Privacy Policy
Effective date: September 23, 2026
This Privacy Policy explains what data PassGenerate ("we", "the site") processes when you use passgenerate.com, and what choices you have.
The short version
- Generated passwords are never sent to us. Password generation happens entirely in your browser using the Web Crypto API. We have no server-side password generation, no database, and no way to see the passwords you create.
- We don't require an account. There is no sign-up, no login, and no user profile.
- We store almost nothing ourselves. The only thing our own code saves is your cookie-consent choice itself (so we don't ask again every visit). Your language isn't stored anywhere β switching languages just navigates to a different URL.
- We show ads (Google AdSense), and, only if you consent, we use Google Analytics to understand aggregate site traffic. These are the only two third parties that process data on this site β details below.
What we do not collect
We do not collect, store, or transmit:
- Passwords or passphrases you generate
- The character-set or length settings you choose
- Any account credentials (we have no accounts)
Password generation runs client-side via crypto.getRandomValues() (a cryptographically secure random number generator built into your browser). Nothing about the password itself is transmitted to any server, including ours β this applies equally to the hash generator and WiFi QR code tools: nothing typed into those tools is uploaded either, regardless of your cookie-consent choices below.
Local storage and cookies
The "π Privacy Settings" panel available on every page lets you manage three categories. Here's exactly what each one does today:
| Category | What it actually does today |
|---|---|
| Necessary | Stores your cookie-consent choice itself, in your browser's local storage, so we don't ask again every visit. |
| Functional | Not currently used to collect or store anything. Toggling it on does not enable any feature yet. |
| Analytics | If enabled, loads Google Analytics (GA4), which sets its own cookies to measure aggregate site traffic. Nothing loads until you turn this on β see the next section. |
Turning on Functional or Analytics also allows Google AdSense to serve personalized (rather than non-personalized) ads β see the Advertising section below. You can accept all, reject all, or customize these categories at any time from the same panel.
Analytics (Google Analytics)
If you turn on the "Analytics" category in the Privacy Settings panel, we load Google Analytics (GA4) to understand how the site is used in aggregate β which pages are visited, roughly how much traffic we get, what device/browser types are common. This helps us understand what's actually useful to prioritize.
- Nothing loads until you consent. If you don't turn on Analytics, no Google Analytics script or cookie is ever set, and no data goes to Google Analytics.
- Google Analytics uses cookies (such as
_gaand_ga_*) to distinguish visitors and sessions. It does not have access to anything you type into the password generator, hash generator, or WiFi QR tool β those remain entirely client-side regardless of this setting. - Data collected is processed by Google according to its own policies, not ours. See Google's Privacy Policy and how Google uses data from sites that use its services.
- You can withdraw consent at any time via the "π Privacy Settings" panel. Turning Analytics off clears the Google Analytics cookies already set in your browser.
Advertising (Google AdSense)
PassGenerate displays ads served by Google AdSense to support running this tool for free. When ads are shown:
- If you have not consented to functional/analytics cookies, we request non-personalized ads from Google (
requestNonPersonalizedAds), which use less data and rely on contextual rather than behavioral targeting. - If you consent to functional/analytics cookies, ads may be personalized based on Google's own data practices.
- Google may set its own cookies and process data according to its policies, not ours. See How Google uses information from sites or apps that use our services and Google's Privacy Policy. You can control ad personalization directly at Google Ads Settings.
Other third parties
- Hosting/CDN (Cloudflare): Like any website, requests to passgenerate.com pass through our hosting provider, which processes standard technical data (such as IP address) to deliver the page and provide security protections (e.g., DDoS mitigation). This is inherent to operating any website over HTTPS and is not used by us for tracking.
- We do not sell personal data, and we do not share data with third parties beyond Google AdSense, Google Analytics (only with consent), and Cloudflare hosting as described above.
Your choices and rights
- Change or withdraw cookie consent anytime via the "π Privacy Settings" panel (accept all / reject all / customize) β this includes turning Google Analytics on or off.
- Clear the stored consent choice through your browser's own site-data or cookie settings.
- Opt out of personalized ads via Google Ads Settings or aboutads.info.
- Opt out of Google Analytics by leaving the Analytics category off (nothing loads by default), or using Google's Analytics opt-out browser add-on if you've previously consented on another device.
- If you are covered by a statutory data-protection framework (such as the EU GDPR, UK GDPR, or another applicable data protection law), you can contact us using the details below with any data-subject request; given we hold minimal personal data server-side, most requests can typically be resolved by clearing your local browser data.
Children's privacy
PassGenerate is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to a third-party service used on this site (such as Google AdSense or Google Analytics), please contact the relevant third party directly using the links above, and let us know so we can review the situation.
Security
The site is served over HTTPS, and standard security headers (including Content-Security-Policy-adjacent protections, X-Frame-Options, X-Content-Type-Options, and a restrictive Permissions-Policy) are applied to reduce common web risks. Since password generation and storage happen entirely client-side, there is no central database of generated credentials to secure or that could be breached.
Changes to this policy
We may update this Privacy Policy as the site or the services it uses change (for example, if advertising or analytics providers change). We'll update the effective date above when we do. Continued use of the site after changes means you accept the revised policy.
Contact
Questions about this policy can be sent via the "Contact Us" link in the site footer.