Terms of Service

Last updated: September 22, 2026

By using PassZen you agree to these terms. If you disagree, please don't use the site.

These terms are written to be read, not just accepted: they cover what the service is, how you may use it, what we do and do not promise, the limits of the strength meter, how liability is limited, and where privacy details live. Nothing here changes the privacy promises in our Privacy Policy: generated passwords still stay on your device whether or not you ever open this page. We keep the terms deliberately short because the product is deliberately simple: a free, browser-based generator with no accounts and no billing.

PassZen is a convenience tool, not a substitute for professional security advice. Generated secrets use your browser's cryptographic RNG, but we make no guarantee that any specific password is unguessable in your threat model. The generator applies well-established, publicly documented techniques (a cryptographic random source, unbiased character selection, and standard entropy math) and the guides on this site summarize mainstream security guidance as we understand it. Security is a moving target: browsers change, attack capabilities grow, regulators update recommendations, and your circumstances vary enormously. The sections below describe the limits of what we claim, so you can decide how to use the tool responsibly alongside everything else in your security setup.

1. The service

A free, client-side tool that generates random passwords and PINs on your device. No account, no guarantee of availability; we may change or discontinue features.

The site is provided on an “as available” basis: pages may be updated, features may be added or retired, and there may be occasions when the generator is unreachable for maintenance, hosting issues, or circumstances beyond our control. Because there is no account system, there are no subscriptions to cancel and no service-level commitments to miss; we simply aim to keep the tool working in modern browsers. The entropy and strength figures shown by the meter are educational estimates based on standard formulas; they are not a certification, an audit, or a guarantee against any particular attack.

2. Acceptable use

Use secrets lawfully and for your own accounts. Don't attempt to disrupt the site, misrepresent it, or strip privacy/ad disclosures. Ad-blockers are your choice, but please consider allowing our clearly-labelled ads to keep the tool free.

Specifically, do not use the service to generate material intended for fraud, harassment, or any activity unlawful in your jurisdiction; do not probe, scan, overload, or reverse-engineer the site beyond ordinary browser use; do not rebrand or resell the generator as your own service without written permission; and do not remove or obscure the consent, privacy, or advertising disclosures that make the funding model honest. Automated scraping of the site's text content is unnecessary (the generator works in your browser) and should be limited to reasonable rates if you do crawl for archival purposes.

3. Your responsibility for generated secrets

Secrets are created by code running locally in your browser; once displayed, they are yours to manage. You are responsible for storing them safely (ideally in a password manager), for not pasting them into untrusted sites or messages, and for replacing them if you believe they have been exposed. We cannot recover, reset, or re-issue anything we never received; by design there is no server-side copy. If you generate a password and close the tab without saving it, it is gone; that is the privacy trade-off working as intended, not a bug.

4. What the strength meter can and cannot tell you

Entropy figures are statistical estimates of a secret's resistance to blind guessing, assuming the characters were chosen uniformly at random, which is true for values this tool produces, and false for values a human invents. The meter cannot account for what happens after generation: a password pasted into a phishing page, written on a sticky note, reused across ten sites, or recovered from a leaked database is weak regardless of its bit count. It also does not model targeted attacks that know something about you, offline cracking against a specific hashing algorithm, or implementation flaws in the site where the password is ultimately stored. Treat “Very strong” as a necessary condition, not a sufficient one.

Recommended companion practices:

  • Always store important secrets in a reputable password manager and enable two-factor authentication.
  • Use a unique password for every account so one breach cannot cascade into others.
  • Prefer authenticator apps or hardware keys over SMS for 2FA where the site offers the choice.
  • Keep your browser and operating system updated, cryptographic APIs and phishing protections live there too.
  • Verify compliance needs (e.g. PCI-DSS, HIPAA, corporate policies) with your own security team: some systems impose composition rules this tool can't know.
  • External links and ads are third-party content we don't control or endorse.

5. Your devices and environment

Client-side generation is only as trustworthy as the browser and device running it. Malicious extensions, compromised operating systems, keyloggers, shoulder-surfers, and untrusted networks can capture anything you type or display, no password generator can protect against a machine an attacker already controls. Use the tool on devices you trust, keep them patched, and be skeptical of unofficial copies of this site: check that the address matches ours before generating anything you care about.

6. No professional or legal advice; no warranty

Content is general information, not security advice for your specific situation. Articles, FAQs, and in-page tips are educational information current to the best of our knowledge on the date shown (not security consulting, not legal advice, and not regulatory guidance for your organization). If you are securing a business, handling regulated data, or fulfilling a contractual security obligation, engage a qualified professional who can assess your actual environment; do not rely on a free web page, however carefully written, as your entire program.

The site and its content are provided “as is” and “as available”, without warranties of any kind (express, implied, or statutory) to the maximum extent permitted by law. We do not warrant that the site will be uninterrupted, error-free, or free of harmful components; that strength labels are correct for every edge case; or that the tool is suitable for a regulated or high-assurance environment without independent review. To the fullest extent permitted by law, we disclaim implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that any generated password will withstand every attack vector, or that the guides and FAQs reflect the latest guidance from every regulator or standards body. Security is contextual: your threat model, device hygiene, and surrounding practices matter as much as any single password, and only you (or your security advisor) can weigh them together.

7. Liability

To the maximum extent permitted by law, we are not liable for indirect or consequential losses (including account compromise) arising from use of the site. Nothing here limits rights you have under applicable consumer law (including UK Consumer Rights Act 2015 where it applies).

Where liability can be limited, our aggregate liability arising out of or relating to the service will not exceed the greater of the amount you paid us to use the site (always zero, since the tool is free) or the minimum amount required by mandatory consumer law. Some jurisdictions do not allow certain limitations, so portions of this section may not apply to you, in those places, liability is limited to the smallest extent those laws still permit. Nothing in these terms excludes liability for fraud, deliberate misconduct, or any other liability that cannot lawfully be excluded.

8. External content & advertising

The site may link to third-party pages (documentation, breach-check tools, standards) and may display clearly-labelled advertisements when advertising is enabled and consented to. Those links and ads are provided for convenience; we do not control and do not endorse their content, policies, or practices, and visiting them takes you outside these terms. If you click an ad or an outbound link, the destination's own terms and privacy policy govern what happens next. Ad-blocking is respected: declining marketing consent simply leaves the ad areas empty and does not reduce your access to any feature.

References to products, standards, or services (password managers, breach-check sites, regulatory documents) are illustrative, not endorsements or partnerships, unless we explicitly say otherwise. Their features, pricing, and policies change without notice; confirm details at the source. Advertisements, when shown, are marked as such and are the responsibility of the advertising network and advertiser under their own terms.

9. Intellectual property

The site's branding, written content, layout, and original code are owned by us or our licensors and are protected by applicable copyright and trademark laws. You may read, print, and link to our guides for personal and internal educational use, provided you do not misrepresent authorship or strip attributions. You may not republish the full content on another website, sell it, or use it as training data for a commercial product without permission. Passwords you generate are yours (there is no claim over your secrets) and the underlying cryptographic algorithms are public standards anyone is free to implement.

10. Privacy

Use of the site is also governed by our Privacy Policy, which includes the full cookie and storage details, the consent categories, and how to exercise your rights. Those documents explain what is collected (very little), what is never collected (your generated secrets), and how to change your choices. In the event of any conflict between a summary on this page and the full privacy policy, the privacy policy controls for privacy matters.

11. Changes to these terms

We may update these terms as the service evolves. The “Last updated” date at the top always shows when the current version took effect. Material changes will be posted on this page; continued use of the site after a change means you accept the updated terms. If you do not agree with a revision, stop using the site, there is no account to close and no data of yours on our side to delete. We will not silently roll you into a materially different agreement: significant shifts (for example introducing paid features or new data uses) would be highlighted prominently and, where required, re-consented through the privacy controls.

12. Governing law

These terms are governed by the laws applicable where the site operator is established, without regard to conflict-of-law rules, except that mandatory consumer protections in your country of residence continue to apply and cannot be waived by contract. If any provision of these terms is found unenforceable, the remaining provisions stay in full effect, and the unenforceable provision will be applied to the maximum extent the law allows. Our failure to enforce a provision once does not waive our right to enforce it later.

13. Reporting problems & contact

If you spot something on this site that contradicts these terms, behaves unexpectedly, or could mislead users about security properties, please tell us via the contact page. Corrections and clarifications are updated here with a new date at the top. Never include a real password in your report, steps to reproduce, screenshots, and descriptions are enough.

Questions about these terms: contact us. We are happy to explain any clause in plain language, the goal of this page is informed use, not a gotcha. For general questions about how the generator works, the About page and the FAQ go into more depth than a legal document ever should.